CWE-668

Exposure of Resource to Wrong Sphere

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

732 vulnerabilities with CWE-668
CVE-2023-49346 MEDIUM
Budgie Extras WeatherShow - Info Disclosure
CVSS 6.0
CVE-2023-49345 MEDIUM
Budgie Extras Takeabreak - Info Disclosure
CVSS 6.0
CVE-2023-49344 MEDIUM
Budgie Extras Window Shuffler - Info Disclosure
CVSS 6.0
CVE-2023-49343 MEDIUM
Budgie Extras Dropby - Info Disclosure
CVSS 6.0
CVE-2023-49342 MEDIUM
Budgie Extras Clockworks - Info Disclosure
CVSS 6.0
CVE-2023-41120 MEDIUM
EnterpriseDB Postgres Advanced Server <15.4.0 - Privilege Escalation
CVSS 6.5
CVE-2023-39171 HIGH
SENEC Storage Box - Info Disclosure
CVSS 7.2
CVE-2023-42718 MEDIUM
Android - Local Information Disclosure via Missing Permission Check in Dialer
CVSS 5.5
CVE-2023-42717 HIGH
Android - Remote Information Disclosure via Telephony Service Permission Bypass
CVSS 7.5
CVE-2023-42716 HIGH
Android - Remote Information Disclosure via Telephony Service Missing Permission Check
CVSS 7.5
CVE-2023-42715 MEDIUM
Android - Local Information Disclosure via Telephony Service Missing Permission Check
CVSS 5.5
CVE-2023-41786 MEDIUM
Pandora FMS 700-772 - Unauthorized Database Backup Download
CVSS 6.8
CVE-2023-36013 MEDIUM
PowerShell 7.2-7.2.16 - Information Disclosure via Hard-coded Credentials
CVSS 6.5
CVE-2023-36043 MEDIUM
Microsoft Open Management Infrastructure - Information Disclosure
CVSS 6.5
CVE-2023-5545 LOW
moodle < 3.9.24 and >= 4.0.0 < 4.3.0-rc2 - Exposure of Sensitive Information via H5P Metadata Author Field
CVSS 3.3
CVE-2023-5542 LOW
moodle < 4.3.0-rc2 - Improper Access Control in Group Membership Visibility
CVSS 3.3
CVE-2023-42551 MEDIUM
Samsung Account < 14.5.00.7 - Unauthenticated Arbitrary File Access via Implicit Intent
CVSS 5.5
CVE-2023-42549 MEDIUM
Samsung Account < 14.5.00.7 - Unauthenticated Arbitrary File Access via Implicit Intent
CVSS 5.5
CVE-2023-42547 MEDIUM
Samsung Account < 14.5.00.7 - Unauthenticated Arbitrary File Access via Implicit Intent
CVSS 5.5
CVE-2023-42546 MEDIUM
Samsung Account < 14.5.00.7 - Unauthenticated Arbitrary File Access via Implicit Intent
CVSS 5.5
CVE-2023-4910 MEDIUM
3scale_api_management - Exposure of Sensitive Information via Browser Cache
CVSS 5.5
CVE-2023-4217 LOW
PT-G503 Series <5.2 - Info Disclosure
CVSS 3.1
CVE-2023-3972 HIGH
insights-client < 3.2.2 - Local Privilege Escalation via Insecure Temporary Directory Permissions
CVSS 7.8
CVE-2023-2622 LOW
Hitachi Energy Modular Advanced Control for HVDC 7.10.0.0-7.17.x - Arbitrary File Read via InspectSetup RPC
CVSS 2.7
CVE-2023-38994 HIGH
univention_corporate_server 5.0-5 - Exposure of LDAP Credentials in Process List
CVSS 7.9
Details
Vulnerabilities 732