CWE-668
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
721 vulnerabilities with CWE-668
CVE-2017-12342
MEDIUM
Cisco Nexus Series Switches - Info Disclosure
CVSS 6.8
CVE-2017-8185
HIGH
Huawei ME906s-158 < ME906S_Installer_13.1805.10.3 - Privilege Escalation via Malicious Configuration File Execution
CVSS 7.8
CVE-2017-8171
MEDIUM
Huawei P10 Plus Firmware < Vicky-AL00AC00B172D - Factory Reset Protection Bypass via Talkback Mode
CVSS 4.6
CVE-2017-8161
MEDIUM
Huawei EVA-L09 - Factory Reset Protection Bypass via Swype Login
CVSS 4.6
CVE-2017-16660
HIGH
Cacti 1.1.27 - Authenticated Remote Code Execution via Log Path Misconfiguration
CVSS 7.2
CVE-2017-15592
HIGH
Xen < 4.9.0 - Denial of Service or Privilege Escalation via Self-Linear Shadow Mapping Mishandling
CVSS 8.8
CVE-2017-12249
CRITICAL
Cisco Meeting Server - Privilege Escalation
CVSS 9.1
CVE-2017-6872
MEDIUM
Siemens OZW672/OZW772 - Info Disclosure
CVSS 6.5
CVE-2017-11382
HIGH
Trend Micro Deep Discovery Email Inspector 2.5.1 - Denial of Service via Arbitrary File Deletion
CVSS 7.5
CVE-2017-0215
MEDIUM
Microsoft Windows 10 1607/Server 2016 Device Guard Security Feature Bypass via PowerShell
CVSS 5.3
CVE-2017-7490
MEDIUM
Moodle 2.x and 3.x - Unauthenticated Arbitrary Blog Search via Missing Capability Check
CVSS 5.3
CVE-2017-8418
LOW
RuboCop < 0.48.1 - Unsafe Temporary File Handling
CVSS 3.3
CVE-2017-5648
CRITICAL
Apache Tomcat < 9.0.0.M18 - Exposure to Wrong Actor
CVSS 9.1
CVE-2017-6100
HIGH
TCPDF < 6.1.1 - Exposure of Resource to Wrong Sphere via FTP Upload
CVSS 7.5
CVE-2017-5634
MEDIUM
Norwegian Air Kiosk - Unauthenticated Privilege Escalation via Print Dialog Manipulation
CVSS 6.6
CVE-2016-11010
MEDIUM
WP-Invoice < 4.1.1 - Unauthenticated Exposure of Resource to Wrong Sphere via wpi_twocheckout Payer Metadata
CVSS 5.3
CVE-2016-11009
MEDIUM
WP-Invoice < 4.1.1 - Unauthenticated Payer Metadata Update
CVSS 5.3
CVE-2016-11008
MEDIUM
WP-Invoice < 4.1.1 - Unauthenticated Payer Metadata Update
CVSS 5.3
CVE-2016-11007
MEDIUM
WP-Invoice < 4.1.1 - Unauthenticated Invoice Data Exposure via wpi_user_id Parameter
CVSS 5.3
CVE-2016-11006
MEDIUM
WP-Invoice < 4.1.1 - Unauthenticated Settings Change via admin_init
CVSS 5.3
CVE-2016-10840
HIGH
cPanel 11.48.0.5-11.48.5.2 - Remote Code Execution via Locale Duplication
CVSS 8.8
CVE-2016-5334
MEDIUM
VMware Identity Manager 2.0-2.7.0 and vRealize Automation 7.0-7.1.9 - Unauthenticated Sensitive File Exposure
CVSS 5.3
CVE-2016-5787
MEDIUM
General Electric GE Digital Proficy HMI/SCADA - CIMPLICITY <8.2 SIM...
CVSS 6.3
CVE-2015-10004
HIGH
Token Validation - Timing Side-Channel
CVSS 7.5
CVE-2015-9550
HIGH
TOTOLINK A850R-V1 and F1-V2 - Unauthenticated Exposure of Web Management Interface via WAN Packet
CVSS 7.5
Details
Vulnerabilities
721