← Back
CWE-668

730 CVEs • Abstraction: Class

Exposure of Resource to Wrong Sphere

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

JSON object

Loading...

CVEs (730)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Norwegian Air
1Norwegian Air Kiosk
May 13, 2026
Feb 9, 2017
N/A· v4
6.6 MEDIUM· v3
7.2 HIGH· v2
The Norwegian Air Shuttle (aka norwegian.com) airline kiosk allows physically proximate attackers to bypass the intended "Please select booking identification" UI step, and obtain administrative privileges and network ac...Show more
The Norwegian Air Shuttle (aka norwegian.com) airline kiosk allows physically proximate attackers to bypass the intended "Please select booking identification" UI step, and obtain administrative privileges and network access on the underlying Windows OS, by accessing a touch-screen print icon to manipulate the print dialog.Show less
1Vmware
2Identity Manager
Vrealize Automation
May 6, 2026
Dec 29, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
VMware Identity Manager 2.x before 2.7.1 and vRealize Automation 7.x before 7.2.0 allow remote attackers to read /SAAS/WEB-INF and /SAAS/META-INF files via unspecified vectors.
1Ge
1Cimplicity
May 6, 2026
Jul 15, 2016
N/A· v4
6.3 MEDIUM· v3
4.6 MEDIUM· v2
General Electric (GE) Digital Proficy HMI/SCADA - CIMPLICITY before 8.2 SIM 27 mishandles service DACLs, which allows local users to modify a service configuration via unspecified vectors.
2Redhat
Suse
5Linux Enterprise
ManagerNetwork Satellite+2 more
Apr 29, 2026
Nov 18, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Red Hat Satellite 5.6 and earlier does not disable the web interface that is used to create the first user for a satellite, which allows remote attackers to create administrator accounts.
1Google
1Chrome
Apr 29, 2026
Mar 22, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
Google Chrome 17.0.963.66 and earlier allows remote attackers to bypass the sandbox protection mechanism by leveraging access to a sandboxed process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 20...Show more
Google Chrome 17.0.963.66 and earlier allows remote attackers to bypass the sandbox protection mechanism by leveraging access to a sandboxed process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012. NOTE: the primary affected product may be clarified later; it was not identified by the researcher, who reportedly stated "it really doesn't matter if it's third-party code."Show less
1Microsoft
1Internet Explorer
Apr 29, 2026
Aug 10, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Microsoft Internet Explorer 6 through 9 does not properly implement JavaScript event handlers, which allows remote attackers to access content from a different (1) domain or (2) zone via unspecified script code, aka "Eve...Show more
Microsoft Internet Explorer 6 through 9 does not properly implement JavaScript event handlers, which allows remote attackers to access content from a different (1) domain or (2) zone via unspecified script code, aka "Event Handlers Information Disclosure Vulnerability."Show less
1Microsoft
1Internet Explorer
Apr 29, 2026
Jun 16, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Microsoft Internet Explorer 6 through 8 does not properly restrict web script, which allows user-assisted remote attackers to obtain sensitive information from a different (1) domain or (2) zone via vectors involving a d...Show more
Microsoft Internet Explorer 6 through 8 does not properly restrict web script, which allows user-assisted remote attackers to obtain sensitive information from a different (1) domain or (2) zone via vectors involving a drag-and-drop operation, aka "Drag and Drop Information Disclosure Vulnerability."Show less
1Opera
1Opera Browser
Apr 16, 2026
Dec 31, 2004
N/A· v4
N/A· v3
2.6 LOW· v2
Opera 7.54 and earlier does not properly limit an applet's access to internal Java packages from Sun, which allows remote attackers to gain sensitive information, such as user names and the installation directory.
1Acme
1Mini Httpd
Apr 16, 2026
Nov 13, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Acme mini_httpd before 1.16 allows remote attackers to view sensitive files under the document root (such as .htpasswd) via a GET request with a trailing /.
1Acme
1Thttpd
Apr 16, 2026
Nov 13, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Acme Thttpd Secure Webserver before 2.22, with the chroot option enabled, allows remote attackers to view sensitive files under the document root (such as .htpasswd) via a GET request with a trailing /.