CWE-939
28 CVEs • Abstraction: Base
Improper Authorization in Handler for Custom URL Scheme
The product uses a handler for a custom URL scheme, but it does not properly restrict which actors can invoke the handler using the scheme.
CVEs (28)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Improper authorization in handler for custom URL scheme issue in "@cosme" App for Android versions prior 5.69.0 and "@cosme" App for iOS versions prior to 6.74.0 allows an attacker to lead a user to access an arbitrary w...Show more |
'Rakuten Ichiba App' for Android 12.4.0 and earlier and 'Rakuten Ichiba App' for iOS 11.7.0 and earlier are vulnerable to improper authorization in handler for custom URL scheme. An arbitrary site may be displayed on the...Show more |
Improper authorization in handler for custom URL scheme issue in 'ZOZOTOWN' App for Android versions prior to 7.39.6 allows an attacker to lead a user to access an arbitrary website via another application installed on t...Show more |
An attacker could retrieve sensitive files (medical images) as well as plant new medical images or overwrite existing medical images on a MicroDicom DICOM Viewer system. User interaction is required to exploit this vulne...Show more |
1Zoom 4Meetings RoomsVirtual Desktop Infrastructure+1 moreJun 17, 2026 Nov 15, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access. |
1Cisco 1Appdynamics Controller Jun 17, 2026 Jun 15, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco AppDynamics Controller Software could allow an unauthenticated, remote attacker to access a configuration file and the login page for an administrative conso...Show more |
Due to a Missing Authorization weakness and Insufficient Granularity of Access Control in a specific device configuration, a vulnerability exists in Juniper Networks Junos OS on SRX Series whereby an attacker who attempt...Show more |
1Greenbrowser Project 1Greenbrowser Jun 17, 2026 Apr 8, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 GreenBrowser before version 1.2 has a vulnerability where apps that rely on URL Parsing to verify that a given URL is pointing to a trust server may be susceptible to many different ways to get URL parsing and verificati...Show more |