CWE-668

Exposure of Resource to Wrong Sphere

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

732 vulnerabilities with CWE-668
CVE-2023-21611 HIGH
Adobe Acrobat Reader <22.003.20282 - Privilege Escalation
CVSS 7.8
CVE-2023-22497 MEDIUM
netdata < 1.37.0 - Improper Authentication via MACHINE_GUID as API Key
CVSS 6.5
CVE-2023-21536 MEDIUM
Event Tracing for Windows - Info Disclosure
CVSS 4.7
CVE-2022-49509 HIGH
Linux Kernel 5.9-5.15.45, 5.16.0-5.17.13, 5.18.0-5.18.2 - Use-After-Free in max9286 I2C Driver
CVSS 7.1
CVE-2022-48757 HIGH
Linux Kernel - Information Disclosure via /proc/net/ptype
CVSS 7.1
CVE-2022-20917 MEDIUM
Cisco Jabber < 12.6.6, < 12.8.8, < 14.1.4 - Authenticated XMPP Message Manipulation via Nested Message Handling
CVSS 4.3
CVE-2022-46901 HIGH
Vocera Report Server & Voice Server <5.8 - Info Disclosure
CVSS 7.5
CVE-2022-43684 CRITICAL
ServiceNow Quebec Rome San Diego Tokyo Utah - Authenticated Exposure of Sensitive Information via ACL Bypass
CVSS 9.9
CVE-2022-40525 HIGH
Qualcomm CSR8811 and IPQ/QCA/QCN Firmware - Information Disclosure via Side Channel Analysis
CVSS 7.1
CVE-2022-40523 HIGH
Qualcomm 9205 LTE Modem Firmware - Information Disclosure via Indirect Branch Misprediction
CVSS 7.1
CVE-2022-40210 MEDIUM
Intel Data Center Manager < 5.0.1 - Authenticated Privilege Escalation via Session Data Exposure
CVSS 6.8
CVE-2022-38087 MEDIUM
Intel(R) Processors - Info Disclosure
CVSS 4.1
CVE-2022-47338 HIGH
Android - Denial of Service in Telecom Service
CVSS 7.1
CVE-2022-46257 MEDIUM
GitHub Enterprise Server - Info Disclosure
CVSS 4.3
CVE-2022-44310 HIGH
ecdh < 0.2.0 - Exposure of Resource to Wrong Sphere via Invalid Public Key
CVSS 7.5
CVE-2022-39952 CRITICAL
Fortinet FortiNAC keyUpload.jsp arbitrary file write
CVSS 9.8
CVE-2022-34387 MEDIUM
Dell SupportAssist < 3.11.4 (Home) / < 3.2.0 (Business) - Privilege Escalation via Insecure Temporary File
CVSS 6.4
CVE-2022-34364 MEDIUM
BSAFE SSL-J <6.5, 7.0 - Info Disclosure
CVSS 4.4
CVE-2022-4903 MEDIUM
CodenameOne < 7.0.71 - Use of Implicit Intent for Sensitive Communication
CVSS 5.0
CVE-2022-34452 LOW
Dell PowerPath Management Appliance 3.0-3.3 - Authenticated Sensitive Information Disclosure via Log Files
CVSS 2.7
CVE-2022-46756 HIGH
Dell VxRail < 7.0.410 - Container Escape and OS Command Execution
CVSS 8.2
CVE-2022-22732 LOW
EcoStruxure Power Commission < 2.22 - Exposure of Resource to Wrong Sphere via Fetch Request
CVSS 3.9
CVE-2022-26329 LOW
NetIQ Identity Manager <4.8.5 - Info Disclosure
CVSS 1.8
CVE-2022-45438 MEDIUM
Apache Superset <=1.5.2 and 2.0.0 - Unauthenticated Exposure of Dashboard Metadata via REST API
CVSS 5.3
CVE-2022-24913 MEDIUM
java-merge-sort < 1.1.0 - Insecure Temporary File via StdTempFileProvider
CVSS 5.5
Details
Vulnerabilities 732