CWE-668

Exposure of Resource to Wrong Sphere

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

719 vulnerabilities with CWE-668
CVE-2021-20999 CRITICAL
Weidmüller u-controls/IoT-Gateways <1.12.1 - DoS
CVSS 9.4
CVE-2021-26309 LOW
TeamCity < 2020.2.2.85899 - Information Disclosure via Insecure Temporary File Permissions
CVSS 3.3
CVE-2021-21430 MEDIUM
OpenAPI Generator < 5.1.1 - Insecure Temporary File Creation via File.createTempFile
CVSS 6.2
CVE-2021-21428 CRITICAL
openapi-generator < 5.1.0 - Insecure Temporary File Permissions
CVSS 9.3
CVE-2021-1438 MEDIUM
Cisco Wide Area Application Services < 6.4.5a - Authenticated Arbitrary File Read via CLI Command Injection
CVSS 5.5
CVE-2021-31410 HIGH
Vaadin Designer <4.6.3 - Info Disclosure
CVSS 8.6
CVE-2021-31407 HIGH
com.vaadin:flow-server <2.4.7, Vaadin <14.4.9 - RCE
CVSS 8.6
CVE-2021-28168 MEDIUM
Eclipse Jersey 2.28-2.33 & 3.0.0-3.0.1 - Info Disclosure
CVSS 6.2
CVE-2021-22539 HIGH
VScode-bazel <0.4.1 - Code Injection
CVSS 8.2
CVE-2021-25314 HIGH
SUSE Linux Enterprise High Availability <15-SP2 - Privilege Escalation
CVSS 7.8
CVE-2021-25364 MEDIUM
Secure Folder <SMR APR-2021 Release 1 - Info Disclosure
CVSS 4.0
CVE-2021-25357 MEDIUM
Create Movie <SMR APR-2021 Release 1 - Info Disclosure
CVSS 5.6
CVE-2021-25352 MEDIUM
Bixby Voice <3.0.52.14 - Privilege Escalation
CVSS 5.5
CVE-2021-1423 MEDIUM
Cisco Aironet Access Point Software - Authenticated Arbitrary File Write via CLI Command
CVSS 4.4
CVE-2021-21334 MEDIUM
containerd <1.3.10 and 1.4.0-<1.4.4 - Unintended Environment Variable Exposure via CRI Implementation
CVSS 6.3
CVE-2021-23958 MEDIUM
Firefox < 85.0 - Unintended Information Leak via Screen Sharing State Transfer
CVSS 6.5
CVE-2021-27236 CRITICAL
Mutare Voice 3.0.0-3.3.7 - Unauthenticated Local File Inclusion and Remote Code Execution via getfile.asp
CVSS 9.8
CVE-2021-21290 MEDIUM
Netty <4.1.59.Final - Info Disclosure
CVSS 6.2
CVE-2020-22647 CRITICAL
DepositGame 1.0 - Info Disclosure
CVSS 9.1
CVE-2020-27601 LOW
BigBlueButton <2.2.7 - Info Disclosure
CVSS 3.5
CVE-2020-25459 HIGH
WeBank FATE 0.1-1.4.2 - Sensitive Information Exposure via sync_tree Function
CVSS 7.5
CVE-2020-36532 MEDIUM
Klapp App - Unauthenticated Exposure of Sensitive Information via Authorization Component
CVSS 4.3
CVE-2020-4989 MEDIUM
IBM Rational Team Concert - Exposure to Wrong Actor
CVSS 4.3
CVE-2020-13670 HIGH
Drupal Core 8.8.0-8.8.9, 8.9.0-8.9.5, 9.0.0-9.0.5 - Unauthenticated Information Disclosure in File Module
CVSS 7.5
CVE-2020-20948 HIGH
jeecg v3.8 - Arbitrary File Download via LocalPath Variable
CVSS 7.5
Details
Vulnerabilities 719