← Back
CWE-668

730 CVEs • Abstraction: Class

Exposure of Resource to Wrong Sphere

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

JSON object

Loading...

CVEs (730)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Gri Project
2Debian Linux
Gri
Nov 21, 2024
Nov 8, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
gri before 2.12.18 generates temporary files in an insecure way.
1Mandriva
1Mondo
Nov 21, 2024
Nov 7, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Mondo 2.24 has insecure handling of temporary files.
1Redhat
2Jboss Operations Network
Rhq Mongo Db Drift Server
Nov 21, 2024
Nov 4, 2019
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
An insecurity temporary file vulnerability exists in RHQ Mongo DB Drift Server through 2013-09-25 when unpacking zipped files.
1Redhat
3Enterprise Virtualization
StorageVirtual Desktop Server Manager
Nov 21, 2024
Nov 4, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Insecure temporary file vulnerability in RedHat vsdm 4.9.6.
2Debian
Mutt
2Debian Linux
Mutt
Nov 20, 2024
Nov 1, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Mutt before 1.5.20 patch 7 allows an attacker to cause a denial of service via a series of requests to mutt temporary files.
2Debian
Python Docutils Project
2Debian Linux
Python Docutils
Nov 21, 2024
Oct 31, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
python-docutils allows insecure usage of temporary files
1Ibm
1Security Guardium Big Data Intelligence
Jun 17, 2026
Oct 29, 2019
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 specifies permissions for a security-critical resource which could lead to the exposure of sensitive information or the modification of that resource by unintended...Show more
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 specifies permissions for a security-critical resource which could lead to the exposure of sensitive information or the modification of that resource by unintended parties. IBM X-Force ID: 160986.Show less
1Philips
1Intellispace Perinatal
Jun 17, 2026
Oct 25, 2019
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
In IntelliSpace Perinatal, Versions K and prior, a vulnerability within the IntelliSpace Perinatal application environment could enable an unauthorized attacker with physical access to a locked application screen, or an...Show more
In IntelliSpace Perinatal, Versions K and prior, a vulnerability within the IntelliSpace Perinatal application environment could enable an unauthorized attacker with physical access to a locked application screen, or an authorized remote desktop session host application user to break-out from the containment of the application and access unauthorized resources from the Windows operating system as the limited-access Windows user. Due to potential Windows vulnerabilities, it may be possible for additional attack methods to be used to escalate privileges on the operating system.Show less
1Cisco
1Ios Xe
Jun 17, 2026
Sep 25, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to write values to the underlying memory of an affected device. The vulnerability is due to improper input validation and a...Show more
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to write values to the underlying memory of an affected device. The vulnerability is due to improper input validation and authorization of specific commands that a user can execute within the CLI. An attacker could exploit this vulnerability by authenticating to an affected device and issuing a specific set of commands. A successful exploit could allow the attacker to modify the configuration of the device to cause it to be non-secure and abnormally functioning.Show less
1Vandyvape
1Swell Kit Mod Firmware
Jun 17, 2026
Sep 23, 2019
N/A· v4
4.3 MEDIUM· v3
3.3 LOW· v2
An issue was discovered on Swell Kit Mod devices that use the Vandy Vape platform. An attacker may be able to trigger an unintended temperature in the victim's mouth and throat via Bluetooth Low Energy (BLE) packets that...Show more
An issue was discovered on Swell Kit Mod devices that use the Vandy Vape platform. An attacker may be able to trigger an unintended temperature in the victim's mouth and throat via Bluetooth Low Energy (BLE) packets that specify large power or voltage values.Show less
1Html Pdf Project
1Html Pdf
Jun 17, 2026
Sep 20, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The html-pdf package 2.2.0 for Node.js has an arbitrary file read vulnerability via an HTML file that uses XMLHttpRequest to access a file:/// URL.
1Usabilitydynamics
1Wp Invoice
Nov 21, 2024
Sep 20, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_twocheckout payer metadata updates.
1Usabilitydynamics
1Wp Invoice
Nov 21, 2024
Sep 20, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_interkassa payer metadata updates.
1Usabilitydynamics
1Wp Invoice
Nov 21, 2024
Sep 20, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_paypal payer metadata updates.
1Usabilitydynamics
1Wp Invoice
Nov 21, 2024
Sep 20, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_user_id for invoice retrieval.
1Usabilitydynamics
1Wp Invoice
Nov 21, 2024
Sep 20, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control for admin_init settings changes.
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
cPanel before 68.0.27 allows certain file-write operations via the telnetcrt script (SEC-356).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
cPanel before 11.54.0.4 allows arbitrary code execution during locale duplication (SEC-72).
1Google
1Kubernetes Engine
Jun 17, 2026
Jul 31, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Google Kubernetes Engine Plugin 0.6.2 and earlier created a temporary file containing a temporary access token in the project workspace, where it could be accessed by users with Job/Read permission.
2Mozilla
Opensuse
2Firefox
Leap
Jun 17, 2026
Jul 23, 2019
N/A· v4
4.7 MEDIUM· v3
4.3 MEDIUM· v2
The HTTP Alternative Services header, Alt-Svc, can be used by a malicious site to scan all TCP ports of any host that the accessible to a user when web content is loaded. This vulnerability affects Firefox < 68.