CWE-668

Exposure of Resource to Wrong Sphere

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

721 vulnerabilities with CWE-668
CVE-2014-2387 MEDIUM
Pen 0.18.0 - Insecure Temporary File Creation
CVSS 4.4
CVE-2014-0023 HIGH
OpenShift - Arbitrary Code Execution via Temporary File Creation
CVSS 7.8
CVE-2013-4253 HIGH
Red Hat OpenShift 1 - Insecure Default SSH Key in OpenShift Extras Deployment Script
CVSS 7.5
CVE-2013-4561 CRITICAL
OpenShift - Insecure Temporary File Handling in Mcollective Facts Update Cron Job
CVSS 9.1
CVE-2013-2183 HIGH
Monkey HTTP Daemon - Local Security Bypass
CVSS 7.1
CVE-2013-0163 MEDIUM
OpenShift - Denial of Service via Predictable /tmp in HAProxy Cartridge
CVSS 5.5
CVE-2013-4374 HIGH
RHQ Mongo DB Drift Server < 2013-09-25 - Insecure Temporary File Handling
CVSS 7.1
CVE-2013-4280 MEDIUM
RedHat Virtual Desktop Server Manager 4.9.6 - Insecure Temporary File Handling
CVSS 5.5
CVE-2013-4480
Red Hat Satellite < 5.6 - Unauthenticated Administrator Account Creation
CVE-2012-5639 MEDIUM
LibreOffice/OpenOffice - Info Disclosure
CVSS 6.5
CVE-2012-1846
Google Chrome < 17.0.963.66 - Sandbox Protection Bypass
CVE-2011-1960
Microsoft Internet Explorer <10 - Info Disclosure
CVE-2011-1258
Microsoft Internet Explorer 6-8 - Information Disclosure via Drag-and-Drop Operation
CVE-2009-5042 CRITICAL
python-docutils - Insecure Temporary File Handling
CVSS 9.1
CVE-2008-2544 MEDIUM
Linux Kernel - Unprotected User Data Exposure via Chroot /proc Mount
CVSS 5.5
CVE-2008-7291 CRITICAL
gri < 2.12.18 - Insecure Temporary File Handling
CVSS 9.8
CVE-2007-3915 CRITICAL
Mondo 2.24 - Insecure Temporary File Handling
CVSS 9.1
CVE-2005-2351 MEDIUM
mutt < 1.5.20 - Denial of Service via Temporary File Handling
CVSS 5.5
CVE-2004-1489
Opera < 7.54 - Unauthenticated Exposure of Sensitive Information via Java Applet
CVE-2001-0892
Acme Thttpd < 2.22 - Unauthenticated Sensitive File Exposure via Trailing Slash
CVE-2001-0893
mini_httpd < 1.16 - Unauthenticated Sensitive File Exposure via Trailing Slash
Details
Vulnerabilities 721