CWE-668
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
732 vulnerabilities with CWE-668
CVE-2023-21611
HIGH
Adobe Acrobat Reader <22.003.20282 - Privilege Escalation
CVSS 7.8
CVE-2023-22497
MEDIUM
netdata < 1.37.0 - Improper Authentication via MACHINE_GUID as API Key
CVSS 6.5
CVE-2023-21536
MEDIUM
Event Tracing for Windows - Info Disclosure
CVSS 4.7
CVE-2022-49509
HIGH
Linux Kernel 5.9-5.15.45, 5.16.0-5.17.13, 5.18.0-5.18.2 - Use-After-Free in max9286 I2C Driver
CVSS 7.1
CVE-2022-48757
HIGH
Linux Kernel - Information Disclosure via /proc/net/ptype
CVSS 7.1
CVE-2022-20917
MEDIUM
Cisco Jabber < 12.6.6, < 12.8.8, < 14.1.4 - Authenticated XMPP Message Manipulation via Nested Message Handling
CVSS 4.3
CVE-2022-46901
HIGH
Vocera Report Server & Voice Server <5.8 - Info Disclosure
CVSS 7.5
CVE-2022-43684
CRITICAL
ServiceNow Quebec Rome San Diego Tokyo Utah - Authenticated Exposure of Sensitive Information via ACL Bypass
CVSS 9.9
CVE-2022-40525
HIGH
Qualcomm CSR8811 and IPQ/QCA/QCN Firmware - Information Disclosure via Side Channel Analysis
CVSS 7.1
CVE-2022-40523
HIGH
Qualcomm 9205 LTE Modem Firmware - Information Disclosure via Indirect Branch Misprediction
CVSS 7.1
CVE-2022-40210
MEDIUM
Intel Data Center Manager < 5.0.1 - Authenticated Privilege Escalation via Session Data Exposure
CVSS 6.8
CVE-2022-38087
MEDIUM
Intel(R) Processors - Info Disclosure
CVSS 4.1
CVE-2022-47338
HIGH
Android - Denial of Service in Telecom Service
CVSS 7.1
CVE-2022-46257
MEDIUM
GitHub Enterprise Server - Info Disclosure
CVSS 4.3
CVE-2022-44310
HIGH
ecdh < 0.2.0 - Exposure of Resource to Wrong Sphere via Invalid Public Key
CVSS 7.5
CVE-2022-39952
CRITICAL
Fortinet FortiNAC keyUpload.jsp arbitrary file write
CVSS 9.8
CVE-2022-34387
MEDIUM
Dell SupportAssist < 3.11.4 (Home) / < 3.2.0 (Business) - Privilege Escalation via Insecure Temporary File
CVSS 6.4
CVE-2022-34364
MEDIUM
BSAFE SSL-J <6.5, 7.0 - Info Disclosure
CVSS 4.4
CVE-2022-4903
MEDIUM
CodenameOne < 7.0.71 - Use of Implicit Intent for Sensitive Communication
CVSS 5.0
CVE-2022-34452
LOW
Dell PowerPath Management Appliance 3.0-3.3 - Authenticated Sensitive Information Disclosure via Log Files
CVSS 2.7
CVE-2022-46756
HIGH
Dell VxRail < 7.0.410 - Container Escape and OS Command Execution
CVSS 8.2
CVE-2022-22732
LOW
EcoStruxure Power Commission < 2.22 - Exposure of Resource to Wrong Sphere via Fetch Request
CVSS 3.9
CVE-2022-26329
LOW
NetIQ Identity Manager <4.8.5 - Info Disclosure
CVSS 1.8
CVE-2022-45438
MEDIUM
Apache Superset <=1.5.2 and 2.0.0 - Unauthenticated Exposure of Dashboard Metadata via REST API
CVSS 5.3
CVE-2022-24913
MEDIUM
java-merge-sort < 1.1.0 - Insecure Temporary File via StdTempFileProvider
CVSS 5.5
Details
Vulnerabilities
732