CWE-668
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
732 vulnerabilities with CWE-668
CVE-2021-28623
MEDIUM
Adobe Premiere Elements < 5.3 - Unauthenticated Privilege Escalation via Insecure Temporary File Creation
CVSS 5.5
CVE-2021-28597
MEDIUM
Adobe Photoshop Elements < 5.3 - Unauthenticated Insecure Temporary File Creation
CVSS 5.5
CVE-2021-24001
MEDIUM
Firefox < 88.0 - Unauthorized Session History Manipulation via Compromised Content Process
CVSS 4.3
CVE-2021-25652
MEDIUM
Avaya Aura Appliance Virtualization Platform 8.0.0.0-8.1.3.1 - Unauthorized Information Disclosure
CVSS 4.9
CVE-2021-0542
MEDIUM
Android 11 - Unauthenticated Local Information Disclosure via BeamTransferManager
CVSS 5.5
CVE-2021-21382
HIGH
restund < 0.4.15 - Unauthenticated Administrative Command Execution via TURN Relay
CVSS 8.6
CVE-2021-22897
MEDIUM
curl 7.61.0-7.76.1 - Data Element Exposure via CURLOPT_SSL_CIPHER_LIST
CVSS 5.3
CVE-2021-34539
HIGH
CubeCoders AMP < 2.1.1.8 - Authenticated Remote Code Execution via Java Version Setting
CVSS 7.2
CVE-2021-33669
HIGH
SAP Mobile SDK Certificate Provider < 3.0.8 - Insecure Temporary File Storage
CVSS 7.8
CVE-2021-22550
MEDIUM
Google Asylo <0.6.3 - Memory Corruption
CVSS 6.5
CVE-2021-22549
MEDIUM
Google Asylo < 0.6.2 - Arbitrary Trusted Memory Overwrite via Out-of-range Pointer Offset
CVSS 6.5
CVE-2021-22118
HIGH
Spring Framework 5.2.0-5.2.14 - Authenticated Privilege Escalation via WebFlux Temporary Storage Directory
CVSS 7.8
CVE-2021-31154
HIGH
pleaseedit <0.4 - Privilege Escalation
CVSS 7.8
CVE-2021-20999
CRITICAL
Weidmüller u-controls/IoT-Gateways <1.12.1 - DoS
CVSS 9.4
CVE-2021-26309
LOW
TeamCity < 2020.2.2.85899 - Information Disclosure via Insecure Temporary File Permissions
CVSS 3.3
CVE-2021-21430
MEDIUM
OpenAPI Generator < 5.1.1 - Insecure Temporary File Creation via File.createTempFile
CVSS 6.2
CVE-2021-21428
CRITICAL
openapi-generator < 5.1.0 - Insecure Temporary File Permissions
CVSS 9.3
CVE-2021-1438
MEDIUM
Cisco Wide Area Application Services < 6.4.5a - Authenticated Arbitrary File Read via CLI Command Injection
CVSS 5.5
CVE-2021-31410
HIGH
Vaadin Designer <4.6.3 - Info Disclosure
CVSS 8.6
CVE-2021-31407
HIGH
com.vaadin:flow-server <2.4.7, Vaadin <14.4.9 - RCE
CVSS 8.6
CVE-2021-28168
MEDIUM
Eclipse Jersey 2.28-2.33 & 3.0.0-3.0.1 - Info Disclosure
CVSS 6.2
CVE-2021-22539
HIGH
VScode-bazel <0.4.1 - Code Injection
CVSS 8.2
CVE-2021-25314
HIGH
SUSE Linux Enterprise High Availability <15-SP2 - Privilege Escalation
CVSS 7.8
CVE-2021-25364
MEDIUM
Secure Folder <SMR APR-2021 Release 1 - Info Disclosure
CVSS 4.0
CVE-2021-25357
MEDIUM
Create Movie <SMR APR-2021 Release 1 - Info Disclosure
CVSS 5.6
Details
Vulnerabilities
732