CWE-668

Exposure of Resource to Wrong Sphere

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

721 vulnerabilities with CWE-668
CVE-2017-12342 MEDIUM
Cisco Nexus Series Switches - Info Disclosure
CVSS 6.8
CVE-2017-8185 HIGH
Huawei ME906s-158 < ME906S_Installer_13.1805.10.3 - Privilege Escalation via Malicious Configuration File Execution
CVSS 7.8
CVE-2017-8171 MEDIUM
Huawei P10 Plus Firmware < Vicky-AL00AC00B172D - Factory Reset Protection Bypass via Talkback Mode
CVSS 4.6
CVE-2017-8161 MEDIUM
Huawei EVA-L09 - Factory Reset Protection Bypass via Swype Login
CVSS 4.6
CVE-2017-16660 HIGH
Cacti 1.1.27 - Authenticated Remote Code Execution via Log Path Misconfiguration
CVSS 7.2
CVE-2017-15592 HIGH
Xen < 4.9.0 - Denial of Service or Privilege Escalation via Self-Linear Shadow Mapping Mishandling
CVSS 8.8
CVE-2017-12249 CRITICAL
Cisco Meeting Server - Privilege Escalation
CVSS 9.1
CVE-2017-6872 MEDIUM
Siemens OZW672/OZW772 - Info Disclosure
CVSS 6.5
CVE-2017-11382 HIGH
Trend Micro Deep Discovery Email Inspector 2.5.1 - Denial of Service via Arbitrary File Deletion
CVSS 7.5
CVE-2017-0215 MEDIUM
Microsoft Windows 10 1607/Server 2016 Device Guard Security Feature Bypass via PowerShell
CVSS 5.3
CVE-2017-7490 MEDIUM
Moodle 2.x and 3.x - Unauthenticated Arbitrary Blog Search via Missing Capability Check
CVSS 5.3
CVE-2017-8418 LOW
RuboCop < 0.48.1 - Unsafe Temporary File Handling
CVSS 3.3
CVE-2017-5648 CRITICAL
Apache Tomcat < 9.0.0.M18 - Exposure to Wrong Actor
CVSS 9.1
CVE-2017-6100 HIGH
TCPDF < 6.1.1 - Exposure of Resource to Wrong Sphere via FTP Upload
CVSS 7.5
CVE-2017-5634 MEDIUM
Norwegian Air Kiosk - Unauthenticated Privilege Escalation via Print Dialog Manipulation
CVSS 6.6
CVE-2016-11010 MEDIUM
WP-Invoice < 4.1.1 - Unauthenticated Exposure of Resource to Wrong Sphere via wpi_twocheckout Payer Metadata
CVSS 5.3
CVE-2016-11009 MEDIUM
WP-Invoice < 4.1.1 - Unauthenticated Payer Metadata Update
CVSS 5.3
CVE-2016-11008 MEDIUM
WP-Invoice < 4.1.1 - Unauthenticated Payer Metadata Update
CVSS 5.3
CVE-2016-11007 MEDIUM
WP-Invoice < 4.1.1 - Unauthenticated Invoice Data Exposure via wpi_user_id Parameter
CVSS 5.3
CVE-2016-11006 MEDIUM
WP-Invoice < 4.1.1 - Unauthenticated Settings Change via admin_init
CVSS 5.3
CVE-2016-10840 HIGH
cPanel 11.48.0.5-11.48.5.2 - Remote Code Execution via Locale Duplication
CVSS 8.8
CVE-2016-5334 MEDIUM
VMware Identity Manager 2.0-2.7.0 and vRealize Automation 7.0-7.1.9 - Unauthenticated Sensitive File Exposure
CVSS 5.3
CVE-2016-5787 MEDIUM
General Electric GE Digital Proficy HMI/SCADA - CIMPLICITY <8.2 SIM...
CVSS 6.3
CVE-2015-10004 HIGH
Token Validation - Timing Side-Channel
CVSS 7.5
CVE-2015-9550 HIGH
TOTOLINK A850R-V1 and F1-V2 - Unauthenticated Exposure of Web Management Interface via WAN Packet
CVSS 7.5
Details
Vulnerabilities 721