CWE-668
717 CVEs • Abstraction: Class
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
CVEs (717)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Aliasrobotics Enabled RoboticsMobile Industrial Robotics+1 more10Er Flex Firmware Er Lite FirmwareEr One Firmware+7 moreNov 21, 2024 Jun 24, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 MiR100, MiR200 and other MiR robots use the Robot Operating System (ROS) default packages exposing the computational graph to all network interfaces, wireless and wired. This is the result of a bad set up and can be miti...Show more |
1Mattermost 1Mattermost Packages Nov 21, 2024 Jun 19, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Mattermost Packages before 5.16.3. A Droplet could allow Internet access to a service that has a remote code execution problem. |
An Insecure Temporary File vulnerability in FortiClient for Windows 6.2.1 and below may allow a local user to gain elevated privileges via exhausting the pool of temporary file names combined with a symbolic link attack. |
1Bosch 1Recording Station Firmware Nov 21, 2024 May 27, 2020 N/A· v4 8.8 HIGH· v3 7.2 HIGH· v2 Improper Access Control in the Kiosk Mode functionality of Bosch Recording Station allows a local unauthenticated attacker to escape from the Kiosk Mode and access the underlying operating system. |
4Debian FedoraprojectGoogle+1 more5Backports Sle ChromeDebian Linux+2 moreNov 21, 2024 May 21, 2020 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient data validation in loader in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had been able to write to disk to leak cross-origin data via a crafted HTML page. |
The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file extensions. This bypasses the .noexe protection mechanism against XSS. |
2Canonical Pulseaudio2Pulseaudio Ubuntu LinuxNov 21, 2024 May 15, 2020 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 An Ubuntu-specific modification to Pulseaudio to provide security mediation for Snap-packaged applications was found to have a bypass of intended access restriction for snaps which plugs any of pulseaudio, audio-playback...Show more |
5Apache CanonicalFedoraproject+2 more50Agile Engineering Data Management AntBanking Enterprise Collections+47 moreNov 21, 2024 May 14, 2020 N/A· v4 6.3 MEDIUM· v3 3.3 LOW· v2 Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replacer...Show more |
An issue was discovered in Serpico before 1.3.3. The /admin/attacments_backup endpoint can be requested by non-admin authenticated users. This means that an attacker with a user account can retrieve all of the attachment...Show more |
1Cisco 3Firepower Threat Defense IosSecure Firewall Management CenterNov 26, 2024 May 6, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured file policies on an affected system. The vulnerability i...Show more |
1Silver Peak 24Nx 1000 Firmware Nx 10k FirmwareNx 11k Firmware+21 moreNov 21, 2024 May 5, 2020 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 1. IPSec UDP key material can be retrieved from machine-to-machine interfaces and human-accessible interfaces by a user with admin credentials. Such a user, with the required system knowledge, could use this material to...Show more |
1F5 13Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+10 moreNov 21, 2024 Apr 30, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 On versions 15.1.0-15.1.0.1, 15.0.0-15.0.1.2, and 14.1.0-14.1.2.3, BIG-IP Virtual Edition (VE) may expose a mechanism for remote attackers to access local daemons and bypass port lockdown settings. |
4Debian FedoraprojectGoogle+1 more5Backports ChromeDebian Linux+2 moreNov 21, 2024 Apr 13, 2020 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Inappropriate implementation in cache in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to leak cross-origin data via a crafted HTML page. |
1Cross Domain Local Storage Project 1Cross Domain Local Storage Nov 21, 2024 Apr 7, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in xdLocalStorage through 2.0.5. The postData() function in xdLocalStoragePostMessageApi.js specifies the wildcard (*) as the targetOrigin when calling the postMessage() function on the parent obj...Show more |
1Pulsesecure 2Pulse Connect Secure Pulse Policy SecureNov 21, 2024 Apr 6, 2020 N/A· v4 8.8 HIGH· v3 3.3 LOW· v2 An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, launches a TCP server t...Show more |
An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to bypass intended access restrictions on tasks from an untrusted...Show more |
3Fedoraproject OpensuseRedhat8Ansible Engine Ansible TowerBackports Sle+5 moreNov 21, 2024 Mar 31, 2020 N/A· v4 5.6 MEDIUM· v3 4.6 MEDIUM· v2 A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on...Show more |
An issue was discovered in Joomla! before 3.9.16. Various actions in com_templates lack the required ACL checks, leading to various potential attack vectors. |
An exploitable improper input validation vulnerability exists in the firmware update functionality of WAGO e!COCKPIT automation software v1.6.0.7. A specially crafted firmware update file can allow an attacker to write a...Show more |
A predictable temporary filename vulnerability in PAN-OS allows local privilege escalation. This issue allows a local attacker who bypassed the restricted shell to execute commands as a low privileged user and gain root...Show more |