← Back
CWE-668

743 CVEs • Abstraction: Class

Exposure of Resource to Wrong Sphere

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

JSON object

Loading...

CVEs (743)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Opera
1Opera Browser
Apr 16, 2026
Dec 31, 2004
N/A· v4
N/A· v3
2.6 LOW· v2
Opera 7.54 and earlier does not properly limit an applet's access to internal Java packages from Sun, which allows remote attackers to gain sensitive information, such as user names and the installation directory.
1Acme
1Mini Httpd
Apr 16, 2026
Nov 13, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Acme mini_httpd before 1.16 allows remote attackers to view sensitive files under the document root (such as .htpasswd) via a GET request with a trailing /.
1Acme
1Thttpd
Apr 16, 2026
Nov 13, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Acme Thttpd Secure Webserver before 2.22, with the chroot option enabled, allows remote attackers to view sensitive files under the document root (such as .htpasswd) via a GET request with a trailing /.