CWE-668

Exposure of Resource to Wrong Sphere

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

721 vulnerabilities with CWE-668
CVE-2019-11728 MEDIUM
Firefox < 68.0 - TCP Port Scanning via Alt-Svc Header
CVSS 4.7
CVE-2019-3970 MEDIUM
Comodo Antivirus <= 12.0.0.6810 - Arbitrary File Write via Cavwp.exe Database Handling
CVSS 5.5
CVE-2019-13379 HIGH
AVTECH Room Alert 3E Firmware < 2.2.5 - Unauthenticated Privilege Escalation via Default Credential Reset
CVSS 8.8
CVE-2019-9186 CRITICAL
JetBrains IntelliJ IDEA 2018.1-2018.1.7 - Remote Code Execution via JMX Server
CVSS 9.8
CVE-2019-3569 HIGH
HHVM < 3.30.5 and 4.0-4.8 - Unintended FastCGI Interface Binding
CVSS 7.5
CVE-2019-12929 CRITICAL
QEMU < 4.0.0 - OS Command Injection via QMP guest_exec Command
CVSS 9.8
CVE-2019-12928 CRITICAL
QEMU < 4.0.0 - OS Command Injection via QMP Migrate Command
CVSS 9.8
CVE-2019-1848 CRITICAL
Cisco DNA Center < 1.3 - Unauthenticated Critical Internal Services Access
CVSS 9.3
CVE-2019-12904 MEDIUM
Libgcrypt 1.8.4 - Information Exposure via Flush-and-Reload Side-Channel Attack
CVSS 5.9
CVE-2019-12875 MEDIUM
Alpine Linux abuild < 3.4.0 - Unauthenticated Untrusted Package Addition via Keys Directory Option
CVSS 6.5
CVE-2019-12274 HIGH
Rancher 1-2.2.3 - Privilege Escalation
CVSS 8.8
CVE-2019-8934 LOW
QEMU <= 3.1.0 - Information Exposure via Shared /proc/device-tree Attributes
CVSS 3.3
CVE-2019-8308 HIGH
flatpak < 1.0.7 and 1.1.x-1.2.x < 1.2.3 - Arbitrary File Modification via /proc Exposure
CVSS 8.2
CVE-2018-25068 MEDIUM
devent globalpom-utils <4.5.0 - Insecure Temp File
CVSS 6.3
CVE-2018-16494 HIGH
Versa Operating System < 16.1r2s11 - Insecure File Permissions via Umask Setting
CVSS 8.8
CVE-2018-20947 MEDIUM
cPanel 61.9999.55-62.0.39 - Unauthenticated Arbitrary File Write via telnetcrt Script
CVSS 5.5
CVE-2018-4048 HIGH
GOG Galaxy 1.2.48.36 - Local Privilege Escalation via Temp Directory File Overwrite
CVSS 7.8
CVE-2018-7846 CRITICAL
Modicon M580, M340, Quantum and Premium Firmware - Unauthorized Access via Modbus Brute Force Attack
CVSS 9.8
CVE-2018-20321 HIGH
Rancher <2.1.5 - Privilege Escalation
CVSS 8.8
CVE-2018-18068 CRITICAL
Raspberry Pi 3 Model B+ Firmware - Unauthenticated Privilege Escalation via ARM Debugging Feature
CVSS 9.8
CVE-2018-20237 MEDIUM
Atlassian Confluence <6.13.1 - Info Disclosure
CVSS 6.5
CVE-2018-1840 MEDIUM
IBM WebSphere Application Server 8.5.0.0-8.5.5.13 - Privilege Escalation via Federated Repository Migration
CVSS 6.0
CVE-2018-15591 HIGH
Ivanti Workspace Control < 10.3.10.0 - Application Whitelist Bypass via PowerGrid SEE
CVSS 7.8
CVE-2018-8040 MEDIUM
Apache Traffic Server <6.2.2, <7.1.3 - Info Disclosure
CVSS 5.3
CVE-2018-7073 MEDIUM
HPE Moonshot Provisioning Manager < 1.24 - Local Arbitrary File Modification
CVSS 5.5
Details
Vulnerabilities 721