CWE-668
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
732 vulnerabilities with CWE-668
CVE-2021-4180
MEDIUM
openstack-tripleo-heat-templates < 11.6.1 - Sensitive Information Exposure via www_authenticate_uri
CVSS 4.3
CVE-2021-27424
MEDIUM
GE Multilin UR Firmware < 8.10 - Unauthorized Information Exposure via MODBUS Register
CVSS 5.3
CVE-2021-28488
MEDIUM
Ericsson Network Manager < 21.2 - Incorrect Access Control in AMOS Authorization Group
CVSS 6.5
CVE-2021-42714
HIGH
Splashtop < 3.5.0.0 - Exposure of Resource to Wrong Sphere via Temporary File in Directory with Insecure Permissions
CVSS 7.8
CVE-2021-42713
HIGH
Splashtop < 3.4.8.4 - Exposure of Resource to Wrong Sphere via Temporary File Creation
CVSS 7.8
CVE-2021-42712
HIGH
Splashtop Streamer < 3.5.0.0 - Temporary File Creation in Directory with Insecure Permissions
CVSS 7.8
CVE-2021-45420
CRITICAL
Emerson Dixell XWEB-500 Firmware - Unauthenticated Arbitrary File Write via logo_extra_upload.cgi
CVSS 9.8
CVE-2021-45402
MEDIUM
Linux Kernel < 5.16 - Information Disclosure via BPF Verifier Bounds Check
CVSS 5.5
CVE-2021-33096
MEDIUM
Intel 82599EN/ES/EB Firmware < 5.13.4 - Authenticated Denial of Service via Network on Chip Resource Isolation
CVSS 5.5
CVE-2021-46354
HIGH
Thinfinity VirtualUI <3.0 - Info Disclosure
CVSS 7.5
CVE-2021-42641
HIGH
PrinterLogic Web Stack <= 19.1.1.13 SP9 - Unauthenticated Insecure Direct Object Reference
CVSS 7.5
CVE-2021-42640
CRITICAL
PrinterLogic Web Stack <= 19.1.1.13 SP9 - Unauthenticated Insecure Direct Object Reference
CVSS 9.1
CVE-2021-24868
MEDIUM
Document Embedder <1.7.9 - Info Disclosure
CVSS 4.3
CVE-2021-24775
MEDIUM
Document Embedder <1.7.5 - Info Disclosure
CVSS 5.3
CVE-2021-44049
HIGH
CyberArk Endpoint Privilege Manager 11.5.3.328-11.5.4.355 - Local Privilege Escalation via Trojan Horse Procmon64.exe
CVSS 7.8
CVE-2021-39628
LOW
Android 10-11 - Local Information Disclosure via StatusBar Notification Logic Error
CVSS 3.3
CVE-2021-42749
MEDIUM
Beaver Themer - Unauthenticated Content Visibility Bypass via Conditional Logic
CVSS 5.3
CVE-2021-39971
HIGH
HarmonyOS < 2.0 - Exposure of Resource to Wrong Sphere in Password Vault
CVSS 7.5
CVE-2021-37112
MEDIUM
HarmonyOS < 2.0 - External Control of System or Configuration Setting in Hisuite Module
CVSS 5.3
CVE-2021-1918
MEDIUM
Qualcomm Snapdragon Firmware - Information Exposure via Improper Resource Allocation
CVSS 6.5
CVE-2021-45708
HIGH
abomination <2021-10-17 - Info Disclosure
CVSS 7.5
CVE-2021-21878
MEDIUM
Lantronix PremierWave 2050 8.9.0.0R4 Authenticated Local File Inclusion
CVSS 4.9
CVE-2021-43893
HIGH
Windows Encrypting File System - Privilege Escalation
CVSS 7.5
CVE-2021-43216
MEDIUM
Microsoft LSA Server - Info Disclosure
CVSS 6.5
CVE-2021-41065
HIGH
Listary < 6 - Unauthenticated Privilege Escalation via Named Pipe Impersonation
CVSS 7.3
Details
Vulnerabilities
732