CWE-668
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
719 vulnerabilities with CWE-668
CVE-2021-30921
MEDIUM
iOS <14.5, iPadOS <14.5 - Info Disclosure
CVSS 5.5
CVE-2021-28633
MEDIUM
Adobe Creative Cloud Desktop Application < 2.4 - Arbitrary File Overwrite via Insecure Temporary File Creation
CVSS 6.1
CVE-2021-29280
MEDIUM
TP-Link TL-WR840N Firmware - Buffer Overflow via ARP Poisoning
CVSS 6.4
CVE-2021-38712
HIGH
OneNav 0.9.12 - Information Disclosure via Database File Exposure
CVSS 7.5
CVE-2021-37704
MEDIUM
phpfastcache < 6.1.5 - Exposure of Sensitive Information via Unprotected Vendor Directory
CVSS 5.4
CVE-2021-22385
HIGH
Huawei EMUI and Magic UI - Local Kernel Code Execution
CVSS 7.8
CVE-2021-22420
HIGH
HarmonyOS - External Control of System or Configuration Setting
CVSS 7.8
CVE-2021-32788
MEDIUM
Discourse < 2.7.7 - Unauthorized Post Creator Exposure via Whisper Post Handling
CVSS 4.3
CVE-2021-32760
MEDIUM
containerd <1.4.8-1.5.4 - Privilege Escalation
CVSS 5.0
CVE-2021-0588
MEDIUM
Android 8.1-9 - Unauthenticated SMS Disclosure via MceStateMachine
CVSS 5.5
CVE-2021-25432
LOW
Samsung Members <2.4.85.11-3.9.10.11 - Info Disclosure
CVSS 3.3
CVE-2021-20461
MEDIUM
IBM Cognos Analytics <11.1 - Privilege Escalation
CVSS 6.5
CVE-2021-28623
MEDIUM
Adobe Premiere Elements < 5.3 - Unauthenticated Privilege Escalation via Insecure Temporary File Creation
CVSS 5.5
CVE-2021-28597
MEDIUM
Adobe Photoshop Elements < 5.3 - Unauthenticated Insecure Temporary File Creation
CVSS 5.5
CVE-2021-24001
MEDIUM
Firefox < 88.0 - Unauthorized Session History Manipulation via Compromised Content Process
CVSS 4.3
CVE-2021-25652
MEDIUM
Avaya Aura Appliance Virtualization Platform 8.0.0.0-8.1.3.1 - Unauthorized Information Disclosure
CVSS 4.9
CVE-2021-0542
MEDIUM
Android 11 - Unauthenticated Local Information Disclosure via BeamTransferManager
CVSS 5.5
CVE-2021-21382
HIGH
restund < 0.4.15 - Unauthenticated Administrative Command Execution via TURN Relay
CVSS 8.6
CVE-2021-22897
MEDIUM
curl 7.61.0-7.76.1 - Data Element Exposure via CURLOPT_SSL_CIPHER_LIST
CVSS 5.3
CVE-2021-34539
HIGH
CubeCoders AMP < 2.1.1.8 - Authenticated Remote Code Execution via Java Version Setting
CVSS 7.2
CVE-2021-33669
HIGH
SAP Mobile SDK Certificate Provider < 3.0.8 - Insecure Temporary File Storage
CVSS 7.8
CVE-2021-22550
MEDIUM
Google Asylo <0.6.3 - Memory Corruption
CVSS 6.5
CVE-2021-22549
MEDIUM
Google Asylo < 0.6.2 - Arbitrary Trusted Memory Overwrite via Out-of-range Pointer Offset
CVSS 6.5
CVE-2021-22118
HIGH
Spring Framework 5.2.0-5.2.14 - Authenticated Privilege Escalation via WebFlux Temporary Storage Directory
CVSS 7.8
CVE-2021-31154
HIGH
pleaseedit <0.4 - Privilege Escalation
CVSS 7.8
Details
Vulnerabilities
719