Vulnerabilities (CVE)

Filtered by CWE-284
Total 2377 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-39870 1 Samsung 1 Smartthings 2022-10-11 N/A 7.5 HIGH
Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via PUSH_MESSAGE_RECEIVED broadcast.
CVE-2022-39871 1 Samsung 1 Smartthings 2022-10-11 N/A 7.5 HIGH
Improper access control vulnerability cloudNotificationManager.java in SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcasts.
CVE-2022-39855 1 Google 1 Android 2022-10-11 N/A 4.3 MEDIUM
Improper access control vulnerability in FACM application prior to SMR Oct-2022 Release 1 allows a local attacker to connect arbitrary AP and Bluetooth devices.
CVE-2022-39875 1 Samsung 1 Account 2022-10-11 N/A 4.4 MEDIUM
Improper component protection vulnerability in Samsung Account prior to version 13.5.0 allows attackers to unauthorized logout.
CVE-2022-39851 1 Google 1 Android 2022-10-11 N/A 3.3 LOW
Improper access control vulnerability in CocktailBarService prior to SMR Oct-2022 Release 1 allows local attacker to bind service that require BIND_REMOTEVIEWS permission.
CVE-2022-39849 1 Google 1 Android 2022-10-08 N/A 3.3 LOW
Improper access control in knox_vpn_policy service prior to SMR Oct-2022 Release 1 allows allows unauthorized read of configuration data.
CVE-2022-39850 1 Google 1 Android 2022-10-08 N/A 3.3 LOW
Improper access control in mum_container_policy service prior to SMR Oct-2022 Release 1 allows allows unauthorized read of configuration data.
CVE-2022-39854 2 Google, Samsung 2 Android, Exynos 2022-10-08 N/A 7.8 HIGH
Improper protection in IOMMU prior to SMR Oct-2022 Release 1 allows unauthorized access to secure memory.
CVE-2021-27598 1 Sap 1 Netweaver Application Server Java 2022-10-07 5.0 MEDIUM 5.3 MEDIUM
SAP NetWeaver AS JAVA (Customer Usage Provisioning Servlet), versions - 7.31, 7.40, 7.50, allows an attacker to read some statistical data like product version, traffic, timestamp etc. because of missing authorization check in the servlet.
CVE-2021-40415 1 Reolink 2 Rlc-410w, Rlc-410w Firmware 2022-10-06 6.8 MEDIUM 6.5 MEDIUM
An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. In cgi_check_ability the Format API does not have a specific case, the user permission will default to 7. This will give non-administrative users the possibility to format the SD card and reboot the device.
CVE-2022-36867 1 Samsung 1 Editor Lite 2022-10-01 N/A 5.5 MEDIUM
Improper access control vulnerability in Editor Lite prior to version 4.0.40.14 allows attackers to access sensitive information.
CVE-2022-36869 1 Samsung 1 Contacts Provider 2022-10-01 N/A 6.1 MEDIUM
Improper access control vulnerability in ContactsDumpActivity of?Contacts Provider prior to version 12.7.59 allows attacker to access the file without permission.
CVE-2022-3263 1 Measuresoft 1 Scadapro Server 2022-09-27 N/A 7.8 HIGH
The security descriptor of Measuresoft ScadaPro Server version 6.7 has inconsistent permissions, which could allow a local user with limited privileges to modify the service binary path and start malicious commands with SYSTEM privileges.
CVE-2022-32226 1 Rocket.chat 1 Rocket.chat 2022-09-27 N/A 4.3 MEDIUM
An improper access control vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 due to input data in the getUsersOfRoom Meteor server method is not type validated, so that MongoDB query operator objects are accepted by the server, so that instead of a matching rid String a$regex query can be executed, bypassing the room access permission check for every but the first matching room.
CVE-2021-25340 1 Google 1 Android 2022-09-23 2.1 LOW 2.4 LOW
Improper access control vulnerability in Samsung keyboard version prior to SMR Feb-2021 Release 1 allows physically proximate attackers to change in arbitrary settings during Initialization State.
CVE-2021-25446 1 Samsung 2 Smartthings, Smartthings Firmware 2022-09-23 5.0 MEDIUM 5.3 MEDIUM
Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause arbitrary webpage loading in webview.
CVE-2021-25447 1 Samsung 2 Smartthings, Smartthings Firmware 2022-09-23 5.0 MEDIUM 5.3 MEDIUM
Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause local file inclusion in webview.
CVE-2021-25448 1 Samsung 1 Smart Touch Call 2022-09-23 5.0 MEDIUM 5.3 MEDIUM
Improper access control vulnerability in Smart Touch Call prior to version 1.0.0.5 allows arbitrary webpage loading in webview.
CVE-2022-36851 1 Samsung 1 Samsung Pass 2022-09-21 N/A 4.6 MEDIUM
Improper access control vulnerability in Samsung pass prior to version 4.0.03.1 allow physical attackers to access data of Samsung pass on a certain state of an unlocked device.
CVE-2022-36865 2 Google, Samsung 2 Android, Group Sharing 2022-09-21 N/A 3.3 LOW
Improper access control in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(11) and below allows attackers to access device information.