CWE-668

Exposure of Resource to Wrong Sphere

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

721 vulnerabilities with CWE-668
CVE-2019-10805 HIGH
valib.js < 2.0.0 - Internal Property Tampering via hasOwnProperty Override
CVSS 7.5
CVE-2019-10790 HIGH
taffydb <= 2.7.3 - Unauthenticated Data Access via Index Forgery
CVSS 7.5
CVE-2019-4633 MEDIUM
IBM Security Secret Server <10.7 - Info Disclosure
CVSS 4.3
CVE-2019-10781 CRITICAL
schema-inspector < 1.6.9 - Validation Bypass via Malicious JavaScript Object
CVSS 9.8
CVE-2019-3682 HIGH
SUSE CaaS Platform 3.0 - Exposure of Resource to Wrong Sphere via Insecure Docker API
CVSS 8.4
CVE-2019-20149 HIGH
kind-of 6.0.0-6.0.2 - Exposure of Resource to Wrong Sphere via ctorName Overwrite
CVSS 7.5
CVE-2019-8779 CRITICAL
iPadOS < 13.1.1 - Unauthenticated Exposure of Resource to Wrong Sphere
CVSS 10.0
CVE-2019-13927 MEDIUM
Siemens Desigo PX Automation Controllers - Denial of Service via Crafted HTTP Message
CVSS 5.3
CVE-2019-15689 MEDIUM
Kaspersky Secure Connection/Internet Security/Total Security/Security Cloud - Unauthenticated Arbitrary Code Execution
CVSS 6.7
CVE-2019-19015 CRITICAL
TitanHQ WebTitan <5.18 - Code Injection
CVSS 9.8
CVE-2019-16387 HIGH
PEGA Platform 8.3.0 - Privilege Escalation
CVSS 8.1
CVE-2019-16241 MEDIUM
TCL Alcatel Cingular Flip 2 B9HUAH1 - Auth Bypass
CVSS 6.8
CVE-2019-16541 CRITICAL
Jenkins JIRA Plugin <3.0.10 - Privilege Escalation
CVSS 9.9
CVE-2019-15350 HIGH
TECNO H622 Camon - Unauthenticated Privilege Escalation via com.lovelyfont.defcontainer FunctionService
CVSS 7.8
CVE-2019-15349 HIGH
TECNO H612 Camon - Unauthenticated Privilege Escalation via com.lovelyfont.defcontainer FunctionService
CVSS 7.8
CVE-2019-15346 HIGH
Tecno Camon iClick 2 Firmware - Unauthenticated Privilege Escalation via com.lovelyfont.defcontainer FunctionService
CVSS 7.8
CVE-2019-15345 HIGH
Tecno Camon iClick Firmware - Unauthenticated Arbitrary Code Execution via com.lovelyfont.defcontainer FunctionService
CVSS 7.8
CVE-2019-15341 HIGH
Tecno Camon iAir 2 Plus Firmware - Unauthenticated Privilege Escalation via com.lovelyfont.defcontainer FunctionService
CVSS 7.8
CVE-2019-18954 MEDIUM
Pomelo < 2.2.7 - Critical State Data Manipulation via User Input
CVSS 5.3
CVE-2019-4306 MEDIUM
IBM Security Guardium Big Data Intelligence - Info Disclosure
CVSS 6.5
CVE-2019-13546 MEDIUM
IntelliSpace Perinatal K- - Privilege Escalation
CVSS 6.8
CVE-2019-12660 MEDIUM
Cisco IOS XE >= 16.1.1 - Authenticated Memory Write via CLI Command Injection
CVSS 5.5
CVE-2019-16518 MEDIUM
Vandy Vape Swell Kit Mod Firmware - Unintended Temperature Control via Bluetooth Low Energy Packets
CVSS 4.3
CVE-2019-15138 HIGH
html-pdf < 3.0.1 - Arbitrary File Read via XMLHttpRequest
CVSS 7.5
CVE-2019-10365 MEDIUM
Jenkins Google Kubernetes Engine Plugin <= 0.6.2 - Unauthorized Access Token Exposure via Temporary File
CVSS 4.3
Details
Vulnerabilities 721