CWE-668

Exposure of Resource to Wrong Sphere

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

732 vulnerabilities with CWE-668
CVE-2023-34119 HIGH
Zoom Rooms for Windows <5.15.0 - Privilege Escalation
CVSS 8.2
CVE-2023-31818 HIGH
Marukyu Line <13.4.1 - Info Disclosure
CVSS 7.5
CVE-2023-30960 MEDIUM
Foundry Job-Tracker <4.645.0 - Info Disclosure
CVSS 4.3
CVE-2023-3270 HIGH
SICK ICR890-4 Firmware < 2.5.0 - Unauthenticated Exposure of Sensitive Information
CVSS 8.6
CVE-2023-35696 HIGH
SICK ICR890-4 Firmware < 2.5.0 - Unauthenticated Sensitive Information Exposure via HTTP Endpoints
CVSS 7.5
CVE-2023-3456 MEDIUM
Huawei EMUI and HarmonyOS - Kernel Raw Address Leakage in Hang Detector Module
CVSS 5.3
CVE-2023-3455 CRITICAL
Huawei EMUI and HarmonyOS - Exposure of Sensitive Information via Key Management Vulnerability
CVSS 9.1
CVE-2023-32613 HIGH
WL-WN531AX2 Firmware < 2023526 - Unauthenticated Exposure of Resource to Wrong Sphere
CVSS 8.1
CVE-2023-32394 LOW
iPadOS < 16.5 - Unprotected Contact Information Exposure via Lock Screen
CVSS 2.4
CVE-2023-35151 HIGH
XWiki 7.3-milestone-1-14.4.8 - Unauthenticated Exposure of Obfuscated Passwords via REST Endpoint
CVSS 7.5
CVE-2023-34467 HIGH
XWiki Platform <14.4.8-15.0-rc-1 - Info Disclosure
CVSS 7.5
CVE-2023-2820 MEDIUM
Proofpoint Threat Response <5.10.0 - Info Disclosure
CVSS 6.1
CVE-2023-32019 MEDIUM
Windows Kernel - Information Disclosure via KTM Registry Transactions
CVSS 4.7
CVE-2023-29355 MEDIUM
Windows Server 2012, 2016, 2019, 2022 - Information Disclosure in DHCP Server Service
CVSS 5.3
CVE-2023-34250 MEDIUM
Discourse < 3.0.4 - Unauthorized Sensitive Information Exposure via New Topics Dismissal Endpoint
CVSS 4.8
CVE-2023-34114 HIGH
Zoom < 5.14.10 - Authenticated Information Disclosure via Network Access
CVSS 7.4
CVE-2023-29403 HIGH
GO < 1.19.10 - Exposure to Wrong Actor
CVSS 7.8
CVE-2023-33510 HIGH
Jeecg P3 Biz Chat <1.0.5 - Info Disclosure
CVSS 7.5
CVE-2023-32550 CRITICAL
Landscape < 19.10.5 - Sensitive Information Exposure via Server-Status Page
CVSS 9.3
CVE-2023-33518 MEDIUM
emoncms v11 and later - Information Disclosure via Crafted Web Request
CVSS 5.3
CVE-2023-29538 MEDIUM
Firefox < 112.0 - Directory Path Exposure via WebExtension URI Handling
CVSS 4.3
CVE-2023-25750 MEDIUM
Firefox < 111.0 - Path Traversal via ServiceWorker Offline Cache
CVSS 4.3
CVE-2023-2062 MEDIUM
Mitsubishielectric Fx5-enet/ip Firmware - Exposure to Wrong Actor
CVSS 6.2
CVE-2023-28344 HIGH
Faronics Insight 10.0.19045 - Unauthenticated Screenshot Spoofing and Information Disclosure
CVSS 7.1
CVE-2023-2703 HIGH
Finex Media Competition Management System < 23.07 - Exposure of Private Personal Information
CVSS 7.5
Details
Vulnerabilities 732