CWE-939
24 CVEs • Abstraction: Base
Improper Authorization in Handler for Custom URL Scheme
The product uses a handler for a custom URL scheme, but it does not properly restrict which actors can invoke the handler using the scheme.
CVEs (24)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Zoom 4Meetings RoomsVirtual Desktop Infrastructure+1 moreJun 17, 2026 Nov 15, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access. |
1Cisco 1Appdynamics Controller Jun 17, 2026 Jun 15, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco AppDynamics Controller Software could allow an unauthenticated, remote attacker to access a configuration file and the login page for an administrative conso...Show more |
Due to a Missing Authorization weakness and Insufficient Granularity of Access Control in a specific device configuration, a vulnerability exists in Juniper Networks Junos OS on SRX Series whereby an attacker who attempt...Show more |
1Greenbrowser Project 1Greenbrowser Jun 17, 2026 Apr 8, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 GreenBrowser before version 1.2 has a vulnerability where apps that rely on URL Parsing to verify that a given URL is pointing to a trust server may be susceptible to many different ways to get URL parsing and verificati...Show more |