VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 104 of 187
  • CVE-2024-36055MedMay 26, 2024
    risk 0.36cvss 5.5epss 0.00

    Hw64.sys in Marvin Test HW.exe before 5.0.5.0 allows unprivileged user-mode processes to arbitrarily map physical memory with read/write access via the MmMapIoSpace API (IOCTL 0x9c40a4f8, 0x9c40a4e8, 0x9c40a4c0, 0x9c40a4c4, 0x9c40a4ec, and seven others), leading to a denial of…

  • CVE-2023-45793MedMar 12, 2024
    risk 0.36cvss 5.5epss 0.00

    A vulnerability has been identified in Siveillance Control (All versions >= V2.8 < V3.1.1). The affected product does not properly check the list of access groups that are assigned to an individual user. This could enable a locally logged on user to gain write privileges for…

  • CVE-2024-23250MedMar 8, 2024
    risk 0.36cvss 5.5epss 0.00

    An access issue was addressed with improved access restrictions. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An app may be able to access Bluetooth-connected microphones without user permission.

  • CVE-2023-42860MedFeb 21, 2024
    risk 0.36cvss 5.5epss 0.00

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1. An app may be able to modify protected parts of the file system.

  • CVE-2024-0017MedFeb 16, 2024
    risk 0.36cvss 5.5epss 0.00

    In shouldUseNoOpLocation of CameraActivity.java, there is a possible confused deputy due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2023-41994MedJan 10, 2024
    risk 0.36cvss 5.5epss 0.00

    A logic issue was addressed with improved checks This issue is fixed in macOS Sonoma 14. A camera extension may be able to access the camera view from apps other than the app for which it was granted permission.

  • CVE-2023-45626MedNov 14, 2023
    risk 0.36cvss 5.5epss 0.01

    An authenticated vulnerability has been identified allowing an attacker to effectively establish highly privileged persistent arbitrary code execution across boot cycles.

  • CVE-2023-21311MedOct 30, 2023
    risk 0.36cvss 5.5epss 0.00

    In Settings, there is a possible way to control private DNS settings from a secondary user due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-41077MedOct 25, 2023
    risk 0.36cvss 5.5epss 0.00

    An app may be able to access protected user data. This issue is fixed in macOS Sonoma 14, macOS Ventura 13.6.1. The issue was addressed with improved checks.

  • CVE-2023-41078MedSep 27, 2023
    risk 0.36cvss 5.5epss 0.00

    An authorization issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14. An app may be able to bypass certain Privacy preferences.

  • CVE-2023-4194MedAug 7, 2023
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in the Linux kernel's TUN/TAP functionality. This issue could allow a local user to bypass network filters and gain unauthorized access to some resources. The original patches fixing CVE-2023-1076 are incorrect or incomplete. The problem is that the following…

  • CVE-2023-35983MedJul 27, 2023
    risk 0.36cvss 5.5epss 0.00

    This issue was addressed with improved data protection. This issue is fixed in macOS Monterey 12.6.8, macOS Ventura 13.5, macOS Big Sur 11.7.9. An app may be able to modify protected parts of the file system.

  • CVE-2023-35866MedJun 19, 2023
    risk 0.36cvss 5.5epss 0.00

    In KeePassXC through 2.7.5, a local attacker can make changes to the Database security settings, including master password and second-factor authentication, within an authenticated KeePassXC Database session, without the need to authenticate these changes by entering the…

  • CVE-2023-29761MedJun 9, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue found in Sleep v.20230303 for Android allows unauthorized apps to cause a persistent denial of service by manipulating the SharedPreference files.

  • CVE-2023-29759MedJun 9, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue found in FlightAware v.5.8.0 for Android allows unauthorized apps to cause a persistent denial of service by manipulating the database files.

  • CVE-2023-29758MedJun 9, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue found in Blue Light Filter v.1.5.5 for Android allows unauthorized apps to cause a persistent denial of service by manipulating the SharedPreference files.

  • CVE-2023-26818MedMay 19, 2023
    risk 0.36cvss 5.5epss 0.01

    Telegram 9.3.1 and 9.4.0 allows attackers to access restricted files, microphone ,or video recording via the DYLD_INSERT_LIBRARIES flag.

  • CVE-2023-2782MedMay 18, 2023
    risk 0.36cvss 5.5epss 0.00

    Sensitive information disclosure due to improper authorization. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.3.1-38.

  • CVE-2023-29819MedMay 12, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to bypass protections via a crafted payload.

  • CVE-2023-29818MedMay 12, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to bypass protections via the default allowlist feature being stored as non-admin.