CWE-668
730 CVEs • Abstraction: Class
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
CVEs (730)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Gri Project2Debian Linux GriNov 21, 2024 Nov 8, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 gri before 2.12.18 generates temporary files in an insecure way. |
Mondo 2.24 has insecure handling of temporary files. |
1Redhat 2Jboss Operations Network Rhq Mongo Db Drift ServerNov 21, 2024 Nov 4, 2019 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 An insecurity temporary file vulnerability exists in RHQ Mongo DB Drift Server through 2013-09-25 when unpacking zipped files. |
1Redhat 3Enterprise Virtualization StorageVirtual Desktop Server ManagerNov 21, 2024 Nov 4, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Insecure temporary file vulnerability in RedHat vsdm 4.9.6. |
Mutt before 1.5.20 patch 7 allows an attacker to cause a denial of service via a series of requests to mutt temporary files. |
2Debian Python Docutils Project2Debian Linux Python DocutilsNov 21, 2024 Oct 31, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 python-docutils allows insecure usage of temporary files |
1Ibm 1Security Guardium Big Data Intelligence Jun 17, 2026 Oct 29, 2019 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 IBM Security Guardium Big Data Intelligence (SonarG) 4.0 specifies permissions for a security-critical resource which could lead to the exposure of sensitive information or the modification of that resource by unintended...Show more |
1Philips 1Intellispace Perinatal Jun 17, 2026 Oct 25, 2019 N/A· v4 6.8 MEDIUM· v3 7.2 HIGH· v2 In IntelliSpace Perinatal, Versions K and prior, a vulnerability within the IntelliSpace Perinatal application environment could enable an unauthorized attacker with physical access to a locked application screen, or an...Show more |
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to write values to the underlying memory of an affected device. The vulnerability is due to improper input validation and a...Show more |
1Vandyvape 1Swell Kit Mod Firmware Jun 17, 2026 Sep 23, 2019 N/A· v4 4.3 MEDIUM· v3 3.3 LOW· v2 An issue was discovered on Swell Kit Mod devices that use the Vandy Vape platform. An attacker may be able to trigger an unintended temperature in the victim's mouth and throat via Bluetooth Low Energy (BLE) packets that...Show more |
The html-pdf package 2.2.0 for Node.js has an arbitrary file read vulnerability via an HTML file that uses XMLHttpRequest to access a file:/// URL. |
1Usabilitydynamics 1Wp Invoice Nov 21, 2024 Sep 20, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_twocheckout payer metadata updates. |
1Usabilitydynamics 1Wp Invoice Nov 21, 2024 Sep 20, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_interkassa payer metadata updates. |
1Usabilitydynamics 1Wp Invoice Nov 21, 2024 Sep 20, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_paypal payer metadata updates. |
1Usabilitydynamics 1Wp Invoice Nov 21, 2024 Sep 20, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_user_id for invoice retrieval. |
1Usabilitydynamics 1Wp Invoice Nov 21, 2024 Sep 20, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control for admin_init settings changes. |
cPanel before 68.0.27 allows certain file-write operations via the telnetcrt script (SEC-356). |
cPanel before 11.54.0.4 allows arbitrary code execution during locale duplication (SEC-72). |
Jenkins Google Kubernetes Engine Plugin 0.6.2 and earlier created a temporary file containing a temporary access token in the project workspace, where it could be accessed by users with Job/Read permission. |
2Mozilla Opensuse2Firefox LeapJun 17, 2026 Jul 23, 2019 N/A· v4 4.7 MEDIUM· v3 4.3 MEDIUM· v2 The HTTP Alternative Services header, Alt-Svc, can be used by a malicious site to scan all TCP ports of any host that the accessible to a user when web content is loaded. This vulnerability affects Firefox < 68. |