CWE-668

Exposure of Resource to Wrong Sphere

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

719 vulnerabilities with CWE-668
CVE-2021-41989 HIGH
Qlik QlikView < 12.60.20100.0 - Temporary File Creation in Directory with Insecure Permissions
CVSS 7.8
CVE-2021-41988 HIGH
Qlik NPrinting Designer < 21.14.3.0 - Temporary File Creation in Directory with Insecure Permissions
CVSS 7.8
CVE-2021-26343 MEDIUM
AMD EPYC 7003 Firmware < milanpi_1.0.0.3 - Information Disclosure via ASP BIOS and DRTM Commands
CVSS 5.5
CVE-2021-3859 HIGH
Undertow - Denial of Service
CVSS 7.5
CVE-2021-0734 MEDIUM
Android 13 - Unauthenticated Local Information Disclosure via Installed App Detection Side Channel
CVSS 5.5
CVE-2021-46687 MEDIUM
JFrog Artifactory <7.31.10,6.23.38 - Info Disclosure
CVSS 4.9
CVE-2021-20551 LOW
IBM Jazz Team Server - Info Disclosure
CVSS 3.3
CVE-2021-36710 HIGH
ToaruOS 1.99.2 - Privilege Escalation via MMU and GDT Manipulation
CVSS 8.8
CVE-2021-43066 HIGH
FortiClientWindows < 6.4.7 - Privilege Escalation via MSI Installer
CVSS 8.4
CVE-2021-42255 HIGH
AppGuard Enterprise < 6.7.100.1 - Privilege Escalation via Insecure Temporary File Permissions
CVSS 7.8
CVE-2021-39777 MEDIUM
Android 12L - Unauthenticated Local Information Disclosure via Telephony App Installation Check
CVSS 5.5
CVE-2021-22572 MEDIUM
File.createTempFile - Info Disclosure
CVSS 5.5
CVE-2021-4180 MEDIUM
openstack-tripleo-heat-templates < 11.6.1 - Sensitive Information Exposure via www_authenticate_uri
CVSS 4.3
CVE-2021-27424 MEDIUM
GE Multilin UR Firmware < 8.10 - Unauthorized Information Exposure via MODBUS Register
CVSS 5.3
CVE-2021-28488 MEDIUM
Ericsson Network Manager < 21.2 - Incorrect Access Control in AMOS Authorization Group
CVSS 6.5
CVE-2021-42714 HIGH
Splashtop < 3.5.0.0 - Exposure of Resource to Wrong Sphere via Temporary File in Directory with Insecure Permissions
CVSS 7.8
CVE-2021-42713 HIGH
Splashtop < 3.4.8.4 - Exposure of Resource to Wrong Sphere via Temporary File Creation
CVSS 7.8
CVE-2021-42712 HIGH
Splashtop Streamer < 3.5.0.0 - Temporary File Creation in Directory with Insecure Permissions
CVSS 7.8
CVE-2021-45420 CRITICAL
Emerson Dixell XWEB-500 Firmware - Unauthenticated Arbitrary File Write via logo_extra_upload.cgi
CVSS 9.8
CVE-2021-45402 MEDIUM
Linux Kernel < 5.16 - Information Disclosure via BPF Verifier Bounds Check
CVSS 5.5
CVE-2021-33096 MEDIUM
Intel 82599EN/ES/EB Firmware < 5.13.4 - Authenticated Denial of Service via Network on Chip Resource Isolation
CVSS 5.5
CVE-2021-46354 HIGH
Thinfinity VirtualUI <3.0 - Info Disclosure
CVSS 7.5
CVE-2021-42641 HIGH
PrinterLogic Web Stack <= 19.1.1.13 SP9 - Unauthenticated Insecure Direct Object Reference
CVSS 7.5
CVE-2021-42640 CRITICAL
PrinterLogic Web Stack <= 19.1.1.13 SP9 - Unauthenticated Insecure Direct Object Reference
CVSS 9.1
CVE-2021-24868 MEDIUM
Document Embedder <1.7.9 - Info Disclosure
CVSS 4.3
Details
Vulnerabilities 719