CWE-668
730 CVEs • Abstraction: Class
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
CVEs (730)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Opensuse Sylabs2Leap SingularityJun 17, 2026 Sep 16, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Sylabs Singularity through 3.6.2 has Insecure Permissions on temporary directories used in explicit and implicit container build operations, a different vulnerability than CVE-2020-25039. |
2Opensuse Sylabs2Leap SingularityJun 17, 2026 Sep 16, 2020 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 Sylabs Singularity 3.2.0 through 3.6.2 has Insecure Permissions on temporary directories used in fakeroot or user namespace container execution. |
1Philips 1Patient Information Center Ix Jun 17, 2026 Sep 11, 2020 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 In Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, the product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource. The application on th...Show more |
1Dell 1Emc Elastic Cloud Storage Jun 17, 2026 Sep 2, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Dell EMC ECS, versions prior to 3.5, contains an Exposure of Resource vulnerability. A remote unauthenticated attacker can access the list of DT (Directory Table) objects of all internally running services and gain knowl...Show more |
FreedomBox through 20.13 allows remote attackers to obtain sensitive information from the /server-status page of the Apache HTTP Server, because a connection from the Tor onion service (or from PageKite) is considered a...Show more |
2Apache Netapp2Cassandra Oncommand InsightJun 17, 2026 Sep 1, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI reg...Show more |
The flash memory readout protection in Gigadevice GD32F103 devices allows physical attackers to extract firmware via the debug interface by utilizing the DMA module. |
1Gigadevice 2Gd32f103 Firmware Gd32f130 FirmwareJun 17, 2026 Aug 31, 2020 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 Gigadevice GD32F103 and GD32F130 devices allow physical attackers to extract data via the probing of easily accessible bonding wires and de-obfuscation of the observed data. |
1Gigadevice 1Gd32vf103 Firmware Jun 17, 2026 Aug 31, 2020 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 The flash memory readout protection in Gigadevice GD32VF103 devices allows physical attackers to extract firmware via the debug interface by utilizing the CPU. |
It was discovered that snapctl user-open allowed altering the $XDG_DATA_DIRS environment variable when calling the system xdg-open. OpenURL() in usersession/userd/launcher.go would alter $XDG_DATA_DIRS to append a path t...Show more |
In Western Digital WD Discovery before 4.0.251.0, a malicious application running with standard user permissions could potentially execute code in the application's process through library injection by using DYLD environ...Show more |
IceWarp Email Server 12.3.0.1 has Incorrect Access Control for user accounts. |
1Baxter 2Em1200 Firmware Em2400 FirmwareJun 17, 2026 Jun 29, 2020 N/A· v4 6.1 MEDIUM· v3 3.6 LOW· v2 Baxter ExactaMix EM 2400 Versions 1.10, 1.11, and 1.13 and ExactaMix EM1200 Versions 1.1, 1.2, and 1.4 does not restrict non administrative users from gaining access to the operating system and editing the application st...Show more |
4Aliasrobotics Enabled RoboticsMobile Industrial Robotics+1 more10Er Flex Firmware Er Lite FirmwareEr One Firmware+7 moreJun 17, 2026 Jun 24, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 MiR100, MiR200 and other MiR robots use the Robot Operating System (ROS) default packages exposing the computational graph to all network interfaces, wireless and wired. This is the result of a bad set up and can be miti...Show more |
1Mattermost 1Mattermost Packages Jun 17, 2026 Jun 19, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Mattermost Packages before 5.16.3. A Droplet could allow Internet access to a service that has a remote code execution problem. |
An Insecure Temporary File vulnerability in FortiClient for Windows 6.2.1 and below may allow a local user to gain elevated privileges via exhausting the pool of temporary file names combined with a symbolic link attack. |
1Bosch 1Recording Station Firmware Jun 17, 2026 May 27, 2020 N/A· v4 8.8 HIGH· v3 7.2 HIGH· v2 Improper Access Control in the Kiosk Mode functionality of Bosch Recording Station allows a local unauthenticated attacker to escape from the Kiosk Mode and access the underlying operating system. |
4Debian FedoraprojectGoogle+1 more5Backports Sle ChromeDebian Linux+2 moreJun 17, 2026 May 21, 2020 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient data validation in loader in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had been able to write to disk to leak cross-origin data via a crafted HTML page. |
The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file extensions. This bypasses the .noexe protection mechanism against XSS. |
2Canonical Pulseaudio2Pulseaudio Ubuntu LinuxJun 17, 2026 May 15, 2020 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 An Ubuntu-specific modification to Pulseaudio to provide security mediation for Snap-packaged applications was found to have a bypass of intended access restriction for snaps which plugs any of pulseaudio, audio-playback...Show more |