CWE-668

Exposure of Resource to Wrong Sphere

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

732 vulnerabilities with CWE-668
CVE-2022-45935 MEDIUM
Apache James < 3.7.2 - Unprotected User Data Exposure via Temporary Files
CVSS 5.5
CVE-2022-0337 MEDIUM
Google Chrome <97.0.4692.71 - Info Disclosure
CVSS 6.5
CVE-2022-48198 CRITICAL
ntpd_driver < 1.3.0 and 2.x < 2.2.0 - Unauthenticated Exposure of Resource to Wrong Sphere via time_ref_topic Parameter
CVSS 9.8
CVE-2022-4817 LOW
centic9 jgit-cookbook - Insecure Temp File
CVSS 3.1
CVE-2022-45895 MEDIUM
Planet eStream < 6.72.10.07 - Sensitive Information Exposure via ON Cookie and WhoAmI Endpoint
CVSS 6.5
CVE-2022-38474 MEDIUM
Firefox < 104.0 for Android - Unauthenticated Audio Recording Without Notification
CVSS 4.3
CVE-2022-31596 MEDIUM
SAP BusinessObjects <430 - Info Disclosure
CVSS 6.0
CVE-2022-38599 MEDIUM
Teleport v3.2.2 v3.5.6-rc6 v3.6.3-b2 - Information Leak via /user/get-role-list
CVSS 6.5
CVE-2022-32221 CRITICAL
curl - Exposure of Sensitive Information via Reused Handle Logic
CVSS 9.8
CVE-2022-41971 MEDIUM
Nextcloud Talk 12.0.0-12.2.7 - Unauthorized Video Stream Access After Removal
CVSS 4.8
CVE-2022-43901 MEDIUM
IBM WebSphere Automation <1.4.3 - Info Disclosure
CVSS 5.7
CVE-2022-1911 MEDIUM
M-Files Server <22.6.11534.1, <22.6.11505.0 - Info Disclosure
CVSS 5.3
CVE-2022-21126 HIGH
htsjdk < 3.0.1 - Insecure Temporary Directory Creation in IOUtil.createTempDir()
CVSS 7.3
CVE-2022-41954 LOW
mpxj < 10.14.1 - Insecure Temporary File Permissions on Unix-like Systems
CVSS 3.3
CVE-2022-38813 HIGH
PHPGurukul Blood Donor Mgmt <1.0 - Info Disclosure
CVSS 8.1
CVE-2022-41946 MEDIUM
PostgreSQL JDBC Driver 42.2.0-42.2.27 - Insecure Temporary File Creation via InputStream Handling
CVSS 4.7
CVE-2022-3952 LOW
ManyDesigns Portofino < 5.3.3 - Insecure Temporary File Permissions in WarFileLauncher.java
CVSS 2.6
CVE-2022-41874 LOW
Tauri <1.0.7-1.1.2 - Info Disclosure
CVSS 2.6
CVE-2022-3866 MEDIUM
HashiCorp Nomad <1.4.2 - Info Disclosure
CVSS 5.0
CVE-2022-2882 MEDIUM
GitLab CE/EE <15.2.5, <15.3.4, <15.4.1 - Info Disclosure
CVSS 5.5
CVE-2022-39349 MEDIUM
Tasks.org < 12.7.1 - Unintended Proxy via ShareLinkActivity File Path Handling
CVSS 5.5
CVE-2022-39309 MEDIUM
GoCD < 21.1.0 - Authenticated Sensitive Data Exposure via Symmetric Key Leak
CVSS 4.9
CVE-2022-39015 MEDIUM
BOE AdminTools/BOE SDK - Info Disclosure
CVSS 6.5
CVE-2022-26121 LOW
FortiAnalyzer FortiManager GUI <7.0.4 - Info Disclosure
CVSS 3.7
CVE-2022-39871 MEDIUM
Samsung SmartThings < 1.7.89.0 - Improper Access Control in cloudNotificationManager.java
CVSS 4.0
Details
Vulnerabilities 732