VYPR

CWE-668

Exposure of Resource to Wrong Sphere

ClassDraft

Description

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

Hierarchy (View 1000)

CVEs mapped to this weakness (796)

page 18 of 40
  • CVE-2023-29208HigApr 15, 2023
    risk 0.42cvss 7.5epss 0.01

    XWiki Commons are technical libraries common to several other top level XWiki projects. Rights added to a document are not taken into account for viewing it once it's deleted. Note that this vulnerability only impact deleted documents that where containing view rights: the view…

  • CVE-2023-1777MedMar 31, 2023
    risk 0.42cvss 6.5epss 0.01

    Mattermost allows an attacker to request a preview of an existing message when creating a new message via the createPost API call, disclosing the contents of the linked message.

  • CVE-2023-24906MedMar 14, 2023
    risk 0.42cvss 6.5epss 0.01

    Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability

  • CVE-2023-24870MedMar 14, 2023
    risk 0.42cvss 6.5epss 0.01

    Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability

  • CVE-2023-24866MedMar 14, 2023
    risk 0.42cvss 6.5epss 0.02

    Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability

  • CVE-2023-24863MedMar 14, 2023
    risk 0.42cvss 6.5epss 0.01

    Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability

  • CVE-2023-20061MedMar 3, 2023
    risk 0.42cvss 6.5epss 0.01

    Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect sensitive information or perform a server-side request forgery (SSRF) attack on an affected system. Cisco plans to release software updates that address these…

  • CVE-2023-22775MedMar 1, 2023
    risk 0.42cvss 6.5epss 0.01

    A vulnerability exists which allows an authenticated attacker to access sensitive information on the ArubaOS command line interface. Successful exploitation could allow access to data beyond what is authorized by the users existing privilege level.

  • CVE-2022-44310HigFeb 24, 2023
    risk 0.42cvss 7.5epss 0.01

    In Development IL ecdh before 0.2.0, an attacker can send an invalid point (not on the curve) as the public key, and obtain the derived shared secret.

  • CVE-2022-34387MedFeb 11, 2023
    risk 0.42cvss 6.4epss 0.00

    Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain a privilege escalation vulnerability. A local authenticated malicious user could potentially exploit this vulnerability to elevate privileges and…

  • CVE-2023-22497MedJan 14, 2023
    risk 0.42cvss 6.5epss 0.01

    Netdata is an open source option for real-time infrastructure monitoring and troubleshooting. Each Netdata Agent has an automatically generated MACHINE GUID. It is generated when the agent first starts and it is saved to disk, so that it will persist across restarts and reboots.…

  • CVE-2022-0337MedJan 2, 2023
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in File System API in Google Chrome on Windows prior to 97.0.4692.71 allowed a remote attacker to obtain potentially sensitive information via a crafted HTML page. (Chrome security severity: High)

  • CVE-2015-10004HigDec 27, 2022
    risk 0.42cvss 7.5epss 0.01

    Token validation methods are susceptible to a timing side-channel during HMAC comparison. With a large enough number of requests over a low latency connection, an attacker may use this to determine the expected HMAC.

  • CVE-2022-45895MedDec 25, 2022
    risk 0.42cvss 6.5epss 0.01

    Planet eStream before 6.72.10.07 discloses sensitive information, related to the ON cookie (findable in HTML source code for Default.aspx in some situations) and the WhoAmI endpoint (e.g., path disclosure).

  • CVE-2022-38599MedDec 8, 2022
    risk 0.42cvss 6.5epss 0.01

    Teleport v3.2.2, Teleport v3.5.6-rc6, and Teleport v3.6.3-b2 was discovered to contain an information leak via the /user/get-role-list web interface.

  • CVE-2022-39015MedOct 11, 2022
    risk 0.42cvss 6.5epss 0.01

    Under certain conditions, BOE AdminTools/ BOE SDK allows an attacker to access information which would otherwise be restricted.

  • CVE-2022-2403MedSep 1, 2022
    risk 0.42cvss 6.5epss 0.01

    A credentials leak was found in the OpenShift Container Platform. The private key for the external cluster certificate was stored incorrectly in the oauth-serving-cert ConfigMaps, and accessible to any authenticated OpenShift user or service-account. A malicious user could…

  • CVE-2021-3859HigAug 26, 2022
    risk 0.42cvss 7.5epss 0.02

    A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks.

  • CVE-2022-2610MedAug 12, 2022
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in Background Fetch in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2022-1873MedJul 27, 2022
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in COOP in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to leak cross-origin data via a crafted HTML page.