← Back
CWE-669

105 CVEs • Abstraction: Class

Incorrect Resource Transfer Between Spheres

The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.

JSON object

Loading...

CVEs (105)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
12Amazon
AristaCanonical+9 more
51Amazon Linux
Basesystem ModuleCaas Platform+48 more
Sep 8, 2026
Apr 22, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is...Show more
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.Show less
-
-
Jun 17, 2026
Apr 16, 2026
N/A· v4
6.2 MEDIUM· v3
N/A· v2
In ONLYOFFICE DesktopEditors before 9.3.0, the update service allows attackers to perform actions on files with SYSTEM privileges.
1Systemd Project
1Systemd
Jun 17, 2026
Apr 10, 2026
N/A· v4
3.3 LOW· v3
N/A· v2
In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p emerg" command is executed, if ForwardToWall=yes is set.
1Systemd Project
1Systemd
Jun 17, 2026
Apr 10, 2026
N/A· v4
6.4 MEDIUM· v3
N/A· v2
In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output.
1Roundcube
1Webmail
Jul 24, 2026
Apr 3, 2026
N/A· v4
8.2 HIGH· v3
N/A· v2
An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control byp...Show more
An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. This involves the animate element with attributeName=fill/filter/stroke.Show less
1Roundcube
1Webmail
Jul 24, 2026
Apr 3, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to a fixed-position mitigation bypass via the use of !importa...Show more
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to a fixed-position mitigation bypass via the use of !important.Show less
1Roundcube
1Webmail
Jul 24, 2026
Apr 3, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail message. This may lead to information disclo...Show more
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail message. This may lead to information disclosure or access-control bypass.Show less
1Roundcube
1Webmail
Jul 24, 2026
Apr 3, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an e-mail message. This may lead to informa...Show more
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an e-mail message. This may lead to information disclosure or access-control bypass.Show less
1Roundcube
1Webmail
Jul 24, 2026
Apr 3, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point...Show more
An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts.Show less
-
-
Jun 17, 2026
Mar 24, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
A low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system, enabling unauthorized code execution.
1Librechat
1Librechat
Jun 17, 2026
Mar 18, 2026
N/A· v4
9.0 CRITICAL· v3
N/A· v2
In LibreChat 0.8.1-rc2, a logged-in user obtains a JWT for both the LibreChat API and the RAG API.
1Gnu
1Inetutils
Jun 17, 2026
Mar 16, 2026
N/A· v4
4.7 MEDIUM· v3
N/A· v2
telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON SEND USERVAR.
-
-
Aug 14, 2026
Feb 18, 2026
N/A· v4
8.2 HIGH· v3
N/A· v2
An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering a resize, a user may convince Nova's Fla...Show more
An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering a resize, a user may convince Nova's Flat image backend to call qemu-img without a format restriction, resulting in an unsafe image resize operation that could destroy data on the host system. Only compute nodes using the Flat image backend (usually configured with use_cow_images=False) are affected.Show less
1Openclaw
1Openclaw
Jun 17, 2026
Feb 1, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token value.
1Apache
1Apache Airflow Providers Edge3
Jun 17, 2026
Dec 17, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Edge3 Worker RPC RCE on Airflow 2. This issue affects Apache Airflow Providers Edge3: before 2.0.0 - and only if you installed and configured it on Airflow 2. The Edge3 provider support in Airflow 2 has been always d...Show more
Edge3 Worker RPC RCE on Airflow 2. This issue affects Apache Airflow Providers Edge3: before 2.0.0 - and only if you installed and configured it on Airflow 2. The Edge3 provider support in Airflow 2 has been always development-only and not officially released, however if you installed and configured Edge3 provider in Airflow 2, it implicitly enabled non-public (normally) API which was used to test Edge Provider in Airflow 2 during the development. This API allowed Dag author to perform Remote Code Execution in the webserver context, which Dag Author was not supposed to be able to do. If you installed and configured Edge3 provider for Airflow 2, you should uninstall it and migrate to Airflow 3. The new Edge3 provider versions (>=2.0.0) has minimum version of Airflow set to 3 and the RCE-prone Airflow 2 code is removed, so it should no longer be possible to use the Edge3 provider 2.0.0+ on Airflow 2. If you used Edge Provider in Airflow 3, you are not affected.Show less
-
-
Jun 17, 2026
Oct 22, 2025
N/A· v4
8.0 HIGH· v3
N/A· v2
Mercku M6a devices through 2.1.0 allow root TELNET logins via the web admin password.
1Rbi
1Restaurant Brands International Assistant
Jun 17, 2026
Oct 17, 2025
N/A· v4
7.7 HIGH· v3
N/A· v2
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to review the stored audio of conversations between associates and Drive Thru customers.
-
-
Jun 17, 2026
Oct 17, 2025
N/A· v4
4.0 MEDIUM· v3
N/A· v2
XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT extension functions are enabled.
-
-
Jun 17, 2026
Oct 10, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
In SonarQube before 25.6, 2025.3 Commercial, and 2025.1.3 LTA, authenticated low-privileged users can query the /api/v2/users-management/users endpoint and obtain user fields intended for administrators only, including t...Show more
In SonarQube before 25.6, 2025.3 Commercial, and 2025.1.3 LTA, authenticated low-privileged users can query the /api/v2/users-management/users endpoint and obtain user fields intended for administrators only, including the email addresses of other accounts.Show less
-
-
Jun 17, 2026
Sep 30, 2025
N/A· v4
3.5 LOW· v3
N/A· v2
The EKEN video doorbell T6 BT60PLUS_MAIN_V1.0_GC1084_20230531 periodically sends debug logs to the EKEN cloud servers with sensitive information such as the Wi-Fi SSID and password.