← Back
CWE-668

717 CVEs • Abstraction: Class

Exposure of Resource to Wrong Sphere

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

JSON object

Loading...

CVEs (717)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Huawei
2Emui
Harmonyos
Nov 21, 2024
Jul 6, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Vulnerability of kernel raw address leakage in the hang detector module. Successful exploitation of this vulnerability may affect service confidentiality.
1Huawei
2Emui
Harmonyos
Nov 21, 2024
Jul 5, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Key management vulnerability on system. Successful exploitation of this vulnerability may affect service availability and integrity.
1Wavlink
1Wl Wn531ax2 Firmware
Nov 21, 2024
Jun 30, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
Exposure of resource to wrong sphere issue exists in WL-WN531AX2 firmware versions prior to 2023526, which may allow a network-adjacent attacker to use functions originally available after login without logging in.
1Apple
5Ipados
Iphone OsMacos+2 more
Nov 21, 2024
Jun 23, 2023
N/A· v4
2.4 LOW· v3
N/A· v2
The issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, tvOS 16.5, macOS Ventura 13.4. A person with physical access to a device may be able to view contact information...Show more
The issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, tvOS 16.5, macOS Ventura 13.4. A person with physical access to a device may be able to view contact information from the lock screen.Show less
1Xwiki
1Xwiki
Nov 21, 2024
Jun 23, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
XWiki Platform is a generic wiki platform. Starting in version 7.3-milestone-1 and prior to versions 14.4.8, 14.10.6, and 15.1, ny user can call a REST endpoint and obtain the obfuscated passwords, even when the mail obf...Show more
XWiki Platform is a generic wiki platform. Starting in version 7.3-milestone-1 and prior to versions 14.4.8, 14.10.6, and 15.1, ny user can call a REST endpoint and obtain the obfuscated passwords, even when the mail obfuscation is activated. The issue has been patched in XWiki 14.4.8, 14.10.6, and 15.1. There is no known workaround.Show less
1Xwiki
1Xwiki
Nov 21, 2024
Jun 23, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
XWiki Platform is a generic wiki platform. Starting in version 3.5-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, the mail obfuscation configuration was not fully taken into account. While the mail dis...Show more
XWiki Platform is a generic wiki platform. Starting in version 3.5-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, the mail obfuscation configuration was not fully taken into account. While the mail displayed to the end user was obfuscated, the rest response was also containing the mail unobfuscated and users were able to filter and sort on the unobfuscated, allowing them to infer the mail content. The consequence was the possibility to retrieve the email addresses of all users even when obfuscated. This has been patched in XWiki 14.4.8, 14.10.4, and 15.0-rc-1.Show less
1Proofpoint
1Threat Response Auto Pull
Nov 21, 2024
Jun 14, 2023
N/A· v4
6.8 MEDIUM· v3
N/A· v2
An information disclosure vulnerability in the faye endpoint in Proofpoint Threat Response / Threat Response Auto-Pull (PTR/TRAP) could be used by an attacker on an adjacent network to obtain credentials to integrated se...Show more
An information disclosure vulnerability in the faye endpoint in Proofpoint Threat Response / Threat Response Auto-Pull (PTR/TRAP) could be used by an attacker on an adjacent network to obtain credentials to integrated services via a man-in-the-middle position or cryptanalysis of the session traffic. An attacker could use these credentials to impersonate PTR/TRAP to these services. All versions prior to 5.10.0 are affected.  Show less
1Microsoft
8Windows 10 1607
Windows 10 1809Windows 10 21h2+5 more
Apr 8, 2025
Jun 14, 2023
N/A· v4
4.7 MEDIUM· v3
N/A· v2
Windows Kernel Information Disclosure Vulnerability
1Microsoft
4Windows Server 2012
Windows Server 2016Windows Server 2019+1 more
Nov 21, 2024
Jun 14, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
DHCP Server Service Information Disclosure Vulnerability
1Discourse
1Discourse
Nov 21, 2024
Jun 13, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches, an attacker could use the new topics dismissal endpoint to...Show more
Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches, an attacker could use the new topics dismissal endpoint to reveal the number of topics recently created (but not the actual content thereof) in categories they didn't have access to. This issue is patched in version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches. There are no known workarounds.Show less
1Zoom
1Zoom
Nov 21, 2024
Jun 13, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Exposure of resource to wrong sphere in Zoom for Windows and Zoom for MacOS clients before 5.14.10 may allow an authenticated user to potentially enable information disclosure via network access.
1Servicenow
1Servicenow
Feb 13, 2025
Jun 13, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
ServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core functionality. Additional Details This issue is present in the following supported ServiceNow r...Show more
ServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core functionality. Additional Details This issue is present in the following supported ServiceNow releases: * Quebec prior to Patch 10 Hot Fix 8b * Rome prior to Patch 10 Hot Fix 1 * San Diego prior to Patch 7 * Tokyo prior to Tokyo Patch 1; and * Utah prior to Utah General Availability If this ACL bypass issue were to be successfully exploited, it potentially could allow an authenticated user to obtain sensitive information from tables missing authorization controls.Show less
2Fedoraproject
Golang
2Fedora
Go
Jan 6, 2025
Jun 8, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
On Unix platforms, the Go runtime does not behave differently when a binary is run with the setuid/setgid bits. This can be dangerous in certain cases, such as when dumping memory state, or assuming the status of standar...Show more
On Unix platforms, the Go runtime does not behave differently when a binary is run with the setuid/setgid bits. This can be dangerous in certain cases, such as when dumping memory state, or assuming the status of standard i/o file descriptors. If a setuid/setgid binary is executed with standard I/O file descriptors closed, opening any files can result in unexpected content being read or written with elevated privileges. Similarly, if a setuid/setgid program is terminated, either via panic or signal, it may leak the contents of its registers.Show less
1Jeecg P3 Biz Chat Project
1Jeecg P3 Biz Chat
Jan 7, 2025
Jun 7, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Jeecg P3 Biz Chat 1.0.5 allows remote attackers to read arbitrary files through specific parameters.
1Canonical
1Landscape
Nov 21, 2024
Jun 6, 2023
N/A· v4
8.2 HIGH· v3
N/A· v2
Landscape's server-status page exposed sensitive system information. This data leak included GET requests which contain information to attack and leak further information from the Landscape API.
1Qualcomm
31Csr8811 Firmware
Ipq6000 FirmwareIpq6005 Firmware+28 more
Nov 21, 2024
Jun 6, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Information disclosure in Linux Networking Firmware due to unauthorized information leak during side channel analysis.
1Qualcomm
1859205 Lte Modem Firmware
Aqt1000 FirmwareAr8031 Firmware+182 more
Nov 21, 2024
Jun 6, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Information disclosure in Kernel due to indirect branch misprediction.
1Emoncms
1Emoncms
Jan 8, 2025
Jun 5, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
emoncms v11 and later was discovered to contain an information disclosure vulnerability which allows attackers to obtain the web directory path and other information leaked by the server via a crafted web request.
1Mozilla
2Firefox
Focus
Nov 21, 2024
Jun 2, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Under specific circumstances a WebExtension may have received a <code>jar:file:///</code> URI instead of a <code>moz-extension:///</code> URI during a load request. This leaked directory paths on the user's machine. This...Show more
Under specific circumstances a WebExtension may have received a <code>jar:file:///</code> URI instead of a <code>moz-extension:///</code> URI during a load request. This leaked directory paths on the user's machine. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.Show less
1Mozilla
1Firefox
Jan 9, 2025
Jun 2, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Under certain circumstances, a ServiceWorker's offline cache may have leaked to the file system when using private browsing mode. This vulnerability affects Firefox < 111.