CWE-669
105 CVEs • Abstraction: Class
Incorrect Resource Transfer Between Spheres
The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.
CVEs (105)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Samsung 2Exynos 5123 Firmware Exynos 5300 FirmwareJun 17, 2026 Jun 7, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 An issue was discovered in the Shannon RCS component in Samsung Exynos Modem 5123 and 5300. Incorrect resource transfer between spheres can cause unintended querying of the SIM status via a crafted application. |
An issue was discovered in TigerGraph Enterprise Free Edition 3.x. Data loading jobs in gsql_server, created by any user with designer permissions, can read sensitive data from arbitrary locations. |
Elrond-GO is a go implementation for the Elrond Network protocol. Versions prior to 1.3.50 are subject to a processing issue where nodes are affected when trying to process a cross-shard relayed transaction with a smart...Show more |
PHP Remote File Inclusion in GitHub repository tsolucio/corebos prior to 8.0. |
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 4.10.15, or 5.0.0 and above prior to 5.2.6, a user can write to the session object of another u...Show more |
1Dell 8Evasa Provider Virtual Appliance Powermax OsSolutions Enabler+5 moreJun 17, 2026 Aug 31, 2022 N/A· v4 8.0 HIGH· v3 N/A· v2 Unisphere for PowerMax versions before 9.2.3.15 contain a privilege escalation vulnerability. An adjacent malicious user may potentially exploit this vulnerability to escalate their privileges and access functionalities...Show more |
1Openzeppelin 2Contracts Contracts UpgradeableJun 17, 2026 Aug 1, 2022 N/A· v4 5.3 MEDIUM· v3 N/A· v2 OpenZeppelin Contracts is a library for secure smart contract development. Contracts using the cross chain utilities for Arbitrum L2, `CrossChainEnabledArbitrumL2` or `LibArbitrumL2`, will classify direct interactions of...Show more |
1Schneider Electric 2Wiser Smart Eer21000 Firmware Wiser Smart Eer21001 FirmwareJun 17, 2026 Jun 2, 2022 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 A CWE-669: Incorrect Resource Transfer Between Spheres vulnerability exists that could allow unauthorized access when an attacker uses cross-domain attacks. Affected Products: Wiser Smart, EER21000 & EER21001 (V4.5 and p...Show more |
An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4., that allows attackers to escalate privileges within the application, since all permission checks are done client-side, not server-side. |
1Schneider Electric 3Fellerlynk Firmware Spacelynk FirmwareWiser For Knx FirmwareJun 17, 2026 Feb 11, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A CWE-669: Incorrect Resource Transfer Between Spheres vulnerability exists that could cause data exfiltration and unauthorized access when accessing a malicious website. Affected Product: spaceLYnk (V2.6.1 and prior), W...Show more |
1Cisco 2Unified Contact Center Express Unified Contact Center Management PortalJun 17, 2026 Jan 14, 2022 N/A· v4 9.6 CRITICAL· v3 8.5 HIGH· v2 A vulnerability in the web-based management interface of Cisco Unified Contact Center Management Portal (Unified CCMP) and Cisco Unified Contact Center Domain Manager (Unified CCDM) could allow an authenticated, remote a...Show more |
In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. “guest” role users can self-register even when the admin does not allow. This happens due to front-end restriction only. |
The HM Multiple Roles WordPress plugin before 1.3 does not have any access control to prevent low privilege users to set themselves as admin via their profile page |
2Helmholz Mbconnectline4Mbconnect24 Mymbconnect24Myrex24+1 moreJun 17, 2026 Aug 2, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 In MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 an authenticated attacker can change the password of his account into a new password that violates th...Show more |
Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. The need to use 2FA for authentication in enforce client-side instead of server-side and can be bypassed using a local proxy. Thus rendering 2FA use...Show more |
Firefox used to cache the last filename used for printing a file. When generating a filename for printing, Firefox usually suggests the web page title. The caching and suggestion techniques combined may have lead to the...Show more |
2Ivanti Pulsesecure2Connect Secure Pulse Connect SecureJun 17, 2026 May 27, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a maliciously crafted archive upload in the admi...Show more |
1Dell 5Powermax Os Solutions EnablerSolutions Enabler Virtual Appliance+2 moreJun 17, 2026 Apr 30, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Dell Unisphere for PowerMax versions prior to 9.2.1.6 contain an Authorization Bypass Vulnerability. A local authenticated malicious user with monitor role may exploit this vulnerability to perform unauthorized actions. |
1Ibm 1Security Verify Information Queue Jun 17, 2026 Feb 12, 2021 N/A· v4 8.1 HIGH· v3 4.8 MEDIUM· v2 IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user to impersonate another user on the system due to incorrectly updating the session identifier. IBM X-Force ID: 198191. |
1Sooil 3Anydana A Firmware Anydana I FirmwareDiabecare Rs FirmwareJun 17, 2026 Jan 19, 2021 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a client-side control vulnerability in the insulin pump and its AnyDana-i and AnyDana-A mobile applications allows physically proximate attackers to b...Show more |