CWE-668

Exposure of Resource to Wrong Sphere

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

732 vulnerabilities with CWE-668
CVE-2022-39870 MEDIUM
Samsung SmartThings < 1.7.89.0 - Improper Access Control via PUSH_MESSAGE_RECEIVED Broadcast
CVSS 4.0
CVE-2022-39869 MEDIUM
Samsung SmartThings < 1.7.89.0 - Improper Access Control via REMOVE_PERSISTENT_BANNER Broadcast
CVSS 4.0
CVE-2022-23950 HIGH
Keylime <6.3.0 - Privilege Escalation
CVSS 7.5
CVE-2022-40234 MEDIUM
IBM Spectrum Protect Plus < 10.1.12 - Private Key Exposure in TLS Certificate Upload
CVSS 5.9
CVE-2022-34867 HIGH
WP Libre Form 2 2.0.0-2.0.8 - Unauthenticated Sensitive Information Disclosure
CVSS 7.3
CVE-2022-2403 MEDIUM
OpenShift >=4.9 - Authenticated Credentials Leak via oauth-serving-cert ConfigMap
CVSS 6.5
CVE-2022-1902 HIGH
Red Hat Advanced Cluster Security - Privilege Escalation
CVSS 8.8
CVE-2022-0852 MEDIUM
convert2rhel < 0.26 - Unauthorized Password Exposure via Command Line
CVSS 5.5
CVE-2022-29850 HIGH
Lexmark Multiple Models Firmware Persistence Across Reboots via Compromised Device
CVSS 8.1
CVE-2022-2610 MEDIUM
Google Chrome <104.0.5112.79 - Info Disclosure
CVSS 6.5
CVE-2022-35936 HIGH
Ethermint <0.17.2 - Info Disclosure
CVSS 8.2
CVE-2022-1875 MEDIUM
Google Chrome <102.0.5005.61 - Info Disclosure
CVSS 4.3
CVE-2022-1873 MEDIUM
Google Chrome <102.0.5005.61 - Info Disclosure
CVSS 6.5
CVE-2022-1637 MEDIUM
Google Chrome < 101.0.4951.64 - Cross-Origin Data Leak via Web Contents
CVSS 4.3
CVE-2022-1501 MEDIUM
Google Chrome < 101.0.4951.41 - Cross-Origin Data Leak via Iframe
CVSS 6.5
CVE-2022-1498 MEDIUM
Google Chrome < 101.0.4951.41 - Cross-Origin Data Leak via HTML Parser
CVSS 4.3
CVE-2022-1488 MEDIUM
Google Chrome < 101.0.4951.41 - Cross-Origin Data Leak via Malicious Extension
CVSS 4.3
CVE-2022-1137 MEDIUM
Google Chrome < 100.0.4896.60 - Information Disclosure via Malicious Extension
CVSS 6.5
CVE-2022-34047 HIGH
Wavlink WN530HG4 M30HG4.V5030.191116 - Info Disclosure
CVSS 7.5
CVE-2022-23825 MEDIUM
AMD Processors - Info Disclosure
CVSS 6.5
CVE-2022-34765 MEDIUM
X80 advanced RTU Communication Module - Path Traversal
CVSS 5.5
CVE-2022-32249 HIGH
SAP Business One - Exposure of Sensitive Information via HANA Cockpit Data Volume
CVSS 7.5
CVE-2022-29901 MEDIUM
Intel Core i7 Firmware - Spectre Retpoline Bypass Exposes Sensitive Information
CVSS 5.6
CVE-2022-33700 LOW
TelephonyUI <SMR Jul-2022 Release 1 - Info Disclosure
CVSS 2.0
CVE-2022-33699 LOW
TelephonyUI <SMR Jul-2022 Release 1 - Info Disclosure
CVSS 2.0
Details
Vulnerabilities 732