CWE-668

Exposure of Resource to Wrong Sphere

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

732 vulnerabilities with CWE-668
CVE-2020-5386 HIGH
Dell EMC Elastic Cloud Storage < 3.5.0.0 - Unauthenticated Sensitive Data Exposure via Directory Table Objects
CVSS 7.5
CVE-2020-25073 MEDIUM
FreedomBox < 20.13 - Unauthenticated Sensitive Information Exposure via Apache /server-status
CVSS 5.3
CVE-2020-13946 MEDIUM
Apache Cassandra < 2.1.22, 2.2.18, 3.0.22, 3.11.8, 4.0-beta2 - Credential Exposure via JMX RMI
CVSS 5.9
CVE-2020-13472 MEDIUM
Gigadevice GD32F103 - Info Disclosure
CVSS 4.6
CVE-2020-13470 MEDIUM
Gigadevice GD32F103/GD32F130 - Info Disclosure
CVSS 4.6
CVE-2020-13469 MEDIUM
Gigadevice GD32VF103 - Info Disclosure
CVSS 4.6
CVE-2020-11934 MEDIUM
Ubuntu Linux - Unintended Access Restriction Bypass via snapctl user-open XDG_DATA_DIRS Manipulation
CVSS 5.9
CVE-2020-15816 HIGH
WD Discovery < 4.0.251.0 - Unauthenticated Remote Code Execution via DYLD Environment Variable Injection
CVSS 8.8
CVE-2020-14064 MEDIUM
IceWarp Email Server 12.3.0.1 - Incorrect Access Control
CVSS 6.5
CVE-2020-12020 MEDIUM
Baxter ExactaMix EM 2400 and EM1200 - Unauthorized Operating System Access via Startup Script
CVSS 6.1
CVE-2020-10271 CRITICAL
MiR Robot Firmware < 2.8.1.1 - Unauthenticated ROS Computational Graph Exposure
CVSS 9.8
CVE-2020-9291 MEDIUM
FortiClient < 6.0.9 - Privilege Escalation via Temporary File Symbolic Link Attack
CVSS 6.3
CVE-2020-6774 CRITICAL
Bosch Recording Station Firmware - Unauthenticated Improper Access Control in Kiosk Mode
CVSS 9.3
CVE-2020-6490 MEDIUM
Google Chrome < 83.0.4103.61 - Cross-Origin Data Leak via Loader Insufficient Data Validation
CVSS 4.3
CVE-2020-13240 MEDIUM
Dolibarr 11.0.4 - Stored Cross-Site Scripting via File Extension Bypass
CVSS 5.4
CVE-2020-11931 LOW
pulseaudio < 1.8.0 - Improper Access Control via Snap Policy Module Unload
CVSS 3.3
CVE-2020-1945 MEDIUM
Apache Ant 1.1-1.9.14 and 1.10.0-1.10.7 - Information Disclosure and Arbitrary File Write via Temporary Directory
CVSS 6.3
CVE-2020-12687 MEDIUM
Serpico < 1.3.3 - Authenticated Exposure of Resource to Wrong Sphere via Admin Attachments Backup Endpoint
CVSS 6.5
CVE-2020-3315 MEDIUM
Cisco Firepower Threat Defense < 6.6.0 - Unauthenticated File Policy Bypass via Crafted HTTP Packets
CVSS 5.3
CVE-2020-12142 MEDIUM
Silver Peak Unity Orchestrator <8.9.2 - Authenticated IPSec UDP Key Material Exposure via CLI and REST APIs
CVSS 4.8
CVE-2020-5887 CRITICAL
BIG-IP VE <15.1.0.1 - Privilege Escalation
CVSS 9.1
CVE-2020-6442 MEDIUM
Google Chrome < 81.0.4044.92 - Cross-Origin Data Leak via Cache Implementation
CVSS 4.3
CVE-2020-11610 HIGH
xdLocalStorage < 2.0.5 - Exposure of Sensitive Data via Wildcard TargetOrigin in postMessage
CVSS 8.8
CVE-2020-11582 HIGH
Pulse Secure Pulse Connect Secure < 2020-04-06 - Unauthenticated Resource Exposure via Host Checker Applet
CVSS 8.8
CVE-2020-10867 CRITICAL
Avast Antivirus < 20.0 - Unauthenticated Task Access Bypass via aswTask RPC Endpoint
CVSS 9.8
Details
Vulnerabilities 732