CWE-668
743 CVEs • Abstraction: Class
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
CVEs (743)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Gnupg Opensuse2Leap LibgcryptJun 17, 2026 Jun 20, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In Libgcrypt 1.8.4, the C implementation of AES is vulnerable to a flush-and-reload side-channel attack because physical addresses are available to other processes. (The C implementation is used on platforms where an ass...Show more |
Alpine Linux abuild through 3.4.0 allows an unprivileged member of the abuild group to add an untrusted package via a --keys-dir option that causes acceptance of an untrusted signing key. |
In Rancher 1 and 2 through 2.2.3, unprivileged users (if allowed to deploy nodes) can gain admin access to the Rancher management plane because node driver options intentionally allow posting certain data to the cloud. T...Show more |
An exploitable local privilege elevation vulnerability exists in the file system permissions of the `Temp` directory in GOG Galaxy 1.2.48.36 (Windows 64-bit Installer). An attacker can overwrite executables of the Deskto...Show more |
1Schneider Electric 4Modicon M340 Firmware Modicon M580 FirmwareModicon Premium Firmware+1 moreJun 17, 2026 May 22, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A CWE-501: Trust Boundary Violation vulnerability on connection to the Controller exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum and Modicon Premium which could cause unauthorized access by con...Show more |
An issue was discovered in Rancher 2 through 2.1.5. Any project member with access to the default namespace can mount the netes-default service account in a pod, and then use that pod to execute administrative privileged...Show more |
1Raspberrypi 1Raspberry Pi 3 Model B+ Firmware Nov 21, 2024 Apr 4, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The ARM-based hardware debugging feature on Raspberry Pi 3 module B+ and possibly other devices allows non-secure EL1 code to read/write any EL3 (the highest privilege level in ARMv8) memory/register via inter-processor...Show more |
hw/ppc/spapr.c in QEMU through 3.1.0 allows Information Exposure because the hypervisor shares the /proc/device-tree/system-id and /proc/device-tree/model system attributes with a guest. |
1Atlassian 2Confluence Data Center Confluence ServerNov 21, 2024 Feb 13, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Atlassian Confluence Server and Data Center before version 6.13.1 allows an authenticated user to download a deleted page via the word export feature. |
3Debian FlatpakRedhat8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreJun 17, 2026 Feb 12, 2019 N/A· v4 8.2 HIGH· v3 4.4 MEDIUM· v2 Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows attackers to modify a host-side executable file. |
1Ibm 1Websphere Application Server Nov 21, 2024 Dec 3, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to gain elevated privileges on the system, caused when a security domain is configured to use a federated repository other than global federated...Show more |
An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace. A local authenticated user can bypass Application Whitelisting restrictions to execute arbitrary code by leveraging multiple uns...Show more |
2Apache Debian2Debian Linux Traffic ServerJun 17, 2026 Aug 29, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Pages that are rendered using the ESI plugin can have access to the cookie header when the plugin is configured not to allow access. This affects Apache Traffic Server (ATS) versions 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To...Show more |
An issue was discovered on the PLANEX CS-QR20 1.30. A hidden and undocumented management page allows an attacker to execute arbitrary code on the device when the user is authenticated. The management page was used for de...Show more |
2Canonical Hp2Moonshot Provisioning Manager Ubuntu LinuxJun 17, 2026 Aug 6, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A local arbitrary file modification vulnerability was identified in HPE Moonshot Provisioning Manager prior to v1.24. |
1Hp 1Moonshot Provisioning Manager Jun 17, 2026 Aug 6, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A remote bypass of security restrictions vulnerability was identified in HPE Moonshot Provisioning Manager prior to v1.24. |
1Philips 4 Brilliance Ct Big Bore Firmware Brilliance Firmware 64Brilliance Ict Firmware+1 moreJun 17, 2026 May 4, 2018 N/A· v4 8.7 HIGH· v3 6.8 MEDIUM· v2 Vulnerabilities within the Philips Brilliance CT kiosk environment (Brilliance 64 version 2.6.2 and prior, Brilliance iCT versions 4.1.6 and prior, Brillance iCT SP versions 3.2.4 and prior, and Brilliance CT Big Bore 2....Show more |
An issue was discovered in KTextEditor 5.34.0 through 5.45.0. Insecure handling of temporary files in the KTextEditor's kauth_ktexteditor_helper service (as utilized in the Kate text editor) can allow other unprivileged...Show more |
2Debian Mediawiki2Debian Linux MediawikiNov 21, 2024 Apr 13, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Mediawiki before 1.28.1 / 1.27.2 contains an unsafe use of temporary directory, where having LocalisationCache directory default to system tmp directory is insecure. |
1Qualcomm 5Mdm9206 Firmware Mdm9607 FirmwareMsm8996 Firmware+2 moreNov 21, 2024 Apr 11, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile and Snapdragon Mobile MDM9206, MDM9607, SD 845, MSM8996, MSM8998, it is possible for IPA (internet protocol accelerator) channels owned...Show more |