CWE-668
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
721 vulnerabilities with CWE-668
CVE-2019-10805
HIGH
valib.js < 2.0.0 - Internal Property Tampering via hasOwnProperty Override
CVSS 7.5
CVE-2019-10790
HIGH
taffydb <= 2.7.3 - Unauthenticated Data Access via Index Forgery
CVSS 7.5
CVE-2019-4633
MEDIUM
IBM Security Secret Server <10.7 - Info Disclosure
CVSS 4.3
CVE-2019-10781
CRITICAL
schema-inspector < 1.6.9 - Validation Bypass via Malicious JavaScript Object
CVSS 9.8
CVE-2019-3682
HIGH
SUSE CaaS Platform 3.0 - Exposure of Resource to Wrong Sphere via Insecure Docker API
CVSS 8.4
CVE-2019-20149
HIGH
kind-of 6.0.0-6.0.2 - Exposure of Resource to Wrong Sphere via ctorName Overwrite
CVSS 7.5
CVE-2019-8779
CRITICAL
iPadOS < 13.1.1 - Unauthenticated Exposure of Resource to Wrong Sphere
CVSS 10.0
CVE-2019-13927
MEDIUM
Siemens Desigo PX Automation Controllers - Denial of Service via Crafted HTTP Message
CVSS 5.3
CVE-2019-15689
MEDIUM
Kaspersky Secure Connection/Internet Security/Total Security/Security Cloud - Unauthenticated Arbitrary Code Execution
CVSS 6.7
CVE-2019-19015
CRITICAL
TitanHQ WebTitan <5.18 - Code Injection
CVSS 9.8
CVE-2019-16387
HIGH
PEGA Platform 8.3.0 - Privilege Escalation
CVSS 8.1
CVE-2019-16241
MEDIUM
TCL Alcatel Cingular Flip 2 B9HUAH1 - Auth Bypass
CVSS 6.8
CVE-2019-16541
CRITICAL
Jenkins JIRA Plugin <3.0.10 - Privilege Escalation
CVSS 9.9
CVE-2019-15350
HIGH
TECNO H622 Camon - Unauthenticated Privilege Escalation via com.lovelyfont.defcontainer FunctionService
CVSS 7.8
CVE-2019-15349
HIGH
TECNO H612 Camon - Unauthenticated Privilege Escalation via com.lovelyfont.defcontainer FunctionService
CVSS 7.8
CVE-2019-15346
HIGH
Tecno Camon iClick 2 Firmware - Unauthenticated Privilege Escalation via com.lovelyfont.defcontainer FunctionService
CVSS 7.8
CVE-2019-15345
HIGH
Tecno Camon iClick Firmware - Unauthenticated Arbitrary Code Execution via com.lovelyfont.defcontainer FunctionService
CVSS 7.8
CVE-2019-15341
HIGH
Tecno Camon iAir 2 Plus Firmware - Unauthenticated Privilege Escalation via com.lovelyfont.defcontainer FunctionService
CVSS 7.8
CVE-2019-18954
MEDIUM
Pomelo < 2.2.7 - Critical State Data Manipulation via User Input
CVSS 5.3
CVE-2019-4306
MEDIUM
IBM Security Guardium Big Data Intelligence - Info Disclosure
CVSS 6.5
CVE-2019-13546
MEDIUM
IntelliSpace Perinatal K- - Privilege Escalation
CVSS 6.8
CVE-2019-12660
MEDIUM
Cisco IOS XE >= 16.1.1 - Authenticated Memory Write via CLI Command Injection
CVSS 5.5
CVE-2019-16518
MEDIUM
Vandy Vape Swell Kit Mod Firmware - Unintended Temperature Control via Bluetooth Low Energy Packets
CVSS 4.3
CVE-2019-15138
HIGH
html-pdf < 3.0.1 - Arbitrary File Read via XMLHttpRequest
CVSS 7.5
CVE-2019-10365
MEDIUM
Jenkins Google Kubernetes Engine Plugin <= 0.6.2 - Unauthorized Access Token Exposure via Temporary File
CVSS 4.3
Details
Vulnerabilities
721