← Back
CWE-668

717 CVEs • Abstraction: Class

Exposure of Resource to Wrong Sphere

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

JSON object

Loading...

CVEs (717)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Splashtop
1Streamer
Nov 21, 2024
Feb 15, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Splashtop Streamer through 3.4.8.3 creates a Temporary File in a Directory with Insecure Permissions.
1Emerson
1Dixell Xweb 500 Firmware
Nov 21, 2024
Feb 14, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi. An attacker will be able to write any file on the t...Show more
Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi. An attacker will be able to write any file on the target system without any kind of authentication mechanism, and this can lead to denial of service and potentially remote code execution. Note: the product has not been supported since 2018 and should be removed or replacedShow less
1Git Scm
1Git
Nov 21, 2024
Feb 11, 2022
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the "GitBleed" issue. This could present a security risk if information-disclosure auditing processes rely on a...Show more
The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the "GitBleed" issue. This could present a security risk if information-disclosure auditing processes rely on a clone operation without the --mirror option. Note: This has been disputed by multiple 3rd parties who believe this is an intended feature of the git binary and does not pose a security risk.Show less
1Drupal
1Drupal
Nov 21, 2024
Feb 11, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Information Disclosure vulnerability in file module of Drupal Core allows an attacker to gain access to the file metadata of a permanent private file that they do not have access to by guessing the ID of the file. This i...Show more
Information Disclosure vulnerability in file module of Drupal Core allows an attacker to gain access to the file metadata of a permanent private file that they do not have access to by guessing the ID of the file. This issue affects: Drupal Core 8.8.x versions prior to 8.8.10; 8.9.x versions prior to 8.9.6; 9.0.x versions prior to 9.0.6.Show less
1Linux
1Linux Kernel
Nov 21, 2024
Feb 11, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The check_alu_op() function in kernel/bpf/verifier.c in the Linux kernel through v5.16-rc5 did not properly update bounds while handling the mov32 instruction, which allows local users to obtain potentially sensitive add...Show more
The check_alu_op() function in kernel/bpf/verifier.c in the Linux kernel through v5.16-rc5 did not properly update bounds while handling the mov32 instruction, which allows local users to obtain potentially sensitive address information, aka a "pointer leak."Show less
1Intel
382599eb Firmware
82599en Firmware82599es Firmware
May 5, 2025
Feb 9, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Improper isolation of shared resources in network on chip for the Intel(R) 82599 Ethernet Controllers and Adapters may allow an authenticated user to potentially enable denial of service via local access.
1Cybelesoft
1Thinfinity Virtualui
Nov 21, 2024
Feb 9, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Thinfinity VirtualUI 2.1.28.0, 2.1.32.1 and 2.5.26.2, fixed in version 3.0 is affected by an information disclosure vulnerability in the parameter "Addr" in cmd site. The ability to send requests to other systems can all...Show more
Thinfinity VirtualUI 2.1.28.0, 2.1.32.1 and 2.5.26.2, fixed in version 3.0 is affected by an information disclosure vulnerability in the parameter "Addr" in cmd site. The ability to send requests to other systems can allow the vulnerable server to filtrate the real IP of the web server or increase the attack surface.Show less
1Printerlogic
1Web Stack
Nov 21, 2024
Feb 2, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to disclose the username and email address of all...Show more
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to disclose the username and email address of all users.Show less
1Printerlogic
1Web Stack
Nov 21, 2024
Feb 2, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to reassign drivers for any printer.
1Bplugins
1Document Embedder
Nov 21, 2024
Feb 1, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The Document Embedder WordPress plugin before 1.7.9 contains a AJAX action endpoint, which could allow any authenticated user, such as subscriber to enumerate the title of arbitrary private and draft posts.
1Bplugins
1Document Embedder
Nov 21, 2024
Feb 1, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The Document Embedder WordPress plugin before 1.7.5 contains a REST endpoint, which could allow unauthenticated users to enumerate the title of arbitrary private and draft posts.
1Moodle
1Moodle
Nov 21, 2024
Jan 25, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. Insufficient capability checks could lead to users accessing their grade report for courses where the...Show more
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. Insufficient capability checks could lead to users accessing their grade report for courses where they did not have the required gradereport/user:view capability.Show less
1Juniper
1Junos
Nov 21, 2024
Jan 19, 2022
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
In a Junos Fusion scenario an External Control of Critical State Data vulnerability in the Satellite Device (SD) control state machine of Juniper Networks Junos OS allows an attacker who is able to make physical changes...Show more
In a Junos Fusion scenario an External Control of Critical State Data vulnerability in the Satellite Device (SD) control state machine of Juniper Networks Junos OS allows an attacker who is able to make physical changes to the cabling of the device to cause a denial of service (DoS). An SD can get rebooted and subsequently controlled by an Aggregation Device (AD) which does not belong to the original Fusion setup and is just connected to an extended port of the SD. To carry out this attack the attacker needs to have physical access to the cabling between the SD and the original AD. This issue affects: Juniper Networks Junos OS 16.1R1 and later versions prior to 18.4R3-S10; 19.1 versions prior to 19.1R3-S7; 19.2 versions prior to 19.2R3-S4. This issue does not affect Juniper Networks Junos OS versions prior to 16.1R1.Show less
1Cyberark
1Endpoint Privilege Manager
Nov 21, 2024
Jan 15, 2022
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
CyberArk Endpoint Privilege Manager (EPM) through 11.5.3.328 before 2021-12-20 allows a local user to gain elevated privileges via a Trojan horse Procmon64.exe in the user's Temp directory.
1Google
1Android
Nov 21, 2024
Jan 14, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
In StatusBar.java, there is a possible disclosure of notification content on the lockscreen due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed...Show more
In StatusBar.java, there is a possible disclosure of notification content on the lockscreen due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-189575031Show less
1Jenkins
1Debian Package Builder
Nov 21, 2024
Jan 12, 2022
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Jenkins Debian Package Builder Plugin 1.6.11 and earlier implements functionality that allows agents to invoke command-line `git` at an attacker-specified path on the controller, allowing attackers able to control agent...Show more
Jenkins Debian Package Builder Plugin 1.6.11 and earlier implements functionality that allows agents to invoke command-line `git` at an attacker-specified path on the controller, allowing attackers able to control agent processes to invoke arbitrary OS commands on the controller.Show less
1Microsoft
1Windows 10
Nov 21, 2024
Jan 11, 2022
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
Remote Desktop Licensing Diagnoser Information Disclosure Vulnerability
1Fastlinemedia
1Beaver Themer
Nov 21, 2024
Jan 10, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In Beaver Themer, attackers can bypass conditional logic controls (for hiding content) when viewing the post archives. Exploitation requires that a Themer layout is applied to the archives, and that the post excerpt fiel...Show more
In Beaver Themer, attackers can bypass conditional logic controls (for hiding content) when viewing the post archives. Exploitation requires that a Themer layout is applied to the archives, and that the post excerpt field is not set.Show less
1Huawei
1Harmonyos
Nov 21, 2024
Jan 3, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Password vault has a External Control of System or Configuration Setting vulnerability.Successful exploitation of this vulnerability could compromise confidentiality.
1Huawei
1Harmonyos
Nov 21, 2024
Jan 3, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Hisuite module has a External Control of System or Configuration Setting vulnerability.Successful exploitation of this vulnerability may lead to Firmware leak.