CWE-669

Incorrect Resource Transfer Between Spheres

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.

87 vulnerabilities with CWE-669
CVE-2022-20658 CRITICAL
Cisco Unified CCMP/CCDM - Privilege Escalation
CVSS 9.6
CVE-2021-45891 HIGH
Softwarebuero Zauner ARC 4.2.0.4 - Privilege Escalation
CVSS 8.8
CVE-2021-22806 HIGH
spaceLYnk <2.6.1, Wiser for KNX <2.6.1, fellerLYnk <2.6.1 - Info Di...
CVSS 7.5
CVE-2021-25973 MEDIUM
Publify < 9.2.4 - Improper Authorization
CVSS 6.5
CVE-2021-24602 HIGH
Hmplugin HM Multiple Roles < 1.3 - Improper Privilege Management
CVSS 8.8
CVE-2021-34574 MEDIUM
mymbCONNECT24 - Auth Bypass
CVSS 4.3
CVE-2021-30120 CRITICAL
Kaseya VSA <9.5.7 - Auth Bypass
CVSS 9.9
CVE-2021-29960 MEDIUM
Firefox < 89 - Info Disclosure
CVSS 4.3
CVE-2021-22900 HIGH KEV
Pulse Connect Secure <9.1R11.4 - Code Injection
CVSS 7.2
CVE-2021-21531 HIGH
Dell Unisphere for PowerMax <9.2.1.6 - Auth Bypass
CVSS 8.1
CVE-2021-20411 HIGH
IBM Security Verify Information Queue <1.0.8 - Privilege Escalation
CVSS 8.1
CVE-2020-27268 MEDIUM
SOOIL Developments Co., Ltd Diabecare RS - Auth Bypass
CVSS 6.5
CVE-2020-25917 HIGH
Stratodesk Notouch Center < 4.4.68 - Missing Authorization
CVSS 8.8
CVE-2020-24683 CRITICAL
S+ Operations <2.1 SP1 - Auth Bypass
CVSS 9.8
CVE-2020-26177 MEDIUM
tangro Business Workflow <1.18.1 - Info Disclosure
CVSS 4.3
CVE-2020-5800 CRITICAL
Eat Spray Love - Auth Bypass
CVSS 9.8
CVE-2020-15257 MEDIUM
containerd <1.3.9 and <1.4.3 - Privilege Escalation
CVSS 5.2
CVE-2020-10778 MEDIUM
Red Hat CloudForms <5 - Info Disclosure
CVSS 6.0
CVE-2020-15892 CRITICAL
Dlink Dap-1520 Firmware < 1.10b04 - Out-of-Bounds Write
CVSS 9.8
CVE-2020-1048 HIGH
Microsoft Spooler Local Privilege Elevation Vulnerability
CVSS 7.8
CVE-2020-5188 MEDIUM
Dnnsoftware Dotnetnuke < 9.4.4 - Unrestricted File Upload
CVSS 6.5
CVE-2020-6862 MEDIUM
ZTE F6x2w Firmware - Information Disclosure
CVSS 5.3
CVE-2019-13025 CRITICAL
Compal Ch7465lg Firmware - OS Command Injection
CVSS 9.8
CVE-2019-10753 MEDIUM
Eclipse WTP/CDT/Groovy <3.9.6/<9.4.4/<3.0.1 - Info Disclosure
CVSS 5.9
CVE-2019-13266 HIGH
TP-Link Archer C3200 V1 & Archer C2 V1 - Info Disclosure
CVSS 8.8
Details
Vulnerabilities 87