VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,171)

page 45 of 209
  • CVE-2024-0043HigMay 7, 2024
    risk 0.51cvss 7.8epss 0.00

    In multiple locations, there is a possible notification listener grant to an app running in the work profile due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for…

  • CVE-2023-42124HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.00

    Avast Premium Security Sandbox Protection Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avast Premium Security. An attacker must first obtain the ability to execute…

  • CVE-2024-1156HigFeb 20, 2024
    risk 0.51cvss 7.8epss 0.00

    Incorrect directory permissions for the shared NI RabbitMQ service may allow a local authenticated user to read RabbitMQ configuration information and potentially enable escalation of privileges.

  • CVE-2024-1155HigFeb 20, 2024
    risk 0.51cvss 7.8epss 0.00

    Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-22938HigJan 30, 2024
    risk 0.51cvss 7.8epss 0.00

    Insecure Permissions vulnerability in BossCMS v.1.3.0 allows a local attacker to execute arbitrary code and escalate privileges via the init function in admin.class.php component.

  • CVE-2023-21390HigOct 30, 2023
    risk 0.51cvss 7.8epss 0.00

    In Sim, there is a possible way to evade mobile preference restrictions due to a permission bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-40117HigOct 27, 2023
    risk 0.51cvss 7.8epss 0.00

    In resetSettingsLocked of SettingsProvider.java, there is a possible lockscreen bypass due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-3899HigAug 23, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization. The D-Bus interface com.redhat.RHSM1 exposes a significant number of methods to all users that could change the state of the registration. By using the…

  • CVE-2023-21256HigJul 13, 2023
    risk 0.51cvss 7.8epss 0.00

    In SettingsHomepageActivity.java, there is a possible way to launch arbitrary activities via Settings due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2023-21254HigJul 13, 2023
    risk 0.51cvss 7.8epss 0.00

    In getCurrentState of OneTimePermissionUserManager.java, there is a possible way to hold one-time permissions after the app is being killed due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User…

  • CVE-2023-21245HigJul 13, 2023
    risk 0.51cvss 7.8epss 0.00

    In showNextSecurityScreenOrFinish of KeyguardSecurityContainerController.java, there is a possible way to access the lock screen during device setup due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed.…

  • CVE-2023-21225HigJun 28, 2023
    risk 0.51cvss 7.8epss 0.00

    there is a possible way to bypass the protected confirmation screen due to Failure to lock display power. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions:…

  • CVE-2023-34148HigJun 26, 2023
    risk 0.51cvss 7.8epss 0.00

    An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to escalate privileges and write an arbitrary value to specific Trend Micro agent subkeys on affected installations. Please note: an…

  • CVE-2023-34147HigJun 26, 2023
    risk 0.51cvss 7.8epss 0.00

    An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to escalate privileges and write an arbitrary value to specific Trend Micro agent subkeys on affected installations. Please note: an…

  • CVE-2023-34146HigJun 26, 2023
    risk 0.51cvss 7.8epss 0.00

    An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to escalate privileges and write an arbitrary value to specific Trend Micro agent subkeys on affected installations. Please note: an…

  • CVE-2023-32353HigJun 23, 2023
    risk 0.51cvss 7.8epss 0.01

    A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.12.9 for Windows. An app may be able to elevate privileges.

  • CVE-2022-31646HigJun 14, 2023
    risk 0.51cvss 7.8epss 0.00

    Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

  • CVE-2022-31644HigJun 14, 2023
    risk 0.51cvss 7.8epss 0.00

    Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

  • CVE-2023-29766HigJun 9, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue found in CrossX v.1.15.3 for Android allows a local attacker to cause an escalation of Privileges via the database files.

  • CVE-2023-29752HigJun 9, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue found in Facemoji Emoji Keyboard v.2.9.1.2 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the component.