VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 42 of 187
  • CVE-2023-20971HigMar 24, 2023
    risk 0.51cvss 7.8epss 0.00

    In removePermission of PermissionManagerServiceImpl.java, there is a possible way to obtain dangerous permissions without user consent due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User…

  • CVE-2023-24485HigFeb 16, 2023
    risk 0.51cvss 7.8epss 0.00

    Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix Workspace app.

  • CVE-2021-37409HigAug 18, 2022
    risk 0.51cvss 7.8epss 0.00

    Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2021-39802HigApr 12, 2022
    risk 0.51cvss 7.8epss 0.00

    In change_pte_range of mprotect.c , there is a possible way to make a shared mmap writable due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-39799HigApr 12, 2022
    risk 0.51cvss 7.8epss 0.00

    In AttributionSource of AttributionSource.java, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-0694HigApr 12, 2022
    risk 0.51cvss 7.8epss 0.00

    In setServiceForegroundInnerLocked of ActiveServices.java, there is a possible way for a background application to regain foreground permissions due to insufficient background restrictions. This could lead to local escalation of privilege with no additional execution privileges…

  • CVE-2021-39790HigMar 30, 2022
    risk 0.51cvss 7.8epss 0.00

    In Dialer, there is a possible way to manipulate visual voicemail settings due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-39789HigMar 30, 2022
    risk 0.51cvss 7.8epss 0.00

    In Telecom, there is a possible leak of TTY mode change due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-22042HigFeb 16, 2022
    risk 0.51cvss 7.8epss 0.00

    VMware ESXi contains an unauthorized access vulnerability due to VMX having access to settingsd authorization tickets. A malicious actor with privileges within the VMX process only, may be able to access settingsd service running as a high privileged user.

  • CVE-2020-14110HigJan 18, 2022
    risk 0.51cvss 7.8epss 0.00

    AX3600 router sensitive information leaked.There is an unauthorized interface through luci to obtain sensitive information and log in to the web background.

  • CVE-2021-39630HigJan 14, 2022
    risk 0.51cvss 7.8epss 0.00

    In executeRequest of OverlayManagerService.java, there is a possible way to control fabricated overlays from adb shell due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-45339HigDec 27, 2021
    risk 0.51cvss 7.8epss 0.00

    Privilege escalation vulnerability in Avast Antivirus prior to 20.4 allows a local user to gain elevated privileges by "hollowing" trusted process which could lead to the bypassing of Avast self-defense.

  • CVE-2021-0649HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.00

    In stopVpnProfile of Vpn.java, there is a possible VPN profile reset due to a permissions bypass. This could lead to local escalation of privilege CONTROL_ALWAYS_ON_VPN with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-0645HigAug 17, 2021
    risk 0.51cvss 7.8epss 0.00

    In shouldBlockFromTree of ExternalStorageProvider.java, there is a possible permissions bypass. This could lead to local escalation of privilege, allowing an app to read private app directories in external storage, which should be restricted in Android 11, with no additional…

  • CVE-2021-26273HigJul 7, 2021
    risk 0.51cvss 7.8epss 0.00

    The Agent in NinjaRMM 5.0.909 has Incorrect Access Control.

  • CVE-2021-0571HigJun 22, 2021
    risk 0.51cvss 7.8epss 0.00

    In ActivityTaskManagerService.startActivity() and AppTaskImpl.startActivity() of ActivityTaskManagerService.java and AppTaskImpl.java, there is possible access to restricted activities due to a permissions bypass. This could lead to local escalation of privilege with no…

  • CVE-2021-0472HigJun 11, 2021
    risk 0.51cvss 7.8epss 0.00

    In shouldLockKeyguard of LockTaskController.java, there is a possible way to exit App Pinning without a PIN due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-25418HigJun 11, 2021
    risk 0.51cvss 7.8epss 0.00

    Improper component protection vulnerability in Samsung Internet prior to version 14.0.1.62 allows untrusted applications to execute arbitrary activity in specific condition.

  • CVE-2021-31165HigMay 11, 2021
    risk 0.51cvss 7.8epss 0.01

    Windows Container Manager Service Elevation of Privilege Vulnerability

  • CVE-2021-27086HigApr 13, 2021
    risk 0.51cvss 7.8epss 0.01

    Windows Services and Controller App Elevation of Privilege Vulnerability