← Back
CWE-863

3,038 CVEs • Abstraction: Class • Likelihood of Exploit: High

Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.

JSON object

Loading...

CVEs (3,038)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Google
Opensuse
2Chrome
Opensuse
Apr 29, 2026
Feb 23, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly enforce a user gesture requirement before proceeding with a file download, which might make it easier for rem...Show more
Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly enforce a user gesture requirement before proceeding with a file download, which might make it easier for remote attackers to execute arbitrary code via a crafted file.Show less
1Cisco
1Carrier Routing System
Apr 29, 2026
Aug 6, 2012
N/A· v4
5.8 MEDIUM· v3
5.0 MEDIUM· v2
Cisco Carrier Routing System (CRS) 3.9, 4.0, and 4.1 allows remote attackers to bypass ACL entries via fragmented packets, aka Bug ID CSCtj10975.
1Ibm
1Rational System Architect
Apr 29, 2026
May 5, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
The ActiveBar1 ActiveX control in the Data Dynamics ActiveBar ActiveX controls, as distributed in ActBar.ocx 1.0.6.5 in IBM Rational System Architect 11.4.0.2, 11.4.0.1, and earlier, does not properly restrict the SetLay...Show more
The ActiveBar1 ActiveX control in the Data Dynamics ActiveBar ActiveX controls, as distributed in ActBar.ocx 1.0.6.5 in IBM Rational System Architect 11.4.0.2, 11.4.0.1, and earlier, does not properly restrict the SetLayoutData method, which allows remote attackers to execute arbitrary code via a crafted Data argument, a different vulnerability than CVE-2007-3883. NOTE: some of these details are obtained from third party information.Show less
1Google
1Chrome
Apr 29, 2026
Mar 1, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Google Chrome before 9.0.597.107 does not properly restrict access to internal extension functions, which has unspecified impact and remote attack vectors.
1Vmware
4Fusion
PlayerServer+1 more
Apr 29, 2026
Dec 6, 2010
N/A· v4
N/A· v3
7.2 HIGH· v2
vmware-mount in VMware Workstation 7.x before 7.1.2 build 301548 on Linux, VMware Player 3.1.x before 3.1.2 build 301548 on Linux, VMware Server 2.0.2 on Linux, and VMware Fusion 3.1.x before 3.1.2 build 332101 does not...Show more
vmware-mount in VMware Workstation 7.x before 7.1.2 build 301548 on Linux, VMware Player 3.1.x before 3.1.2 build 301548 on Linux, VMware Server 2.0.2 on Linux, and VMware Fusion 3.1.x before 3.1.2 build 332101 does not properly load libraries, which allows host OS users to gain privileges via vectors involving shared object files.Show less
2Rockwellautomation
Windriver
21756 Enbt/a Firmware
Vxworks
May 28, 2026
Aug 5, 2010
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on the Rockwell Automation 1756-ENBT series A with firmware 3.2.6 and 3.6.1 and other products, allows remote attackers to read or m...Show more
The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on the Rockwell Automation 1756-ENBT series A with firmware 3.2.6 and 3.6.1 and other products, allows remote attackers to read or modify arbitrary memory locations, perform function calls, or manage tasks via requests to UDP port 17185, a related issue to CVE-2005-3804.Show less
1Kyoceramita
1Scanner File Utility
Apr 23, 2026
Aug 28, 2009
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 allows remote attackers to bypass authorization and upload arbitrary files to the client system via a modified program that does not prompt the user fo...Show more
The Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 allows remote attackers to bypass authorization and upload arbitrary files to the client system via a modified program that does not prompt the user for a password.Show less
1Citrix
2Netscaler Access Gateway
Netscaler Access Gateway Firmware
Apr 23, 2026
Jun 25, 2009
N/A· v4
6.5 MEDIUM· v3
6.3 MEDIUM· v2
The default configuration of the Security global settings on the Citrix NetScaler Access Gateway appliance with Enterprise Edition firmware 9.0, 8.1, and earlier specifies Allow for the Default Authorization Action optio...Show more
The default configuration of the Security global settings on the Citrix NetScaler Access Gateway appliance with Enterprise Edition firmware 9.0, 8.1, and earlier specifies Allow for the Default Authorization Action option, which might allow remote authenticated users to bypass intended access restrictions.Show less
4Net Snmp
OpensuseRedhat+1 more
4Enterprise Linux
Linux EnterpriseNet Snmp+1 more
Apr 23, 2026
Feb 12, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The netsnmp_udp_fmtaddr function (snmplib/snmpUDPDomain.c) in net-snmp 5.0.9 through 5.4.2.1, when using TCP wrappers for client authorization, does not properly parse hosts.allow rules, which allows remote attackers to...Show more
The netsnmp_udp_fmtaddr function (snmplib/snmpUDPDomain.c) in net-snmp 5.0.9 through 5.4.2.1, when using TCP wrappers for client authorization, does not properly parse hosts.allow rules, which allows remote attackers to bypass intended access restrictions and execute SNMP queries, related to "source/destination IP address confusion."Show less
2Gratisoft
Vmware
2Esx
Sudo
Apr 23, 2026
Jan 30, 2009
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to lever...Show more
parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain root privileges via a sudo command.Show less
4Canonical
DovecotFedoraproject+1 more
4Dovecot
FedoraOpensuse+1 more
Apr 23, 2026
Oct 15, 2008
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass intended access restrictions.
2Condor Project
Fedoraproject
2Condor
Fedora
Apr 23, 2026
Jul 31, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Condor before 7.0.4 does not properly handle wildcards in the ALLOW_WRITE, DENY_WRITE, HOSTALLOW_WRITE, or HOSTDENY_WRITE configuration variables in authorization policy lists, which might allow remote attackers to bypas...Show more
Condor before 7.0.4 does not properly handle wildcards in the ALLOW_WRITE, DENY_WRITE, HOSTALLOW_WRITE, or HOSTDENY_WRITE configuration variables in authorization policy lists, which might allow remote attackers to bypass intended access restrictions.Show less
4Fedoraproject
FreedesktopMandrakesoft+1 more
4Dbus
Enterprise LinuxFedora+1 more
Apr 23, 2026
Feb 29, 2008
N/A· v4
N/A· v3
4.6 MEDIUM· v2
dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_interface attributes in allow directives in the security policy only for fully qualified method calls, which allows local users to bypass intend...Show more
dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_interface attributes in allow directives in the security policy only for fully qualified method calls, which allows local users to bypass intended access restrictions via a method call with a NULL interface.Show less
1Dirlist
1Dirlist Php
Apr 23, 2026
Jul 25, 2007
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
index.php in dirLIST before 0.1.1 allows remote attackers to list the contents of an excluded folder via a modified URL containing the folder name.
1Cisco
1Ios
Apr 23, 2026
May 10, 2007
N/A· v4
N/A· v3
9.3 HIGH· v2
The FTP Server in Cisco IOS 11.3 through 12.4 does not properly check user authorization, which allows remote attackers to execute arbitrary code, and have other impact including reading startup-config, as demonstrated b...Show more
The FTP Server in Cisco IOS 11.3 through 12.4 does not properly check user authorization, which allows remote attackers to execute arbitrary code, and have other impact including reading startup-config, as demonstrated by a crafted MKD command that involves access to a VTY device and overflows a buffer, aka bug ID CSCek55259.Show less
1Chetcpasswd Project
1Chetcpasswd
Apr 23, 2026
Dec 21, 2006
N/A· v4
7.5 HIGH· v3
7.5 HIGH· v2
Pedro Lineu Orso chetcpasswd before 2.4 relies on the X-Forwarded-For HTTP header when verifying a client's status on an IP address ACL, which allows remote attackers to gain unauthorized access by spoofing this header.
1Raritan
5Dominion Sx16 Firmware
Dominion Sx32 FirmwareDominion Sx4 Firmware+2 more
Apr 16, 2026
Jul 5, 2005
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Raritan Dominion SX (DSX) Console Servers DSX16, DSX32, DSX4, DSX8, and DSXA-48 set (1) world-readable permissions for /etc/shadow and (2) world-writable permissions for /bin/busybox, which allows local users to obtain h...Show more
Raritan Dominion SX (DSX) Console Servers DSX16, DSX32, DSX4, DSX8, and DSXA-48 set (1) world-readable permissions for /etc/shadow and (2) world-writable permissions for /bin/busybox, which allows local users to obtain hashed passwords or execute arbitrary code as other users.Show less
1Freebsd
1Freebsd
Apr 16, 2026
Aug 23, 2001
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TCP Wrappers (tcp_wrappers) in FreeBSD 4.1.1 through 4.3 with the PARANOID ACL option enabled does not properly check the result of a reverse DNS lookup, which could allow remote attackers to bypass intended access restr...Show more
TCP Wrappers (tcp_wrappers) in FreeBSD 4.1.1 through 4.3 with the PARANOID ACL option enabled does not properly check the result of a reverse DNS lookup, which could allow remote attackers to bypass intended access restrictions via DNS spoofing.Show less