CWE-668

Exposure of Resource to Wrong Sphere

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

719 vulnerabilities with CWE-668
CVE-2021-24775 MEDIUM
Document Embedder <1.7.5 - Info Disclosure
CVSS 5.3
CVE-2021-44049 HIGH
CyberArk Endpoint Privilege Manager 11.5.3.328-11.5.4.355 - Local Privilege Escalation via Trojan Horse Procmon64.exe
CVSS 7.8
CVE-2021-39628 LOW
Android 10-11 - Local Information Disclosure via StatusBar Notification Logic Error
CVSS 3.3
CVE-2021-42749 MEDIUM
Beaver Themer - Unauthenticated Content Visibility Bypass via Conditional Logic
CVSS 5.3
CVE-2021-39971 HIGH
HarmonyOS < 2.0 - Exposure of Resource to Wrong Sphere in Password Vault
CVSS 7.5
CVE-2021-37112 MEDIUM
HarmonyOS < 2.0 - External Control of System or Configuration Setting in Hisuite Module
CVSS 5.3
CVE-2021-1918 MEDIUM
Qualcomm Snapdragon Firmware - Information Exposure via Improper Resource Allocation
CVSS 6.5
CVE-2021-45708 HIGH
abomination <2021-10-17 - Info Disclosure
CVSS 7.5
CVE-2021-21878 MEDIUM
Lantronix PremierWave 2050 8.9.0.0R4 Authenticated Local File Inclusion
CVSS 4.9
CVE-2021-43893 HIGH
Windows Encrypting File System - Privilege Escalation
CVSS 7.5
CVE-2021-43216 MEDIUM
Microsoft LSA Server - Info Disclosure
CVSS 6.5
CVE-2021-41065 HIGH
Listary < 6 - Unauthenticated Privilege Escalation via Named Pipe Impersonation
CVSS 7.3
CVE-2021-44524 CRITICAL
SiPass integrated V2.76/V2.80/V2.85 and Siveillance Identity < V1.6.284.0 - Unauthenticated Improper Authentication
CVSS 9.8
CVE-2021-44523 CRITICAL
SiPass integrated V2.76/V2.80/V2.85 and Siveillance Identity < V1.6.284.0 - Unauthenticated Database Access
CVSS 9.1
CVE-2021-44522 HIGH
SiPass integrated V2.76, V2.80, V2.85 and Siveillance Identity < V1.6.284.0 - Unauthenticated Message Broker Access
CVSS 7.5
CVE-2021-39915 MEDIUM
GitLab 13.0-14.3.5, 14.4-14.4.3, 14.5-14.5.1 - Unauthenticated Exposure of Project Access Token Names via GraphQL API
CVSS 5.3
CVE-2021-38931 MEDIUM
IBM Db2 <11.1,11.5 - Info Disclosure
CVSS 6.5
CVE-2021-22568 HIGH
Dart Software Development Kit < 2.15.0 - Unauthenticated OAuth2 Token Exposure via pub publish Command
CVSS 8.8
CVE-2021-38505 MEDIUM
Firefox < 94.0 and Firefox ESR < 91.3.0 - Sensitive Data Exposure via Cloud Clipboard
CVSS 6.5
CVE-2021-25515 MEDIUM
SemRewardManager <SMR Dec-2021 Release 1 - Info Disclosure
CVSS 4.0
CVE-2021-29115 MEDIUM
Esri ArcGIS Enterprise < 10.9 - Information Disclosure via ArcGIS Service Directory
CVSS 5.3
CVE-2021-36198 HIGH
Johnsoncontrols Johnson Controls Kantech EntraPass <= 8.40 - Information Disclosure
CVSS 8.3
CVE-2021-23264 HIGH
Crafter CMS 3.1.0 through 3.1.15 - Unauthenticated Remote Index Manipulation
CVSS 8.1
CVE-2021-23263 MEDIUM
Crafter CMS 3.1.0-3.1.14 - Unauthenticated Sensitive File Exposure via FreeMarker
CVSS 5.9
CVE-2021-38004 MEDIUM
Google Chrome <95.0.4638.69 - Info Disclosure
CVSS 4.3
Details
Vulnerabilities 719