CWE-280

Improper Handling of Insufficient Permissions or Privileges

Parent: CWE-755 - Improper Handling of Exceptional Conditions

The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.

155 vulnerabilities with CWE-280
CVE-2023-22737 MEDIUM
wire-server < 2022-12-09 - Unauthenticated Bot Removal via Missing Permissions Check
CVSS 6.5
CVE-2022-4863 MEDIUM
GitHub usememos/memos <0.9.1 - Info Disclosure
CVSS 6.5
CVE-2022-39912 MEDIUM
Android < 13.0 - Improper Handling of Insufficient Permissions in PersonaManagerService
CVSS 6.2
CVE-2022-39886 MEDIUM
Android - Improper Access Control in IpcRxServiceModeBigDataInfo
CVSS 5.9
CVE-2022-39885 MEDIUM
Android DeviceManagement - Improper Access Control in BootCompletedReceiver_CMCC
CVSS 5.9
CVE-2022-39872 MEDIUM
Samsung ShareLive < 13.2.03.5 - MAC Address Leak via Broadcast Intent
CVSS 5.9
CVE-2022-36874 MEDIUM
Samsung Galaxy Watch Plugin < 2.2.11.22040751 - Unauthorized Device Information Disclosure
CVSS 5.9
CVE-2022-34368 MEDIUM
Dell EMC NetWorker 19.2.1.x-19.7.0.0 - Authenticated Privilege Escalation
CVSS 6.1
CVE-2022-2193 HIGH
HYPR Server <6.14.1 - Code Injection
CVSS 7.5
CVE-2022-30727 MEDIUM
PersonaManagerService <SMR Jun-2022 Release 1 - Info Disclosure
CVSS 6.2
CVE-2022-30725 MEDIUM
Bluetooth <SMR Jun-2022 Release 1 - Info Disclosure
CVSS 4.0
CVE-2022-30724 MEDIUM
Bluetooth <SMR Jun-2022 Release 1 - Info Disclosure
CVSS 4.0
CVE-2022-30723 MEDIUM
Bluetooth <SMR Jun-2022 Release 1 - Info Disclosure
CVSS 4.0
CVE-2022-30716 MEDIUM
Android - Unprotected Toast Message Exposure via DisplayToast Broadcast
CVSS 4.0
CVE-2022-27167 HIGH
ESET Windows Products < 15.1.12.0 - Privilege Escalation via Repair/Uninstall Features
CVSS 7.1
CVE-2022-22292 HIGH
Telecom <SMR Feb-2022 Release 1 - Privilege Escalation
CVSS 7.1
CVE-2022-21814 MEDIUM
NVIDIA GPU Display Driver for Linux - Denial of Service via Improper Permission Handling
CVSS 6.1
CVE-2021-37851 HIGH
ESET Windows Products - Local Privilege Escalation via Installer Repair Feature
CVSS 7.3
CVE-2021-37175 MEDIUM
Siemens RUGGEDCOM ROX Firmware < 2.14.1 - Unauthenticated Directory Traversal
CVSS 5.3
CVE-2021-38312 HIGH
Gutenberg Template Library & Redux Framework <= 4.2.11 - Auth Bypass
CVSS 7.1
CVE-2020-10072 MEDIUM
zephyr >=1.14.2, >=2.2.0 - Privilege Escalation
CVSS 5.9
CVE-2020-29031 HIGH
GateManager < 9.2c - Authenticated Privilege Escalation via Password Reset
CVSS 7.1
CVE-2020-26195 MEDIUM
Dell EMC PowerScale OneFS 8.1.2-9.1.0 - Unauthenticated Denial of Service via SMB Directory Auto-Create
CVSS 5.3
CVE-2020-3427 MEDIUM
Windows Logon <4.1.2 - Privilege Escalation
CVSS 6.6
CVE-2020-8219 HIGH
Pulse Connect Secure <9.1R8 - Privilege Escalation
CVSS 7.2
Details
Vulnerabilities 155