CWE-668
717 CVEs • Abstraction: Class
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
CVEs (717)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Boxstarter installer before version 2.13.0 configures C:\ProgramData\Boxstarter to be in the system-wide PATH environment variable. However, this directory is writable by normal, unprivileged users. To exploit the vu...Show more |
ARC Informatique PcVue prior to version 12.0.17 is vulnerable to a denial-of-service attack due to the ability of an unauthorized user to modify information used to validate messages sent by legitimate web clients. This...Show more |
An issue was discovered in EthernetNetwork on Samsung mobile devices with O(8.1), P(9.0), Q(10.0), and R(11.0) software. PendingIntent allows sdcard access by an unprivileged process. The Samsung ID is SVE-2020-18392 (Oc...Show more |
An issue has been discovered in GitLab affecting all versions starting from 11.2. Unauthorized Users Can View Custom Project Template |
Electron before versions 11.0.0-beta.6, 10.1.2, 9.3.1 or 8.5.2 is vulnerable to a context isolation bypass. Apps using both `contextIsolation` and `sandbox: true` are affected. Apps using both `contextIsolation` and `nod...Show more |
1Cloud Foundry 1Bosh System Metrics Server Nov 21, 2024 Oct 2, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 BOSH System Metrics Server releases prior to 0.1.0 exposed the UAA password as a flag to a process running on the BOSH director. It exposed the password to any user or process with access to the same VM (through ps or lo...Show more |
1Philips 1Clinical Collaboration Platform Jun 4, 2025 Sep 18, 2020 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 Philips Clinical Collaboration Platform, Versions 12.2.1 and prior,
exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource. |
2Opensuse Sylabs2Leap SingularityNov 21, 2024 Sep 16, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Sylabs Singularity through 3.6.2 has Insecure Permissions on temporary directories used in explicit and implicit container build operations, a different vulnerability than CVE-2020-25039. |
2Opensuse Sylabs2Leap SingularityNov 21, 2024 Sep 16, 2020 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 Sylabs Singularity 3.2.0 through 3.6.2 has Insecure Permissions on temporary directories used in fakeroot or user namespace container execution. |
1Philips 1Patient Information Center Ix Nov 21, 2024 Sep 11, 2020 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 In Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, the product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource. The application on th...Show more |
1Dell 1Emc Elastic Cloud Storage Nov 21, 2024 Sep 2, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Dell EMC ECS, versions prior to 3.5, contains an Exposure of Resource vulnerability. A remote unauthenticated attacker can access the list of DT (Directory Table) objects of all internally running services and gain knowl...Show more |
FreedomBox through 20.13 allows remote attackers to obtain sensitive information from the /server-status page of the Apache HTTP Server, because a connection from the Tor onion service (or from PageKite) is considered a...Show more |
2Apache Netapp2Cassandra Oncommand InsightNov 21, 2024 Sep 1, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI reg...Show more |
The flash memory readout protection in Gigadevice GD32F103 devices allows physical attackers to extract firmware via the debug interface by utilizing the DMA module. |
1Gigadevice 2Gd32f103 Firmware Gd32f130 FirmwareNov 21, 2024 Aug 31, 2020 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 Gigadevice GD32F103 and GD32F130 devices allow physical attackers to extract data via the probing of easily accessible bonding wires and de-obfuscation of the observed data. |
1Gigadevice 1Gd32vf103 Firmware Nov 21, 2024 Aug 31, 2020 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 The flash memory readout protection in Gigadevice GD32VF103 devices allows physical attackers to extract firmware via the debug interface by utilizing the CPU. |
It was discovered that snapctl user-open allowed altering the $XDG_DATA_DIRS environment variable when calling the system xdg-open. OpenURL() in usersession/userd/launcher.go would alter $XDG_DATA_DIRS to append a path t...Show more |
In Western Digital WD Discovery before 4.0.251.0, a malicious application running with standard user permissions could potentially execute code in the application's process through library injection by using DYLD environ...Show more |
IceWarp Email Server 12.3.0.1 has Incorrect Access Control for user accounts. |
1Baxter 2Em1200 Firmware Em2400 FirmwareNov 21, 2024 Jun 29, 2020 N/A· v4 6.1 MEDIUM· v3 3.6 LOW· v2 Baxter ExactaMix EM 2400 Versions 1.10, 1.11, and 1.13 and ExactaMix EM1200 Versions 1.1, 1.2, and 1.4 does not restrict non administrative users from gaining access to the operating system and editing the application st...Show more |