Vulnerabilities > Missing Authorization

DATE CVE VULNERABILITY TITLE RISK
2017-04-25 CVE-2017-8217 Missing Authorization vulnerability in Tp-Link C20I Firmware and C2 Firmware
TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n have too permissive iptables rules, e.g., SNMP is not blocked on any interface.
network
low complexity
tp-link CWE-862
5.3
2017-04-10 CVE-2017-7622 Missing Authorization vulnerability in Deepin Desktop Environment
dde-daemon, the daemon process of DDE (Deepin Desktop Environment) 15.0 through 15.3, runs with root privileges and hardly does anything to identify the user who calls the function through D-Bus.
network
low complexity
deepin CWE-862
8.8
2017-04-07 CVE-2017-0554 Missing Authorization vulnerability in Google Android
An elevation of privilege vulnerability in the Telephony component could enable a local malicious application to access capabilities outside of its permission levels.
local
low complexity
google CWE-862
7.8
2017-04-07 CVE-2017-6598 Missing Authorization vulnerability in Cisco products
A vulnerability in the debug plug-in functionality of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to execute arbitrary commands, aka Privilege Escalation.
local
low complexity
cisco CWE-862
6.7
2017-03-24 CVE-2017-6369 Missing Authorization vulnerability in Firebirdsql Firebird
Insufficient checks in the UDF subsystem in Firebird 2.5.x before 2.5.7 and 3.0.x before 3.0.2 allow remote authenticated users to execute code by using a 'system' entrypoint from fbudf.so.
network
low complexity
firebirdsql CWE-862
8.8
2017-03-20 CVE-2017-5930 Missing Authorization vulnerability in multiple products
The AliasHandler component in PostfixAdmin before 3.0.2 allows remote authenticated domain admins to delete protected aliases via the delete parameter to delete.php, involving a missing permission check.
network
low complexity
opensuse postfixadmin-project CWE-862
2.7
2017-03-14 CVE-2017-5985 Missing Authorization vulnerability in Linuxcontainers LXC
lxc-user-nic in Linux Containers (LXC) allows local users with a lxc-usernet allocation to create network interfaces on the host and choose the name of those interfaces by leveraging lack of netns ownership check.
local
low complexity
linuxcontainers CWE-862
3.3
2017-02-09 CVE-2017-5180 Missing Authorization vulnerability in Firejail Project Firejail
Firejail before 0.9.44.4 and 0.9.38.x LTS before 0.9.38.8 LTS does not consider the .Xauthority case during its attempt to prevent accessing user files with an euid of zero, which allows local users to conduct sandbox-escape attacks via vectors involving a symlink and the --private option.
local
low complexity
firejail-project CWE-862
8.8
2017-02-09 CVE-2017-3813 Missing Authorization vulnerability in Cisco Anyconnect Secure Mobility Client
A vulnerability in the Start Before Logon (SBL) module of Cisco AnyConnect Secure Mobility Client Software for Windows could allow an unauthenticated, local attacker to open Internet Explorer with the privileges of the SYSTEM user.
local
low complexity
cisco CWE-862
7.8
2017-02-05 CVE-2017-5136 Missing Authorization vulnerability in Sendquick products
An issue was discovered on SendQuick Entera and Avera devices before 2HF16.
network
low complexity
sendquick CWE-862
7.5