CWE-668

Exposure of Resource to Wrong Sphere

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

732 vulnerabilities with CWE-668
CVE-2024-36033 HIGH
Linux Kernel 6.7-6.8.9 - Information Disclosure via Bluetooth QCA Board ID Fetch
CVSS 7.1
CVE-2024-36032 HIGH
Linux Kernel 5.12-6.8.9 Bluetooth Info Disclosure via Malformed Firmware
CVSS 7.1
CVE-2024-21813 HIGH
Intel(R) DTT - Privilege Escalation
CVSS 7.9
CVE-2024-35183 MEDIUM
wolfictl < 0.16.10 - GitHub Token Exposure to Untrusted Remote Servers
CVSS 4.4
CVE-2024-32473 MEDIUM
Moby 26.0.0-26.0.1 - Unintended IPv6 Network Exposure via ipvlan/macvlan Interfaces
CVSS 4.7
CVE-2024-21605 MEDIUM
Juniper Junos OS Unauthenticated DoS via STP Blocked Port Traffic
CVSS 6.5
CVE-2024-29905 HIGH
DIRAC < 8.0.41 - Unauthorized Proxy Access via Temporary File Exposure
CVSS 8.1
CVE-2024-3019 HIGH
PCP pmproxy >=4.3.4 - Remote Command Execution via Exposed Redis Backend
CVSS 8.8
CVE-2024-24562 MEDIUM
vantage6-ui < 4.2.0 - Missing Security Headers
CVSS 5.4
CVE-2024-25153 CRITICAL
FileCatalyst Workflow Web Portal - Path Traversal
CVSS 9.8
CVE-2024-21626 HIGH
runc (docker) File Descriptor Leak Privilege Escalation
CVSS 8.6
CVE-2024-21597 MEDIUM
Juniper Junos OS MX Series Firewall Filter Bypass via Fabric Routing Misclassification
CVSS 5.3
CVE-2024-0443 MEDIUM
Linux kernel - Privilege Escalation
CVSS 5.5
CVE-2024-20694 MEDIUM
Windows CoreMessaging - Info Disclosure
CVSS 5.5
CVE-2024-20692 MEDIUM
Microsoft Local Security Authority Subsystem Service - Info Disclosure
CVSS 5.7
CVE-2023-53392 HIGH
Linux kernel 5.16.1-6.1.25 - Denial of Service via ISH Firmware Warm Reset
CVSS 7.1
CVE-2023-5751 HIGH
CODESYS Products <= 3.5.20.10 - Information Disclosure and DoS
CVSS 7.8
CVE-2023-52700 MEDIUM
Linux Kernel 4.0-6.1.13 - Information Exposure via TIPC SYN Message Handling
CVSS 5.5
CVE-2023-39478 HIGH
Softing Secure Integration Server - Remote Code Execution via OPC FileDirectory Namespace Handling
CVSS 8.8
CVE-2023-6096 HIGH
Hanwha Vision HRX-1620 <= 3.05.62 - Broken Firmware Encryption
CVSS 7.4
CVE-2023-7014 MEDIUM
Molongui Authorship < 4.7.4 - Unauthenticated Sensitive Information Exposure via ma_debu Parameter
CVSS 5.3
CVE-2023-50328 LOW
IBM PowerSC 1.3, 2.0, 2.1 - Session Identifier Exposure via URL Query String
CVSS 3.7
CVE-2023-7204 HIGH
WP STAGING < 3.2.0 - Unauthenticated Exposure of Sensitive Cache Files During Cloning
CVSS 7.5
CVE-2023-48291 MEDIUM
Apache Airflow < 2.8.0 - Authenticated DAG Resource Access Control Bypass
CVSS 4.3
CVE-2023-49347 MEDIUM
Budgie Extras Windows Previews - Info Disclosure
CVSS 6.0
Details
Vulnerabilities 732