VYPR

CWE-668

Exposure of Resource to Wrong Sphere

ClassDraft

Description

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

Hierarchy (View 1000)

CVEs mapped to this weakness (784)

page 19 of 40
  • CVE-2022-24897HigMay 2, 2022
    risk 0.42cvss 7.5epss 0.02

    APIs to evaluate content with Velocity is a package for APIs to evaluate content with Velocity. Starting with version 2.3 and prior to 12.6.7, 12.10.3, and 13.0, the velocity scripts are not properly sandboxed against using the Java File API to perform read or write operations…

  • CVE-2022-28160MedMar 29, 2022
    risk 0.42cvss 6.5epss 0.01

    Jenkins Tests Selector Plugin 1.3.3 and earlier allows users with Item/Configure permission to read arbitrary files on the Jenkins controller.

  • CVE-2022-0315HigMar 24, 2022
    risk 0.42cvss 7.5epss 0.01

    Insecure Temporary File in GitHub repository horovod/horovod prior to 0.24.0.

  • CVE-2022-0815MedMar 10, 2022
    risk 0.42cvss 6.5epss 0.01

    Improper access control vulnerability in McAfee WebAdvisor Chrome and Edge browser extensions up to 8.1.0.1895 allows a remote attacker to gain access to McAfee WebAdvisor settings and other details about the user’s system. This could lead to unexpected behaviors including;…

  • CVE-2021-28488MedMar 10, 2022
    risk 0.42cvss 6.5epss 0.01

    Ericsson Network Manager (ENM) before 21.2 has incorrect access-control behavior (that only affects the level of access available to persons who were already granted a highly privileged role). Users in the same AMOS authorization group can retrieve managed-network data that was…

  • CVE-2022-0736HigFeb 23, 2022
    risk 0.42cvss 7.5epss 0.02

    Insecure Temporary File in GitHub repository mlflow/mlflow prior to 1.23.1.

  • CVE-2020-13670HigFeb 11, 2022
    risk 0.42cvss 7.5epss 0.01

    Information Disclosure vulnerability in file module of Drupal Core allows an attacker to gain access to the file metadata of a permanent private file that they do not have access to by guessing the ID of the file. This issue affects: Drupal Core 8.8.x versions prior to 8.8.10;…

  • CVE-2021-1918MedJan 3, 2022
    risk 0.42cvss 6.5epss 0.00

    Improper handling of resource allocation in virtual machines can lead to information exposure in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2020-35215MedDec 16, 2021
    risk 0.42cvss 6.5epss 0.01

    An issue in Atomix v3.1.5 allows attackers to access sensitive information when a malicious Atomix node queries distributed variable primitives which contain the entire primitive lists that ONOS nodes use to share important states.

  • CVE-2021-38931MedDec 9, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1, and 11.5 is vulnerable to an information disclosure as a result of a connected user having indirect read access to a table where they are not authorized to select from. IBM X-Force ID: 210418.

  • CVE-2021-38505MedDec 8, 2021
    risk 0.42cvss 6.5epss 0.01

    Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will record data copied to the clipboard to the cloud, and make it available on other computers in certain scenarios. Applications that wish to prevent copied data from being recorded in…

  • CVE-2021-29280MedAug 19, 2021
    risk 0.42cvss 6.4epss 0.01

    In TP-Link Wireless N Router WR840N an ARP poisoning attack can cause buffer overflow

  • CVE-2020-22535MedJul 9, 2021
    risk 0.42cvss 6.5epss 0.01

    Incorrect Access Control vulnerability in PbootCMS 2.0.6 via the list parameter in the update function in upgradecontroller.php.

  • CVE-2021-20461MedJun 30, 2021
    risk 0.42cvss 6.5epss 0.01

    IBM Cognos Analytics 10.0 and 11.1 is susceptible to a weakness in the implementation of the System Appearance configuration setting. An attacker could potentially bypass business logic to modify the appearance and behavior of the application. IBM X-Force ID: 196770.

  • CVE-2020-24511MedJun 9, 2021
    risk 0.42cvss 6.5epss 0.00

    Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2021-23958MedFeb 26, 2021
    risk 0.42cvss 6.5epss 0.01

    The browser could have been confused into transferring a screen sharing state into another tab, which would leak unintended information. This vulnerability affects Firefox < 85.

  • CVE-2020-26084MedNov 6, 2020
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the REST API of Cisco Edge Fog Fabric could allow an authenticated, remote attacker to access files outside of their authorization sphere on an affected device. The vulnerability is due to incorrect authorization enforcement on an affected system. An attacker…

  • CVE-2020-5422MedOct 2, 2020
    risk 0.42cvss 6.5epss 0.01

    BOSH System Metrics Server releases prior to 0.1.0 exposed the UAA password as a flag to a process running on the BOSH director. It exposed the password to any user or process with access to the same VM (through ps or looking at process details).

  • CVE-2020-14064MedJul 15, 2020
    risk 0.42cvss 6.5epss 0.01

    IceWarp Email Server 12.3.0.1 has Incorrect Access Control for user accounts.

  • CVE-2019-20149HigDec 30, 2019
    risk 0.42cvss 7.5epss 0.02

    ctorName in index.js in kind-of v6.0.2 allows external user input to overwrite certain internal attributes via a conflicting name, as demonstrated by 'constructor': {'name':'Symbol'}. Hence, a crafted payload can overwrite this builtin attribute to manipulate the type detection…