CWE-669
98 CVEs • Abstraction: Class
Incorrect Resource Transfer Between Spheres
The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.
CVEs (98)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreJun 17, 2026 May 21, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system, aka 'Windows Print Spooler Elevation of Privilege Vulnerability'. This CVE ID...Show more |
DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions. |
V6.0.10P2T2 and V6.0.10P2T5 of F6x2W product are impacted by Information leak vulnerability. Unauthorized users could log in directly to obtain page information without entering a verification code. |
FreeBSD NSD before 3.2.13 allows remote attackers to crash a NSD child server process (SIGSEGV) and cause a denial of service in the NSD server. |
Compal CH7465LG CH7465LG-NCIP-6.12.18.24-5p8-NOSH devices have Incorrect Access Control because of Improper Input Validation. The attacker can send a maliciously modified POST (HTTP) request containing shell commands, wh...Show more |
1Diffplug 3Eclipse Cdt Eclipse GroovyEclipse WtpJun 17, 2026 Sep 5, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In all versions prior to version 3.9.6 for eclipse-wtp, all versions prior to version 9.4.4 for eclipse-cdt, and all versions prior to version 3.0.1 for eclipse-groovy, Spotless was resolving dependencies over an insecur...Show more |
1Tp Link 2Archer C2 V1 Firmware Archer C3200 V1 FirmwareJun 17, 2026 Aug 27, 2019 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. A DHCP Request is sent to the router with a cert...Show more |
1Dlink 1Dir 825/ac G1 Firmware Jun 17, 2026 Aug 27, 2019 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 D-link DIR-825AC G1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. A DHCP Request is sent to the router with a certain Transaction ID fi...Show more |
1Newgensoft 1Omniflow Intelligent Business Process Suite Nov 21, 2024 Aug 21, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Newgen OmniFlow Intelligent Business Process Suite (iBPS) 7.0 has an "improper server side validation" vulnerability where client-side validations are tampered, and inappropriate information is stored on the server side...Show more |
SmokeDetector intentionally does automatic deployments of updated copies of SmokeDetector without server operator authority. |
In Eclipse Buildship versions prior to 3.1.1, the build files indicate that this project is resolving dependencies over HTTP instead of HTTPS. Any of these artifacts could have been MITM to maliciously compromise them an...Show more |
1Blueprism 1Robotic Process Automation Jun 17, 2026 May 24, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In AutomateAppCore.dll in Blue Prism Robotic Process Automation 6.4.0.8445, a vulnerability in access control can be exploited to escalate privileges. The vulnerability allows for abusing the application for fraud or una...Show more |
Eclipse Vorto versions prior to 0.11 resolved Maven build artifacts for the Xtext project over HTTP instead of HTTPS. Any of these dependent artifacts could have been maliciously compromised by a MITM attack. Hence produ...Show more |
1Juniper 1Identity Management Service Jun 17, 2026 Apr 10, 2019 N/A· v4 4.2 MEDIUM· v3 1.9 LOW· v2 Juniper Identity Management Service (JIMS) for Windows versions prior to 1.1.4 may send an incorrect message to associated SRX services gateways. This may allow an attacker with physical access to an existing domain conn...Show more |
1Prominent 1Multiflex M10a Controller Firmware May 13, 2026 Oct 17, 2017 N/A· v4 5.6 MEDIUM· v3 6.8 MEDIUM· v2 A Client-Side Enforcement of Server-Side Security issue was discovered in ProMinent MultiFLEX M10a Controller web interface. The log out function in the application removes the user's session only on the client side. Thi...Show more |
The web server in Aternity before 9.0.1 does not require authentication for getMBeansFromURL loading of Java MBeans, which allows remote attackers to execute arbitrary Java code by registering MBeans. |
Opera does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unau...Show more |
1Microsoft 3Exchange Server Windows 2000Windows XpApr 16, 2026 Mar 8, 2002 N/A· v4 N/A· v3 5.0 MEDIUM· v2 SMTP service in Microsoft Windows 2000, Windows XP Professional, and Exchange 2000 allows remote attackers to cause a denial of service via a command with a malformed data transfer (BDAT) request. |