CWE-668

Exposure of Resource to Wrong Sphere

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

732 vulnerabilities with CWE-668
CVE-2023-24870 MEDIUM
Microsoft PostScript and PCL6 Class Printer Driver - Info Disclosure
CVSS 6.5
CVE-2023-24866 MEDIUM
Microsoft PostScript and PCL6 Class Printer Driver - Info Disclosure
CVSS 6.5
CVE-2023-24863 MEDIUM
Microsoft PostScript and PCL6 Class Printer Driver - Info Disclosure
CVSS 6.5
CVE-2023-23409 MEDIUM
Windows 10 1507-22H2 and Windows 11 21H2-22H2 - Information Disclosure in Client Server Run-Time Subsystem
CVSS 5.5
CVE-2023-23394 MEDIUM
Windows 10 1507-22H2 and Windows 11 21H2-22H2 - Information Disclosure via CSRSS Untrusted Pointer Dereference
CVSS 5.5
CVE-2023-25802 HIGH
roxy-wi < 6.3.6.0 - Path Traversal via Directory Traversal Sequences
CVSS 7.5
CVE-2023-22892 HIGH
SmartBear Zephyr Enterprise <= 7.15.0 - Unauthenticated Arbitrary File Read
CVSS 7.5
CVE-2023-20061 MEDIUM
Cisco Unified Intelligence Center - SSRF
CVSS 6.5
CVE-2023-25536 MEDIUM
Dell PowerScale OneFS 9.4.0.0-9.4.0.10 - Authenticated Exposure of Sensitive Information in Certificate Management
CVSS 6.7
CVE-2023-25544 HIGH
Dell NetWorker < 19.6 - Apache Tomcat Version Disclosure
CVSS 7.5
CVE-2023-24567 HIGH
Dell NetWorker <19.5 - Info Disclosure
CVSS 7.5
CVE-2023-22777 MEDIUM
ArubaOS 8.6.0.0-8.6.0.18 and SD-WAN 8.7.0.0-2.3.0.0-8.7.0.0-2.3.0.7 - Authenticated Arbitrary File Read
CVSS 4.9
CVE-2023-22775 MEDIUM
Aruba SD-WAN 8.7.0.0-2.3.0.0-8.7.0.0-2.3.0.7 and ArubaOS 8.6.0.0-8.6.0.18 - Authenticated Information Disclosure via CLI
CVSS 6.5
CVE-2023-26041 LOW
Nextcloud Talk <15.0.3 - Info Disclosure
CVSS 2.6
CVE-2023-23501 MEDIUM
macOS < 13.2 - Kernel Memory Exposure via Improper Memory Handling
CVSS 5.5
CVE-2023-27265 LOW
Mattermost 5.12.0-7.6.9 - Authenticated Email Address Exposure via Regenerate Invite Id API
CVSS 2.7
CVE-2023-0481 LOW
Quarkus < 2.16.1 - Insecure Temporary File Permissions in FileBodyHandler
CVSS 3.3
CVE-2023-26081 HIGH
Epiphany < 43.1 - Password Exfiltration via Autofill in Sandboxed Contexts
CVSS 7.5
CVE-2023-25192 MEDIUM
AMI MegaRAC SP-X - User Enumeration via Redfish
CVSS 5.3
CVE-2023-21714 MEDIUM
Microsoft 365 Apps and Office Long Term Servicing Channel - Information Disclosure via Out-of-bounds Read
CVSS 5.5
CVE-2023-21687 MEDIUM
Microsoft Windows HTTP.sys - Information Disclosure
CVSS 5.5
CVE-2023-24523 HIGH
SAP Host Agent <7.22 - Privilege Escalation
CVSS 8.8
CVE-2023-21447 MEDIUM
Samsung Cloud < 5.3.0.32 - Improper Access Control via Implicit Intent
CVSS 4.0
CVE-2023-21445 MEDIUM
Samsung Android MyFiles < 12.2.09/13.1.03.501/14.1.00.422 - Unauthenticated Arbitrary File Write via Implicit Intent
CVSS 5.5
CVE-2023-21438 LOW
Samsung Android - Improper Access Control in HomeScreen
CVSS 2.1
Details
Vulnerabilities 732