VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 105 of 187
  • CVE-2023-27951MedMay 8, 2023
    risk 0.36cvss 5.5epss 0.00

    The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. An archive may be able to bypass Gatekeeper.

  • CVE-2023-23538MedMay 8, 2023
    risk 0.36cvss 5.5epss 0.00

    A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4. An app may be able to modify protected parts of the file system.

  • CVE-2023-23510MedFeb 27, 2023
    risk 0.36cvss 5.5epss 0.00

    A permissions issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.2. An app may be able to access a user’s Safari history.

  • CVE-2023-23506MedFeb 27, 2023
    risk 0.36cvss 5.5epss 0.00

    A permissions issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.2. An app may be able to access user-sensitive data.

  • CVE-2022-46704MedFeb 27, 2023
    risk 0.36cvss 5.5epss 0.00

    A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.1, macOS Big Sur 11.7.2, macOS Monterey 12.6.2. An app may be able to modify protected parts of the file system.

  • CVE-2022-42788MedNov 1, 2022
    risk 0.36cvss 5.5epss 0.00

    A permissions issue existed. This issue was addressed with improved permission validation. This issue is fixed in macOS Ventura 13. A malicious application may be able to read sensitive location information.

  • CVE-2022-26767MedMay 26, 2022
    risk 0.36cvss 5.5epss 0.01

    The issue was addressed with additional permissions checks. This issue is fixed in macOS Monterey 12.4, macOS Big Sur 11.6.6. A malicious application may be able to bypass Privacy preferences.

  • CVE-2022-28774MedMay 11, 2022
    risk 0.36cvss 5.5epss 0.00

    Under certain conditions, the SAP Host Agent logfile shows information which would otherwise be restricted.

  • CVE-2020-14121MedApr 21, 2022
    risk 0.36cvss 5.5epss 0.00

    A business logic vulnerability exists in Mi App Store. The vulnerability is caused by incomplete permission checks of the products being bypassed, and an attacker can exploit the vulnerability to perform a local silent installation.

  • CVE-2021-25735MedSep 6, 2021
    risk 0.36cvss 6.5epss 0.06

    A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. Clusters are only affected by this vulnerability if they run a Validating Admission Webhook for Nodes that denies admission based at least partially on the…

  • CVE-2021-22236MedAug 25, 2021
    risk 0.36cvss 5.5epss 0.01

    Due to improper handling of OAuth client IDs, new subscriptions generated OAuth tokens on an incorrect OAuth client application. This vulnerability is present in GitLab CE/EE since version 14.1.

  • CVE-2021-30987MedAug 24, 2021
    risk 0.36cvss 5.5epss 0.00

    An access issue was addressed with improved access restrictions. This issue is fixed in macOS Monterey 12.1. A device may be passively tracked via BSSIDs.

  • CVE-2021-30972MedAug 24, 2021
    risk 0.36cvss 5.5epss 0.00

    This issue was addressed with improved checks. This issue is fixed in Security Update 2022-001 Catalina, macOS Big Sur 11.6.3. A malicious application may be able to bypass certain Privacy preferences.

  • CVE-2020-14106MedApr 8, 2021
    risk 0.36cvss 5.5epss 0.01

    The application in the mobile phone can unauthorized access to the list of running processes in the mobile phone, Xiaomi Mobile Phone MIUI < 2021.01.26.

  • CVE-2021-26718MedApr 1, 2021
    risk 0.36cvss 5.5epss 0.00

    KIS for macOS in some use cases was vulnerable to AV bypass that potentially allowed an attacker to disable anti-virus protection.

  • CVE-2021-0382MedMar 10, 2021
    risk 0.36cvss 5.5epss 0.00

    In checkSlicePermission of SliceManagerService.java, there is a possible resource exposure due to an incorrect permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-1054MedJan 8, 2021
    risk 0.36cvss 5.5epss 0.00

    NVIDIA GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which the software does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or…

  • CVE-2020-11209MedNov 12, 2020
    risk 0.36cvss 5.5epss 0.02

    Improper authorization in DSP process could allow unauthorized users to downgrade the library versions in SD820, SD821, SD820, QCS603, QCS605, SDA855, SA6155P, SA6145P, SA6155, SA6155P, SD855, SD 675, SD660, SD429, SD439

  • CVE-2020-3477MedSep 24, 2020
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the CLI parser of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to access files from the flash: filesystem. The vulnerability is due to insufficient application of restrictions during the execution of a specific…

  • CVE-2020-9712MedAug 19, 2020
    risk 0.36cvss 5.5epss 0.03

    Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have a security bypass vulnerability. Successful exploitation could lead to security feature bypass.