CWE-668
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
732 vulnerabilities with CWE-668
CVE-2020-5386
HIGH
Dell EMC Elastic Cloud Storage < 3.5.0.0 - Unauthenticated Sensitive Data Exposure via Directory Table Objects
CVSS 7.5
CVE-2020-25073
MEDIUM
FreedomBox < 20.13 - Unauthenticated Sensitive Information Exposure via Apache /server-status
CVSS 5.3
CVE-2020-13946
MEDIUM
Apache Cassandra < 2.1.22, 2.2.18, 3.0.22, 3.11.8, 4.0-beta2 - Credential Exposure via JMX RMI
CVSS 5.9
CVE-2020-13472
MEDIUM
Gigadevice GD32F103 - Info Disclosure
CVSS 4.6
CVE-2020-13470
MEDIUM
Gigadevice GD32F103/GD32F130 - Info Disclosure
CVSS 4.6
CVE-2020-13469
MEDIUM
Gigadevice GD32VF103 - Info Disclosure
CVSS 4.6
CVE-2020-11934
MEDIUM
Ubuntu Linux - Unintended Access Restriction Bypass via snapctl user-open XDG_DATA_DIRS Manipulation
CVSS 5.9
CVE-2020-15816
HIGH
WD Discovery < 4.0.251.0 - Unauthenticated Remote Code Execution via DYLD Environment Variable Injection
CVSS 8.8
CVE-2020-14064
MEDIUM
IceWarp Email Server 12.3.0.1 - Incorrect Access Control
CVSS 6.5
CVE-2020-12020
MEDIUM
Baxter ExactaMix EM 2400 and EM1200 - Unauthorized Operating System Access via Startup Script
CVSS 6.1
CVE-2020-10271
CRITICAL
MiR Robot Firmware < 2.8.1.1 - Unauthenticated ROS Computational Graph Exposure
CVSS 9.8
CVE-2020-9291
MEDIUM
FortiClient < 6.0.9 - Privilege Escalation via Temporary File Symbolic Link Attack
CVSS 6.3
CVE-2020-6774
CRITICAL
Bosch Recording Station Firmware - Unauthenticated Improper Access Control in Kiosk Mode
CVSS 9.3
CVE-2020-6490
MEDIUM
Google Chrome < 83.0.4103.61 - Cross-Origin Data Leak via Loader Insufficient Data Validation
CVSS 4.3
CVE-2020-13240
MEDIUM
Dolibarr 11.0.4 - Stored Cross-Site Scripting via File Extension Bypass
CVSS 5.4
CVE-2020-11931
LOW
pulseaudio < 1.8.0 - Improper Access Control via Snap Policy Module Unload
CVSS 3.3
CVE-2020-1945
MEDIUM
Apache Ant 1.1-1.9.14 and 1.10.0-1.10.7 - Information Disclosure and Arbitrary File Write via Temporary Directory
CVSS 6.3
CVE-2020-12687
MEDIUM
Serpico < 1.3.3 - Authenticated Exposure of Resource to Wrong Sphere via Admin Attachments Backup Endpoint
CVSS 6.5
CVE-2020-3315
MEDIUM
Cisco Firepower Threat Defense < 6.6.0 - Unauthenticated File Policy Bypass via Crafted HTTP Packets
CVSS 5.3
CVE-2020-12142
MEDIUM
Silver Peak Unity Orchestrator <8.9.2 - Authenticated IPSec UDP Key Material Exposure via CLI and REST APIs
CVSS 4.8
CVE-2020-5887
CRITICAL
BIG-IP VE <15.1.0.1 - Privilege Escalation
CVSS 9.1
CVE-2020-6442
MEDIUM
Google Chrome < 81.0.4044.92 - Cross-Origin Data Leak via Cache Implementation
CVSS 4.3
CVE-2020-11610
HIGH
xdLocalStorage < 2.0.5 - Exposure of Sensitive Data via Wildcard TargetOrigin in postMessage
CVSS 8.8
CVE-2020-11582
HIGH
Pulse Secure Pulse Connect Secure < 2020-04-06 - Unauthenticated Resource Exposure via Host Checker Applet
CVSS 8.8
CVE-2020-10867
CRITICAL
Avast Antivirus < 20.0 - Unauthenticated Task Access Bypass via aswTask RPC Endpoint
CVSS 9.8
Details
Vulnerabilities
732