CWE-280

Improper Handling of Insufficient Permissions or Privileges

Parent: CWE-755 - Improper Handling of Exceptional Conditions

The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.

155 vulnerabilities with CWE-280
CVE-2024-30418 HIGH
Huawei EMUI and HarmonyOS - Unauthenticated Denial of Service via App Management Module
CVSS 7.5
CVE-2024-29748 HIGH KEV
Android < 2024-04-05 - Local Privilege Escalation via Logic Error
CVSS 7.8
CVE-2024-22078 HIGH
Espec G5 <1.1.4.15 - Privilege Escalation
CVSS 8.8
CVE-2024-22077 MEDIUM
Espec G5 <1.1.4.15 - Info Disclosure
CVSS 5.3
CVE-2024-25844 HIGH
PrestaShop <4.1.26 - Privilege Escalation/Info Disclosure
CVSS 7.5
CVE-2024-0560 MEDIUM
3scale - Improper Handling of Insufficient Permissions or Privileges in Token Introspection Policy
CVSS 6.3
CVE-2024-1608 CRITICAL
OPPO Usercenter Credit SDK - Privilege Escalation via Loose Permission Check
CVSS 9.1
CVE-2024-0015 HIGH
Google Android Intent Redirection - Privilege Escalation
CVSS 7.8
CVE-2024-25108 CRITICAL
Pixelfed 0.10.4-0.11.9 - Insufficient Permission Validation
CVSS 9.9
CVE-2023-38298 HIGH
TCL 30Z A3X 20XE 10L - Unauthenticated IMEI Leak via System Property
CVSS 8.8
CVE-2023-52537 HIGH
Huawei EMUI and HarmonyOS - Improper Access Control in HwIms Module
CVSS 7.5
CVE-2023-42931 HIGH
macOS < Ventura 13.6.3 - Privilege Escalation
CVSS 7.8
CVE-2023-41972 HIGH
Win ZApp <4.3.0.121 - Info Disclosure
CVSS 7.3
CVE-2023-39249 MEDIUM
Dell SupportAssist for Business PCs 3.4.0 - Local Privilege Escalation via Run as Admin Feature
CVSS 6.3
CVE-2023-25543 HIGH
Dell Power Manager < 3.14 - Privilege Escalation via DPM Service
CVSS 7.8
CVE-2023-6189 MEDIUM
M-Files <23.11.13156.0 - Privilege Escalation
CVSS 4.3
CVE-2023-43591 HIGH
Zoom Rooms for macOS <5.16.0 - Privilege Escalation
CVSS 7.8
CVE-2023-43087 MEDIUM
Dell PowerScale OneFS <9.5.0 - Info Disclosure
CVSS 4.3
CVE-2023-32489 MEDIUM
Dell PowerScale OneFS 9.2.1.0-9.2.1.21 and 9.5.0.0-9.5.0.2 - Privilege Escalation via Mode Protection Bypass
CVSS 6.7
CVE-2023-2480 HIGH
M-Files < 23.5.12598.0 - Privilege Escalation via UI Extension Applications
CVSS 7.5
CVE-2023-2020 MEDIUM
Checkmk <= 2.1.0p27 and <= 2.2.0b4 - Unauthorized Downtime Scheduling via REST API
CVSS 4.3
CVE-2023-0181 HIGH
NVIDIA GPU Display Driver - Memory Corruption
CVSS 7.1
CVE-2023-28114 MEDIUM
cilium-cli < 0.13.2 - Permission Enforcement Removal via Incorrect Mount Point
CVSS 4.8
CVE-2023-27087 HIGH
xxl-job 2.2.0-2.3.1 - Unauthenticated Sensitive Information Exposure via pageList Parameter
CVSS 7.5
CVE-2023-21421 MEDIUM
Samsung Android KnoxCustomManagerService - Improper Privilege Management
CVSS 5.9
Details
Vulnerabilities 155