VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,244)

page 122 of 213
  • CVE-2023-23506MedFeb 27, 2023
    risk 0.36cvss 5.5epss 0.00

    A permissions issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.2. An app may be able to access user-sensitive data.

  • CVE-2022-46704MedFeb 27, 2023
    risk 0.36cvss 5.5epss 0.00

    A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.1, macOS Big Sur 11.7.2, macOS Monterey 12.6.2. An app may be able to modify protected parts of the file system.

  • CVE-2022-42788MedNov 1, 2022
    risk 0.36cvss 5.5epss 0.00

    A permissions issue existed. This issue was addressed with improved permission validation. This issue is fixed in macOS Ventura 13. A malicious application may be able to read sensitive location information.

  • CVE-2022-26767MedMay 26, 2022
    risk 0.36cvss 5.5epss 0.01

    The issue was addressed with additional permissions checks. This issue is fixed in macOS Monterey 12.4, macOS Big Sur 11.6.6. A malicious application may be able to bypass Privacy preferences.

  • CVE-2022-28774MedMay 11, 2022
    risk 0.36cvss 5.5epss 0.00

    Under certain conditions, the SAP Host Agent logfile shows information which would otherwise be restricted.

  • CVE-2020-14121MedApr 21, 2022
    risk 0.36cvss 5.5epss 0.00

    A business logic vulnerability exists in Mi App Store. The vulnerability is caused by incomplete permission checks of the products being bypassed, and an attacker can exploit the vulnerability to perform a local silent installation.

  • CVE-2021-25735MedSep 6, 2021
    risk 0.36cvss 6.5epss 0.06

    A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. Clusters are only affected by this vulnerability if they run a Validating Admission Webhook for Nodes that denies admission based at least partially on the…

  • CVE-2021-22236MedAug 25, 2021
    risk 0.36cvss 5.5epss 0.01

    Due to improper handling of OAuth client IDs, new subscriptions generated OAuth tokens on an incorrect OAuth client application. This vulnerability is present in GitLab CE/EE since version 14.1.

  • CVE-2021-30987MedAug 24, 2021
    risk 0.36cvss 5.5epss 0.00

    An access issue was addressed with improved access restrictions. This issue is fixed in macOS Monterey 12.1. A device may be passively tracked via BSSIDs.

  • CVE-2021-30972MedAug 24, 2021
    risk 0.36cvss 5.5epss 0.00

    This issue was addressed with improved checks. This issue is fixed in Security Update 2022-001 Catalina, macOS Big Sur 11.6.3. A malicious application may be able to bypass certain Privacy preferences.

  • CVE-2021-3499MedJun 2, 2021
    risk 0.36cvss 5.6epss 0.01

    A vulnerability was found in OVN Kubernetes in versions up to and including 0.3.0 where the Egress Firewall does not reliably apply firewall rules when there is multiple DNS rules. It could lead to potentially lose of confidentiality, integrity or availability of a service.

  • CVE-2021-31829MedMay 6, 2021
    risk 0.36cvss 5.5epss 0.00

    kernel/bpf/verifier.c in the Linux kernel through 5.12.1 performs undesirable speculative loads, leading to disclosure of stack content via side-channel attacks, aka CID-801c6058d14a. The specific concern is not protecting the BPF stack area against speculative loads. Also, the…

  • CVE-2020-14106MedApr 8, 2021
    risk 0.36cvss 5.5epss 0.01

    The application in the mobile phone can unauthorized access to the list of running processes in the mobile phone, Xiaomi Mobile Phone MIUI < 2021.01.26.

  • CVE-2021-26718MedApr 1, 2021
    risk 0.36cvss 5.5epss 0.00

    KIS for macOS in some use cases was vulnerable to AV bypass that potentially allowed an attacker to disable anti-virus protection.

  • CVE-2021-0382MedMar 10, 2021
    risk 0.36cvss 5.5epss 0.00

    In checkSlicePermission of SliceManagerService.java, there is a possible resource exposure due to an incorrect permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-1054MedJan 8, 2021
    risk 0.36cvss 5.5epss 0.00

    NVIDIA GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which the software does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or…

  • CVE-2020-11209MedNov 12, 2020
    risk 0.36cvss 5.5epss 0.02

    Improper authorization in DSP process could allow unauthorized users to downgrade the library versions in SD820, SD821, SD820, QCS603, QCS605, SDA855, SA6155P, SA6145P, SA6155, SA6155P, SD855, SD 675, SD660, SD429, SD439

  • CVE-2020-3477MedSep 24, 2020
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the CLI parser of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to access files from the flash: filesystem. The vulnerability is due to insufficient application of restrictions during the execution of a specific…

  • CVE-2020-9712MedAug 19, 2020
    risk 0.36cvss 5.5epss 0.03

    Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have a security bypass vulnerability. Successful exploitation could lead to security feature bypass.

  • CVE-2020-9692MedJul 29, 2020
    risk 0.36cvss 6.5epss 0.04

    Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a security mitigation bypass vulnerability. Successful exploitation could lead to arbitrary code execution.