CWE-668
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
732 vulnerabilities with CWE-668
CVE-2022-24975
HIGH
Git < 2.35.1 - Unintended Data Exposure via Mirror Clone Documentation Gap
CVSS 7.5
CVE-2022-0334
MEDIUM
Moodle <3.11.4-3.10.8-3.9.11 - Info Disclosure
CVSS 4.3
CVE-2022-22154
MEDIUM
Juniper Junos 16.1R1-18.4R3, 19.1-19.1R3, 19.2-19.2R3 - Denial of Service via Satellite Device Cabling Manipulation
CVSS 6.8
CVE-2022-23118
HIGH
Jenkins Debian Package Builder Plugin < 1.6.11 - OS Command Execution via Agent-Controlled Git Path
CVSS 8.8
CVE-2022-21964
MEDIUM
Remote Desktop Licensing Diagnoser - Info Disclosure
CVSS 5.5
CVE-2021-47401
MEDIUM
Linux Kernel 3.5-4.4.286 - Unprotected Kernel Memory Exposure via TTY Driver Name
CVSS 5.5
CVE-2021-46937
MEDIUM
Linux Kernel 5.15-5.15.12 - Memory Leak in DAMON Debugfs Target IDs Write
CVSS 5.5
CVE-2021-46935
MEDIUM
Linux Kernel 4.14.0-4.14.261 - Exposure of Resource to Wrong Sphere via Binder Async Free Space Accounting
CVSS 5.5
CVE-2021-46923
MEDIUM
Linux Kernel 5.12-5.15.12 - Resource Exposure via mount_setattr Reference Leak
CVSS 5.5
CVE-2021-46921
MEDIUM
Linux Kernel 4.15-4.19.188 - Exposure of Resource to Wrong Sphere via Queued Write Lock Slowpath
CVSS 5.5
CVE-2021-46917
MEDIUM
Linux Kernel 5.8-5.12 DMA Engine WQCFG Register Handling Resource Exposure
CVSS 5.5
CVE-2021-46906
MEDIUM
Linux Kernel < 4.4.274 - Information Disclosure in HID usbhid hid_submit_ctrl
CVSS 5.5
CVE-2021-30153
MEDIUM
MediaWiki <1.35.2 - Info Disclosure
CVSS 4.3
CVE-2021-41989
HIGH
Qlik QlikView < 12.60.20100.0 - Temporary File Creation in Directory with Insecure Permissions
CVSS 7.8
CVE-2021-41988
HIGH
Qlik NPrinting Designer < 21.14.3.0 - Temporary File Creation in Directory with Insecure Permissions
CVSS 7.8
CVE-2021-26343
MEDIUM
AMD EPYC 7003 Firmware < milanpi_1.0.0.3 - Information Disclosure via ASP BIOS and DRTM Commands
CVSS 5.5
CVE-2021-3859
HIGH
Undertow - Denial of Service
CVSS 7.5
CVE-2021-0734
MEDIUM
Android 13 - Unauthenticated Local Information Disclosure via Installed App Detection Side Channel
CVSS 5.5
CVE-2021-46687
MEDIUM
JFrog Artifactory <7.31.10,6.23.38 - Info Disclosure
CVSS 4.9
CVE-2021-20551
LOW
IBM Jazz Team Server - Info Disclosure
CVSS 3.3
CVE-2021-36710
HIGH
ToaruOS 1.99.2 - Privilege Escalation via MMU and GDT Manipulation
CVSS 8.8
CVE-2021-43066
HIGH
FortiClientWindows < 6.4.7 - Privilege Escalation via MSI Installer
CVSS 8.4
CVE-2021-42255
HIGH
AppGuard Enterprise < 6.7.100.1 - Privilege Escalation via Insecure Temporary File Permissions
CVSS 7.8
CVE-2021-39777
MEDIUM
Android 12L - Unauthenticated Local Information Disclosure via Telephony App Installation Check
CVSS 5.5
CVE-2021-22572
MEDIUM
File.createTempFile - Info Disclosure
CVSS 5.5
Details
Vulnerabilities
732