CWE-668

Exposure of Resource to Wrong Sphere

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

719 vulnerabilities with CWE-668
CVE-2024-20694 MEDIUM
Windows CoreMessaging - Info Disclosure
CVSS 5.5
CVE-2024-20692 MEDIUM
Microsoft Local Security Authority Subsystem Service - Info Disclosure
CVSS 5.7
CVE-2023-53392 HIGH
Linux kernel 5.16.1-6.1.25 - Denial of Service via ISH Firmware Warm Reset
CVSS 7.1
CVE-2023-5751 HIGH
CODESYS Products <= 3.5.20.10 - Information Disclosure and DoS
CVSS 7.8
CVE-2023-52700 MEDIUM
Linux Kernel 4.0-6.1.13 - Information Exposure via TIPC SYN Message Handling
CVSS 5.5
CVE-2023-39478 HIGH
Softing Secure Integration Server - Remote Code Execution via OPC FileDirectory Namespace Handling
CVSS 8.8
CVE-2023-6096 HIGH
Hanwha Vision HRX-1620 <= 3.05.62 - Broken Firmware Encryption
CVSS 7.4
CVE-2023-7014 MEDIUM
Molongui Authorship < 4.7.4 - Unauthenticated Sensitive Information Exposure via ma_debu Parameter
CVSS 5.3
CVE-2023-50328 LOW
IBM PowerSC 1.3, 2.0, 2.1 - Session Identifier Exposure via URL Query String
CVSS 3.7
CVE-2023-7204 HIGH
WP STAGING < 3.2.0 - Unauthenticated Exposure of Sensitive Cache Files During Cloning
CVSS 7.5
CVE-2023-48291 MEDIUM
Apache Airflow < 2.8.0 - Authenticated DAG Resource Access Control Bypass
CVSS 4.3
CVE-2023-49347 MEDIUM
Budgie Extras Windows Previews - Info Disclosure
CVSS 6.0
CVE-2023-49346 MEDIUM
Budgie Extras WeatherShow - Info Disclosure
CVSS 6.0
CVE-2023-49345 MEDIUM
Budgie Extras Takeabreak - Info Disclosure
CVSS 6.0
CVE-2023-49344 MEDIUM
Budgie Extras Window Shuffler - Info Disclosure
CVSS 6.0
CVE-2023-49343 MEDIUM
Budgie Extras Dropby - Info Disclosure
CVSS 6.0
CVE-2023-49342 MEDIUM
Budgie Extras Clockworks - Info Disclosure
CVSS 6.0
CVE-2023-41120 MEDIUM
EnterpriseDB Postgres Advanced Server <15.4.0 - Privilege Escalation
CVSS 6.5
CVE-2023-39171 HIGH
SENEC Storage Box - Info Disclosure
CVSS 7.2
CVE-2023-42718 MEDIUM
Android - Local Information Disclosure via Missing Permission Check in Dialer
CVSS 5.5
CVE-2023-42717 HIGH
Android - Remote Information Disclosure via Telephony Service Permission Bypass
CVSS 7.5
CVE-2023-42716 HIGH
Android - Remote Information Disclosure via Telephony Service Missing Permission Check
CVSS 7.5
CVE-2023-42715 MEDIUM
Android - Local Information Disclosure via Telephony Service Missing Permission Check
CVSS 5.5
CVE-2023-41786 MEDIUM
Pandora FMS 700-772 - Unauthorized Database Backup Download
CVSS 6.8
CVE-2023-36013 MEDIUM
PowerShell 7.2-7.2.16 - Information Disclosure via Hard-coded Credentials
CVSS 6.5
Details
Vulnerabilities 719