VYPR

CWE-668

Exposure of Resource to Wrong Sphere

ClassDraft

Description

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

Hierarchy (View 1000)

CVEs mapped to this weakness (784)

page 12 of 40
  • CVE-2021-23034HigSep 14, 2021
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP version 16.x before 16.1.0 and 15.1.x before 15.1.3.1, when a DNS profile using a DNS cache resolver is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) process to terminate. Note: Software versions which have…

  • CVE-2021-21996HigSep 8, 2021
    risk 0.49cvss 7.5epss 0.04

    An issue was discovered in SaltStack Salt before 3003.3. A user who has control of the source, and source_hash URLs can gain full file system access as root on a salt minion.

  • CVE-2021-38712HigAug 16, 2021
    risk 0.49cvss 7.5epss 0.01

    OneNav 0.9.12 allows Information Disclosure of the onenav.db3 contents. NOTE: the vendor's recommended solution is to block the access via an NGINX configuration file.

  • CVE-2021-36793HigAug 13, 2021
    risk 0.49cvss 7.5epss 0.01

    The routes (aka Extbase Yaml Routes) extension before 2.1.1 for TYPO3, when CsrfTokenViewHelper is used, allows Sensitive Information Disclosure because a session identifier is unsafely present in HTML output.

  • CVE-2020-18754HigAug 13, 2021
    risk 0.49cvss 7.5epss 0.01

    An information disclosure vulnerability exists within Dut Computer Control Engineering Co.'s PLC MAC1100.

  • CVE-2020-27361HigJul 1, 2021
    risk 0.49cvss 7.5epss 0.07

    An issue exists within Akkadian Provisioning Manager 4.50.02 which allows attackers to view sensitive information within the /pme subdirectories.

  • CVE-2020-18647HigJun 22, 2021
    risk 0.49cvss 7.5epss 0.02

    Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/nonecms/vendor".

  • CVE-2020-18646HigJun 22, 2021
    risk 0.49cvss 7.5epss 0.02

    Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/public/index.php".

  • CVE-2020-10581HigMar 25, 2021
    risk 0.49cvss 7.5epss 0.01

    Multiple session validity check issues in several administration functionalities of Invigo Automatic Device Management (ADM) through 5.0 allow remote attackers to read potentially sensitive data hosted by the application.

  • CVE-2015-9550HigNov 24, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered on TOTOLINK A850R-V1 through 1.0.1-B20150707.1612 and F1-V2 through 1.1-B20150708.1646 devices. By sending a specific hel,xasf packet to the WAN interface, it is possible to open the web management interface on the WAN interface.

  • CVE-2020-26868HigOct 12, 2020
    risk 0.49cvss 7.5epss 0.02

    ARC Informatique PcVue prior to version 12.0.17 is vulnerable to a denial-of-service attack due to the ability of an unauthorized user to modify information used to validate messages sent by legitimate web clients. This issue also affects third-party systems based on the Web…

  • CVE-2020-26602HigOct 6, 2020
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in EthernetNetwork on Samsung mobile devices with O(8.1), P(9.0), Q(10.0), and R(11.0) software. PendingIntent allows sdcard access by an unprivileged process. The Samsung ID is SVE-2020-18392 (October 2020).

  • CVE-2020-13343HigOct 6, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue has been discovered in GitLab affecting all versions starting from 11.2. Unauthorized Users Can View Custom Project Template

  • CVE-2020-5386HigSep 2, 2020
    risk 0.49cvss 7.5epss 0.01

    Dell EMC ECS, versions prior to 3.5, contains an Exposure of Resource vulnerability. A remote unauthenticated attacker can access the list of DT (Directory Table) objects of all internally running services and gain knowledge of sensitive data of the system.

  • CVE-2020-10238HigMar 16, 2020
    risk 0.49cvss 7.5epss 0.05

    An issue was discovered in Joomla! before 3.9.16. Various actions in com_templates lack the required ACL checks, leading to various potential attack vectors.

  • CVE-2019-10805HigFeb 28, 2020
    risk 0.49cvss 7.5epss 0.01

    valib through 2.0.0 allows Internal Property Tampering. A maliciously crafted JavaScript object can bypass several inspection functions provided by valib. Valib uses a built-in function (hasOwnProperty) from the unsafe user-input to examine an object. It is possible for a…

  • CVE-2019-10790HigFeb 17, 2020
    risk 0.49cvss 7.5epss 0.02

    taffydb npm module, vulnerable in all versions up to and including 2.7.3, allows attackers to forge adding additional properties into user-input processed by taffy which can allow access to any data items in the DB. taffy sets an internal index for each data item in its DB.…

  • CVE-2020-8449HigFeb 4, 2020
    risk 0.49cvss 7.5epss 0.08

    An issue was discovered in Squid before 4.10. Due to incorrect input validation, it can interpret crafted HTTP requests in unexpected ways to access server resources prohibited by earlier security filters.

  • CVE-2017-18073HigApr 11, 2018
    risk 0.49cvss 7.5epss 0.01

    In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 820, SD 820A, SD 835, the HLOS can gain access to unauthorized memory.

  • CVE-2017-11382HigAug 3, 2017
    risk 0.49cvss 7.5epss 0.02

    Denial of Service vulnerability in Trend Micro Deep Discovery Email Inspector 2.5.1 allows remote attackers to delete arbitrary files on vulnerable installations, thus disabling the service. Formerly ZDI-CAN-4350.