CWE-863
3,308 CVEs • Abstraction: Class • Likelihood of Exploit: High
Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVEs (3,308)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DovecotFedoraproject+1 more4Dovecot FedoraOpensuse+1 moreApr 23, 2026 Oct 15, 2008 N/A· v4 7.5 HIGH· v3 6.4 MEDIUM· v2 The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass intended access restrictions. |
2Condor Project Fedoraproject2Condor FedoraApr 23, 2026 Jul 31, 2008 N/A· v4 N/A· v3 7.5 HIGH· v2 Condor before 7.0.4 does not properly handle wildcards in the ALLOW_WRITE, DENY_WRITE, HOSTALLOW_WRITE, or HOSTDENY_WRITE configuration variables in authorization policy lists, which might allow remote attackers to bypas...Show more |
4Fedoraproject FreedesktopMandrakesoft+1 more4Dbus Enterprise LinuxFedora+1 moreApr 23, 2026 Feb 29, 2008 N/A· v4 N/A· v3 4.6 MEDIUM· v2 dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_interface attributes in allow directives in the security policy only for fully qualified method calls, which allows local users to bypass intend...Show more |
index.php in dirLIST before 0.1.1 allows remote attackers to list the contents of an excluded folder via a modified URL containing the folder name. |
The FTP Server in Cisco IOS 11.3 through 12.4 does not properly check user authorization, which allows remote attackers to execute arbitrary code, and have other impact including reading startup-config, as demonstrated b...Show more |
1Chetcpasswd Project 1Chetcpasswd Apr 23, 2026 Dec 21, 2006 N/A· v4 7.5 HIGH· v3 7.5 HIGH· v2 Pedro Lineu Orso chetcpasswd before 2.4 relies on the X-Forwarded-For HTTP header when verifying a client's status on an IP address ACL, which allows remote attackers to gain unauthorized access by spoofing this header. |
1Raritan 5Dominion Sx16 Firmware Dominion Sx32 FirmwareDominion Sx4 Firmware+2 moreApr 16, 2026 Jul 5, 2005 N/A· v4 N/A· v3 4.6 MEDIUM· v2 Raritan Dominion SX (DSX) Console Servers DSX16, DSX32, DSX4, DSX8, and DSXA-48 set (1) world-readable permissions for /etc/shadow and (2) world-writable permissions for /bin/busybox, which allows local users to obtain h...Show more |
TCP Wrappers (tcp_wrappers) in FreeBSD 4.1.1 through 4.3 with the PARANOID ACL option enabled does not properly check the result of a reverse DNS lookup, which could allow remote attackers to bypass intended access restr...Show more |