VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,171)

page 47 of 209
  • CVE-2021-39790HigMar 30, 2022
    risk 0.51cvss 7.8epss 0.00

    In Dialer, there is a possible way to manipulate visual voicemail settings due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-39789HigMar 30, 2022
    risk 0.51cvss 7.8epss 0.00

    In Telecom, there is a possible leak of TTY mode change due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-22042HigFeb 16, 2022
    risk 0.51cvss 7.8epss 0.00

    VMware ESXi contains an unauthorized access vulnerability due to VMX having access to settingsd authorization tickets. A malicious actor with privileges within the VMX process only, may be able to access settingsd service running as a high privileged user.

  • CVE-2020-14110HigJan 18, 2022
    risk 0.51cvss 7.8epss 0.00

    AX3600 router sensitive information leaked.There is an unauthorized interface through luci to obtain sensitive information and log in to the web background.

  • CVE-2021-39630HigJan 14, 2022
    risk 0.51cvss 7.8epss 0.00

    In executeRequest of OverlayManagerService.java, there is a possible way to control fabricated overlays from adb shell due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-45339HigDec 27, 2021
    risk 0.51cvss 7.8epss 0.00

    Privilege escalation vulnerability in Avast Antivirus prior to 20.4 allows a local user to gain elevated privileges by "hollowing" trusted process which could lead to the bypassing of Avast self-defense.

  • CVE-2021-0649HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.00

    In stopVpnProfile of Vpn.java, there is a possible VPN profile reset due to a permissions bypass. This could lead to local escalation of privilege CONTROL_ALWAYS_ON_VPN with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-0645HigAug 17, 2021
    risk 0.51cvss 7.8epss 0.00

    In shouldBlockFromTree of ExternalStorageProvider.java, there is a possible permissions bypass. This could lead to local escalation of privilege, allowing an app to read private app directories in external storage, which should be restricted in Android 11, with no additional…

  • CVE-2021-26273HigJul 7, 2021
    risk 0.51cvss 7.8epss 0.00

    The Agent in NinjaRMM 5.0.909 has Incorrect Access Control.

  • CVE-2021-0571HigJun 22, 2021
    risk 0.51cvss 7.8epss 0.00

    In ActivityTaskManagerService.startActivity() and AppTaskImpl.startActivity() of ActivityTaskManagerService.java and AppTaskImpl.java, there is possible access to restricted activities due to a permissions bypass. This could lead to local escalation of privilege with no…

  • CVE-2021-0472HigJun 11, 2021
    risk 0.51cvss 7.8epss 0.00

    In shouldLockKeyguard of LockTaskController.java, there is a possible way to exit App Pinning without a PIN due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-25418HigJun 11, 2021
    risk 0.51cvss 7.8epss 0.00

    Improper component protection vulnerability in Samsung Internet prior to version 14.0.1.62 allows untrusted applications to execute arbitrary activity in specific condition.

  • CVE-2021-31165HigMay 11, 2021
    risk 0.51cvss 7.8epss 0.01

    Windows Container Manager Service Elevation of Privilege Vulnerability

  • CVE-2021-27086HigApr 13, 2021
    risk 0.51cvss 7.8epss 0.01

    Windows Services and Controller App Elevation of Privilege Vulnerability

  • CVE-2021-28791HigMar 18, 2021
    risk 0.51cvss 7.8epss 0.02

    The unofficial SwiftFormat extension before 1.3.7 for Visual Studio Code allows remote attackers to execute arbitrary code by constructing a malicious workspace with a crafted swiftformat.path configuration value that triggers execution upon opening the workspace.

  • CVE-2021-0376HigMar 10, 2021
    risk 0.51cvss 7.8epss 0.00

    In checkUriPermission and related functions of MediaProvider.java, there is a possible way to access external files due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-26026HigJan 26, 2021
    risk 0.51cvss 7.8epss 0.01

    PlugIns\IDE_ACDStd.apl in ACDSee Professional 2021 14.0 1721 has a User Mode Write Access Violation starting at IDE_ACDStd!JPEGTransW+0x000000000000c7f4 via a crafted BMP image.

  • CVE-2021-26025HigJan 26, 2021
    risk 0.51cvss 7.8epss 0.01

    PlugIns\IDE_ACDStd.apl in ACDSee Professional 2021 14.0 1721 has a User Mode Write Access Violation starting at IDE_ACDStd!zlibVersion+0x0000000000004e5e via a crafted BMP image.

  • CVE-2020-9492HigJan 26, 2021
    risk 0.51cvss 8.8epss 0.04

    In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO authorization header to remote URL without proper verification.

  • CVE-2021-0317HigJan 11, 2021
    risk 0.51cvss 7.8epss 0.00

    In createOrUpdate of Permission.java and related code, there is possible permission escalation due to a logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android;…