CWE-653

Improper Isolation or Compartmentalization

Parent: CWE-657 - Violation of Secure Design Principles

The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions.

71 vulnerabilities with CWE-653
CVE-2024-0137 MEDIUM
NVIDIA Container Toolkit <1.17.3 & GPU Operator <24.9.1 - DoS & Privilege Escalation
CVSS 5.5
CVE-2024-0136 HIGH
NVIDIA Container Toolkit < 1.17.3 and NVIDIA GPU Operator < 24.9.1 - Improper Isolation via Container Image
CVSS 7.6
CVE-2024-0135 HIGH
NVIDIA Container Toolkit < 1.17.3 and NVIDIA GPU Operator < 24.9.1 - Improper Isolation Leading to Code Execution
CVSS 7.6
CVE-2024-57723 MEDIUM
lunasvg 3.0.0 - Denial of Service via Composition Source Over
CVSS 6.5
CVE-2024-57721 MEDIUM
lunasvg 3.0.0 - Denial of Service via plutovg_path_add_path
CVSS 6.5
CVE-2024-57720 MEDIUM
lunasvg 3.0.0 - Denial of Service via plutovg_blend Component
CVSS 6.5
CVE-2024-47520 HIGH
Advanced Report App - Privilege Escalation
CVSS 7.6
CVE-2024-53855 LOW
Centurion ERP - Privilege Escalation
CVSS 1.9
CVE-2024-35425 MEDIUM
vmir - Denial of Service via Function Prepare Parse
CVSS 5.5
CVE-2024-49373 MEDIUM
No Fuss Computing Centurion ERP <1.2.1 - Info Disclosure
CVSS 4.1
CVE-2024-8118 MEDIUM
Grafana 8.5.0-10.3.9, 10.4.0-10.4.8, 11.0.0-11.0.4, 11.1.0-11.1.5, 11.2.0 - Alert Rule Write API Permission Bypass
CVE-2024-43803 MEDIUM
Bare Metal Operator < 0.8.0, 0.6.0-0.6.2, < 0.5.2 - Unauthorized Secret Access via BareMetalHost CRD
CVSS 4.9
CVE-2024-20285 MEDIUM
Cisco NX-OS Software - Code Injection
CVSS 5.3
CVE-2024-5801 MEDIUM
B&R Automation Runtime <6.0.2 - SSRF
CVE-2024-33768 CRITICAL
lunasvg 2.3.9 - Segmentation Violation in composition_solid_source_over
CVSS 9.8
CVE-2024-30388 MEDIUM
Juniper Junos OS on QFX5000/EX4400/EX4100/EX4650 - Unauthenticated Denial of Service via Malformed LACP Packet
CVSS 6.5
CVE-2024-23683 HIGH
Artemis Java Test Sandbox <1.7.6 - Code Injection
CVSS 8.2
CVE-2024-23682 HIGH
Artemis Java Test Sandbox <1.8.0 - Code Injection
CVSS 8.2
CVE-2023-1636 MEDIUM
OpenStack Barbican - Privilege Escalation
CVSS 6.0
CVE-2023-29580 MEDIUM
yasm <1.3.0.55.g101bc - Memory Corruption
CVSS 5.5
CVE-2023-1305 HIGH
InsightCloudSec <23.2.1 - Info Disclosure
CVSS 8.1
Details
Vulnerabilities 71