CWE-668

Exposure of Resource to Wrong Sphere

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

732 vulnerabilities with CWE-668
CVE-2021-39184 MEDIUM
Electron < 11.5.0, 12.1.0, 13.3.0 - Unauthorized File Content Exposure via Thumbnail API
CVSS 6.8
CVE-2021-40497 MEDIUM
SAP BusinessObjects Analysis <430 - Info Disclosure
CVSS 5.3
CVE-2021-40496 MEDIUM
SAP NetWeaver ABAP - Authenticated Data Exposure via ICM Authentication Function
CVSS 4.3
CVE-2021-41094 MEDIUM
Wire 3.68-3.69 - Unauthenticated Encryption at Rest Bypass via Passcode Disabling
CVSS 4.2
CVE-2021-22869 CRITICAL
GitHub Enterprise Server - Privilege Escalation
CVSS 9.8
CVE-2021-41088 HIGH
Elvish < 0.14.0 - Origin Validation Error in Web UI Backend
CVSS 8.0
CVE-2021-22009 HIGH
VMware Cloud Foundation 3.0-4.0 and vCenter Server - Denial of Service via VAPI Service Memory Exhaustion
CVSS 7.5
CVE-2021-34723 MEDIUM
Cisco IOS XE SD-WAN - Authenticated Arbitrary File Write via CLI Command
CVSS 6.7
CVE-2021-40639 HIGH
Jfinal CMS 5.1.0 - Incorrect Authorization via /classes/conf/db.properties
CVSS 7.5
CVE-2021-23034 HIGH
BIG-IP <16.1.0, 15.1.x <15.1.3.1 - DoS
CVSS 7.5
CVE-2021-39212 MEDIUM
ImageMagick 6.9.12-0-6.9.12-22 - Race Condition in Policy Enforcement
CVSS 4.4
CVE-2021-28568 MEDIUM
Adobe Genuine Service < 7.1 - Authenticated Privilege Escalation via Insecure File Permissions
CVSS 5.8
CVE-2021-36002 MEDIUM
Adobe Captivate <11.5.5 - Privilege Escalation
CVSS 5.0
CVE-2021-30921 MEDIUM
iOS <14.5, iPadOS <14.5 - Info Disclosure
CVSS 5.5
CVE-2021-28633 MEDIUM
Adobe Creative Cloud Desktop Application < 2.4 - Arbitrary File Overwrite via Insecure Temporary File Creation
CVSS 6.1
CVE-2021-29280 MEDIUM
TP-Link TL-WR840N Firmware - Buffer Overflow via ARP Poisoning
CVSS 6.4
CVE-2021-38712 HIGH
OneNav 0.9.12 - Information Disclosure via Database File Exposure
CVSS 7.5
CVE-2021-37704 MEDIUM
phpfastcache < 6.1.5 - Exposure of Sensitive Information via Unprotected Vendor Directory
CVSS 5.4
CVE-2021-22385 HIGH
Huawei EMUI and Magic UI - Local Kernel Code Execution
CVSS 7.8
CVE-2021-22420 HIGH
HarmonyOS - External Control of System or Configuration Setting
CVSS 7.8
CVE-2021-32788 MEDIUM
Discourse < 2.7.7 - Unauthorized Post Creator Exposure via Whisper Post Handling
CVSS 4.3
CVE-2021-32760 MEDIUM
containerd <1.4.8-1.5.4 - Privilege Escalation
CVSS 5.0
CVE-2021-0588 MEDIUM
Android 8.1-9 - Unauthenticated SMS Disclosure via MceStateMachine
CVSS 5.5
CVE-2021-25432 LOW
Samsung Members <2.4.85.11-3.9.10.11 - Info Disclosure
CVSS 3.3
CVE-2021-20461 MEDIUM
IBM Cognos Analytics <11.1 - Privilege Escalation
CVSS 6.5
Details
Vulnerabilities 732