CWE-668
Exposure of Resource to Wrong Sphere
Description
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Hierarchy (View 1000)
CVEs mapped to this weakness (796)
page 19 of 40| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-1501 | Med | 0.42 | 6.5 | 0.01 | Jul 26, 2022 | Inappropriate implementation in iframe in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | ||
| CVE-2022-1137 | Med | 0.42 | 6.5 | 0.01 | Jul 23, 2022 | Inappropriate implementation in Extensions in Google Chrome prior to 100.0.4896.60 allowed an attacker who convinced a user to install a malicious extension to leak potentially sensitive information via a crafted HTML page. | ||
| CVE-2022-23825 | Med | 0.42 | 6.5 | 0.01 | Jul 14, 2022 | Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure. | ||
| CVE-2022-28924 | Med | 0.42 | 6.5 | 0.01 | May 18, 2022 | An information disclosure vulnerability in UniverSIS-Students before v1.5.0 allows attackers to obtain sensitive information via a crafted GET request to the endpoint /api/students/me/courses/. | ||
| CVE-2022-24897 | Hig | 0.42 | 7.5 | 0.02 | May 2, 2022 | APIs to evaluate content with Velocity is a package for APIs to evaluate content with Velocity. Starting with version 2.3 and prior to 12.6.7, 12.10.3, and 13.0, the velocity scripts are not properly sandboxed against using the Java File API to perform read or write operations… | ||
| CVE-2022-28160 | Med | 0.42 | 6.5 | 0.01 | Mar 29, 2022 | Jenkins Tests Selector Plugin 1.3.3 and earlier allows users with Item/Configure permission to read arbitrary files on the Jenkins controller. | ||
| CVE-2022-0315 | Hig | 0.42 | 7.5 | 0.01 | Mar 24, 2022 | Insecure Temporary File in GitHub repository horovod/horovod prior to 0.24.0. | ||
| CVE-2022-0815 | Med | 0.42 | 6.5 | 0.01 | Mar 10, 2022 | Improper access control vulnerability in McAfee WebAdvisor Chrome and Edge browser extensions up to 8.1.0.1895 allows a remote attacker to gain access to McAfee WebAdvisor settings and other details about the user’s system. This could lead to unexpected behaviors including;… | ||
| CVE-2021-28488 | Med | 0.42 | 6.5 | 0.01 | Mar 10, 2022 | Ericsson Network Manager (ENM) before 21.2 has incorrect access-control behavior (that only affects the level of access available to persons who were already granted a highly privileged role). Users in the same AMOS authorization group can retrieve managed-network data that was… | ||
| CVE-2022-0736 | Hig | 0.42 | 7.5 | 0.02 | Feb 23, 2022 | Insecure Temporary File in GitHub repository mlflow/mlflow prior to 1.23.1. | ||
| CVE-2020-13670 | Hig | 0.42 | 7.5 | 0.01 | Feb 11, 2022 | Information Disclosure vulnerability in file module of Drupal Core allows an attacker to gain access to the file metadata of a permanent private file that they do not have access to by guessing the ID of the file. This issue affects: Drupal Core 8.8.x versions prior to 8.8.10;… | ||
| CVE-2021-1918 | Med | 0.42 | 6.5 | 0.00 | Jan 3, 2022 | Improper handling of resource allocation in virtual machines can lead to information exposure in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile | ||
| CVE-2020-35215 | Med | 0.42 | 6.5 | 0.01 | Dec 16, 2021 | An issue in Atomix v3.1.5 allows attackers to access sensitive information when a malicious Atomix node queries distributed variable primitives which contain the entire primitive lists that ONOS nodes use to share important states. | ||
| CVE-2021-38931 | Med | 0.42 | 6.5 | 0.01 | Dec 9, 2021 | IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1, and 11.5 is vulnerable to an information disclosure as a result of a connected user having indirect read access to a table where they are not authorized to select from. IBM X-Force ID: 210418. | ||
| CVE-2021-38505 | Med | 0.42 | 6.5 | 0.01 | Dec 8, 2021 | Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will record data copied to the clipboard to the cloud, and make it available on other computers in certain scenarios. Applications that wish to prevent copied data from being recorded in… | ||
| CVE-2021-29280 | Med | 0.42 | 6.4 | 0.01 | Aug 19, 2021 | In TP-Link Wireless N Router WR840N an ARP poisoning attack can cause buffer overflow | ||
| CVE-2020-22535 | Med | 0.42 | 6.5 | 0.01 | Jul 9, 2021 | Incorrect Access Control vulnerability in PbootCMS 2.0.6 via the list parameter in the update function in upgradecontroller.php. | ||
| CVE-2021-20461 | Med | 0.42 | 6.5 | 0.01 | Jun 30, 2021 | IBM Cognos Analytics 10.0 and 11.1 is susceptible to a weakness in the implementation of the System Appearance configuration setting. An attacker could potentially bypass business logic to modify the appearance and behavior of the application. IBM X-Force ID: 196770. | ||
| CVE-2020-24511 | Med | 0.42 | 6.5 | 0.00 | Jun 9, 2021 | Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. | ||
| CVE-2021-23958 | Med | 0.42 | 6.5 | 0.01 | Feb 26, 2021 | The browser could have been confused into transferring a screen sharing state into another tab, which would leak unintended information. This vulnerability affects Firefox < 85. |
- risk 0.42cvss 6.5epss 0.01
Inappropriate implementation in iframe in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- risk 0.42cvss 6.5epss 0.01
Inappropriate implementation in Extensions in Google Chrome prior to 100.0.4896.60 allowed an attacker who convinced a user to install a malicious extension to leak potentially sensitive information via a crafted HTML page.
- risk 0.42cvss 6.5epss 0.01
Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure.
- risk 0.42cvss 6.5epss 0.01
An information disclosure vulnerability in UniverSIS-Students before v1.5.0 allows attackers to obtain sensitive information via a crafted GET request to the endpoint /api/students/me/courses/.
- risk 0.42cvss 7.5epss 0.02
APIs to evaluate content with Velocity is a package for APIs to evaluate content with Velocity. Starting with version 2.3 and prior to 12.6.7, 12.10.3, and 13.0, the velocity scripts are not properly sandboxed against using the Java File API to perform read or write operations…
- risk 0.42cvss 6.5epss 0.01
Jenkins Tests Selector Plugin 1.3.3 and earlier allows users with Item/Configure permission to read arbitrary files on the Jenkins controller.
- risk 0.42cvss 7.5epss 0.01
Insecure Temporary File in GitHub repository horovod/horovod prior to 0.24.0.
- risk 0.42cvss 6.5epss 0.01
Improper access control vulnerability in McAfee WebAdvisor Chrome and Edge browser extensions up to 8.1.0.1895 allows a remote attacker to gain access to McAfee WebAdvisor settings and other details about the user’s system. This could lead to unexpected behaviors including;…
- risk 0.42cvss 6.5epss 0.01
Ericsson Network Manager (ENM) before 21.2 has incorrect access-control behavior (that only affects the level of access available to persons who were already granted a highly privileged role). Users in the same AMOS authorization group can retrieve managed-network data that was…
- risk 0.42cvss 7.5epss 0.02
Insecure Temporary File in GitHub repository mlflow/mlflow prior to 1.23.1.
- risk 0.42cvss 7.5epss 0.01
Information Disclosure vulnerability in file module of Drupal Core allows an attacker to gain access to the file metadata of a permanent private file that they do not have access to by guessing the ID of the file. This issue affects: Drupal Core 8.8.x versions prior to 8.8.10;…
- risk 0.42cvss 6.5epss 0.00
Improper handling of resource allocation in virtual machines can lead to information exposure in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile
- risk 0.42cvss 6.5epss 0.01
An issue in Atomix v3.1.5 allows attackers to access sensitive information when a malicious Atomix node queries distributed variable primitives which contain the entire primitive lists that ONOS nodes use to share important states.
- risk 0.42cvss 6.5epss 0.01
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1, and 11.5 is vulnerable to an information disclosure as a result of a connected user having indirect read access to a table where they are not authorized to select from. IBM X-Force ID: 210418.
- risk 0.42cvss 6.5epss 0.01
Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will record data copied to the clipboard to the cloud, and make it available on other computers in certain scenarios. Applications that wish to prevent copied data from being recorded in…
- risk 0.42cvss 6.4epss 0.01
In TP-Link Wireless N Router WR840N an ARP poisoning attack can cause buffer overflow
- risk 0.42cvss 6.5epss 0.01
Incorrect Access Control vulnerability in PbootCMS 2.0.6 via the list parameter in the update function in upgradecontroller.php.
- risk 0.42cvss 6.5epss 0.01
IBM Cognos Analytics 10.0 and 11.1 is susceptible to a weakness in the implementation of the System Appearance configuration setting. An attacker could potentially bypass business logic to modify the appearance and behavior of the application. IBM X-Force ID: 196770.
- risk 0.42cvss 6.5epss 0.00
Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
- risk 0.42cvss 6.5epss 0.01
The browser could have been confused into transferring a screen sharing state into another tab, which would leak unintended information. This vulnerability affects Firefox < 85.