Skip to main content

CWE archive

CWE-862 CVEs

Programmatic archive

9,119 CVEs tagged with CWE-862479 Critical, 2,091 High, 6,248 Medium, 300 Low, 1 Unrated.

CVE-2020-26818

Published Nov 10, 2020

SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro components, which reveals sensitive s…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-0454

Published Nov 10, 2020

In callCallbackForRequest of ConnectivityService.java, there is a possible permission bypass due to a missing permission check. This could lead to local information disclosure of…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-0448

Published Nov 10, 2020

In getPhoneAccountsForPackage of TelecomServiceImpl.java, there is a possible way to access a tracking identifier due to a missing permission check. This could lead to local infor…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-0439

Published Nov 10, 2020

In generatePackageInfo of PackageManagerService.java, there is a possible permissions bypass due to an incorrect permission check. This could lead to local escalation of privilege…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-0437

Published Nov 10, 2020

In CellBroadcastReceiver's intent handlers, there is a possible denial of service due to a missing permission check. This could lead to local denial of service of emergency alerts…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2302

Published Nov 4, 2020

A missing permission check in Jenkins Active Directory Plugin 2.19 and earlier allows attackers with Overall/Read permission to access the domain health check diagnostic page.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-27998

Published Oct 29, 2020

An issue was discovered in FastReport before 2020.4.0. It lacks a ScriptSecurity feature and therefore may mishandle (for example) GetType, typeof, TypeOf, DllImport, LoadLibrary,…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-10746

Published Oct 19, 2020

A flaw was found in Infinispan (org.infinispan:infinispan-server-runtime) version 10, where it permits local access to controls via both REST and HotRod APIs. This flaw allows a u…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19885

Published Oct 16, 2020

In Bender COMTRAXX, user authorization is validated for most, but not all, routes in the system. A user with knowledge about the routes can read and write configuration data witho…

CVSS 9.1 · Critical

CVE-2020-14185

Published Oct 15, 2020

Affected versions of Jira Server allow remote unauthenticated attackers to enumerate issue keys via a missing permissions check in the ActionsAndOperations resource. The affected…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-0420

Published Oct 14, 2020

In setUpdatableDriverPath of GpuService.cpp, there is a possible memory corruption due to a missing permission check. This could lead to local escalation of privilege with no addi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-0419

Published Oct 14, 2020

In generateInfo of PackageInstallerSession.java, there is a possible leak of cross-profile URI data during app installation due to a missing permission check. This could lead to l…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-0412

Published Oct 14, 2020

In setProcessMemoryTrimLevel of ActivityManagerService.java, there is a missing permission check. This could lead to local information disclosure of foreground processes with no a…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-0378

Published Oct 14, 2020

In onWnmFrameReceived of PasspointManager.java, there is a missing permission check. This could lead to local information disclosure of location data with User execution privilege…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-0246

Published Oct 14, 2020

In getCarrierPrivilegeStatus of UiccAccessRule.java, there is a missing permission check. This could lead to local information disclosure of EID data with no additional execution…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15251

Published Oct 13, 2020

In the Channelmgnt plug-in for Sopel (a Python IRC bot) before version 1.0.3, malicious users are able to op/voice and take over a channel. This is an ACL bypass vulnerability. Th…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13626

Published Oct 9, 2020

OnePlus App Locker through 2020-10-06 allows physically proximate attackers to use Google Assistant to bypass an authorization check in order to send an SMS message when the SMS a…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26598

Published Oct 6, 2020

An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, and 9.0 software. The Network Management component could allow an unauthorized actor to kill a TCP connectio…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-25781

Published Sep 30, 2020

An issue was discovered in file_download.php in MantisBT before 2.24.3. Users without access to view private issue notes are able to download the (supposedly private) attachments…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13319

Published Sep 30, 2020

An issue has been discovered in GitLab affecting versions prior to 13.1.2, 13.0.8 and 12.10.13. Missing permission check for adding time spent on an issue.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 8,576-8,600 of 9,119 CVEsPage 344 of 365