CWE-668

Exposure of Resource to Wrong Sphere

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

719 vulnerabilities with CWE-668
CVE-2023-44124 MEDIUM
Screen recording <com/lge/gametools/gamerecorder - Info Disclosure
CVSS 6.1
CVE-2023-44122 MEDIUM
LockScreenSettings - Info Disclosure
CVSS 6.1
CVE-2023-43784 HIGH
Plesk Onyx 17.8.11 - Info Disclosure
CVSS 7.5
CVE-2023-43783 HIGH
Cadence < 0.9.2 - Symlink Attack via Insecure Temporary File
CVSS 7.5
CVE-2023-43782 MEDIUM
Cadence < 0.9.2 - Insecure Temporary File Handling in /tmp/.cadence-aloop-daemon.x
CVSS 5.5
CVE-2023-31014 MEDIUM
NVIDIA GeForce Now - Code Execution
CVSS 4.2
CVE-2023-40788 MEDIUM
SpringBlade <=V3.6.0 - Info Disclosure
CVSS 5.3
CVE-2023-39056 MEDIUM
Coffee-jumbo <13.6.1 - Info Disclosure
CVSS 6.5
CVE-2023-39049 MEDIUM
youmart-tokunaga <13.6.1 - Info Disclosure
CVSS 6.5
CVE-2023-39046 MEDIUM
TonTon-Tei_waiting Line <13.6.1 - Info Disclosure
CVSS 6.5
CVE-2023-39058 MEDIUM
THE_B_members card <13.6.1 - Info Disclosure
CVSS 6.5
CVE-2023-39043 MEDIUM
YKC Tokushima_awayokocho Line <13.6.1 - Info Disclosure
CVSS 6.5
CVE-2023-39040 MEDIUM
Cheese Cafe Line <13.6.1 - Info Disclosure
CVSS 6.5
CVE-2023-39039 MEDIUM
Camp Style Project Line <13.6.1 - Info Disclosure
CVSS 6.5
CVE-2023-38558 MEDIUM
SIMATIC PCS neo Administration Console V4.0 and V4.0 Update 1 - Credential Leak via Windows Admin Credential Exposure
CVSS 5.5
CVE-2023-38152 MEDIUM
Windows Server 2008, 2012, 2016, 2019, 2022 - Information Disclosure via DHCP Server Service Buffer Over-read
CVSS 5.3
CVE-2023-24965 MEDIUM
IBM Aspera Faspex < 5.0.5 - Unauthorized Resource Access
CVSS 5.8
CVE-2023-41745 MEDIUM
Acronis Agent and Cyber Protect - Exposure of Sensitive Information via Excessive System Data Collection
CVSS 5.5
CVE-2023-41742 HIGH
Acronis Agent and Cyber Protect - Exposure of Resource to Wrong Sphere via Unrestricted IP Binding
CVSS 7.5
CVE-2023-34725 MEDIUM
TechView LA-5570 Wireless Gateway 1.0.19_T53 - Unauthenticated Privilege Escalation via Telnet Connection
CVSS 6.8
CVE-2023-4230 MEDIUM
ioLogik 4000 Series <v1.6 - Info Disclosure
CVSS 5.3
CVE-2023-39974 MEDIUM
AcyMailing 6.7.0-8.7.0 - Unauthenticated Exposure of Sensitive Information via Subscriber List Query
CVSS 5.3
CVE-2023-39250 HIGH
Dell Replay Manager <3.1.2 & Storage Integration Tools <6.1.1 - Encryption Key Exposure
CVSS 7.8
CVE-2023-2916 HIGH
InfiniteWP Client <= 1.11.1 - Authenticated Sensitive Information Exposure via admin_notice Function
CVSS 7.5
CVE-2023-39383 HIGH
Huawei EMUI and HarmonyOS - Exposure of Sensitive Information via AMS Module Input Parameter
CVSS 7.5
Details
Vulnerabilities 719