CWE-668
717 CVEs • Abstraction: Class
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
CVEs (717)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Vulnerability of kernel raw address leakage in the hang detector module. Successful exploitation of this vulnerability may affect service confidentiality. |
Key management vulnerability on system. Successful exploitation of this vulnerability may affect service availability and integrity. |
Exposure of resource to wrong sphere issue exists in WL-WN531AX2 firmware versions prior to 2023526, which may allow a network-adjacent attacker to use functions originally available after login without logging in. |
The issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, tvOS 16.5, macOS Ventura 13.4. A person with physical access to a device may be able to view contact information...Show more |
XWiki Platform is a generic wiki platform. Starting in version 7.3-milestone-1 and prior to versions 14.4.8, 14.10.6, and 15.1, ny user can call a REST endpoint and obtain the obfuscated passwords, even when the mail obf...Show more |
XWiki Platform is a generic wiki platform. Starting in version 3.5-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, the mail obfuscation configuration was not fully taken into account. While the mail dis...Show more |
1Proofpoint 1Threat Response Auto Pull Nov 21, 2024 Jun 14, 2023 N/A· v4 6.8 MEDIUM· v3 N/A· v2 An information disclosure vulnerability in the faye endpoint in Proofpoint Threat Response / Threat Response Auto-Pull (PTR/TRAP) could be used by an attacker on an adjacent network to obtain credentials to integrated se...Show more |
1Microsoft 8Windows 10 1607 Windows 10 1809Windows 10 21h2+5 moreApr 8, 2025 Jun 14, 2023 N/A· v4 4.7 MEDIUM· v3 N/A· v2 Windows Kernel Information Disclosure Vulnerability |
1Microsoft 4Windows Server 2012 Windows Server 2016Windows Server 2019+1 moreNov 21, 2024 Jun 14, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 DHCP Server Service Information Disclosure Vulnerability |
Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches, an attacker could use the new topics dismissal endpoint to...Show more |
Exposure of resource to wrong sphere in Zoom for Windows and Zoom for MacOS clients before 5.14.10 may allow an authenticated user to potentially enable information disclosure via network access. |
ServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core functionality. Additional Details This issue is present in the following supported ServiceNow r...Show more |
On Unix platforms, the Go runtime does not behave differently when a binary is run with the setuid/setgid bits. This can be dangerous in certain cases, such as when dumping memory state, or assuming the status of standar...Show more |
1Jeecg P3 Biz Chat Project 1Jeecg P3 Biz Chat Jan 7, 2025 Jun 7, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Jeecg P3 Biz Chat 1.0.5 allows remote attackers to read arbitrary files through specific parameters. |
Landscape's server-status page exposed sensitive system information. This data leak included GET requests which contain information to attack and leak further information from the Landscape API. |
1Qualcomm 31Csr8811 Firmware Ipq6000 FirmwareIpq6005 Firmware+28 moreNov 21, 2024 Jun 6, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Information disclosure in Linux Networking Firmware due to unauthorized information leak during side channel analysis. |
1Qualcomm 1859205 Lte Modem Firmware Aqt1000 FirmwareAr8031 Firmware+182 moreNov 21, 2024 Jun 6, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Information disclosure in Kernel due to indirect branch misprediction. |
emoncms v11 and later was discovered to contain an information disclosure vulnerability which allows attackers to obtain the web directory path and other information leaked by the server via a crafted web request. |
Under specific circumstances a WebExtension may have received a <code>jar:file:///</code> URI instead of a <code>moz-extension:///</code> URI during a load request. This leaked directory paths on the user's machine. This...Show more |
Under certain circumstances, a ServiceWorker's offline cache may have leaked to the file system when using private browsing mode. This vulnerability affects Firefox < 111. |