VYPR

CWE-668

Exposure of Resource to Wrong Sphere

ClassDraft

Description

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

Hierarchy (View 1000)

CVEs mapped to this weakness (784)

page 23 of 40
  • CVE-2021-46906MedFeb 26, 2024
    risk 0.36cvss 5.5epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: HID: usbhid: fix info leak in hid_submit_ctrl In hid_submit_ctrl(), the way of calculating the report length doesn't take into account that report->size can be zero. When running the syzkaller reproducer, a…

  • CVE-2024-0443MedJan 12, 2024
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in the blkgs destruction path in block/blk-cgroup.c in the Linux kernel, leading to a cgroup blkio memory leakage problem. When a cgroup is being destroyed, cgroup_rstat_flush() is only called at css_release_work_fn(), which is called when the blkcg reference…

  • CVE-2024-20694MedJan 9, 2024
    risk 0.36cvss 5.5epss 0.01

    Windows CoreMessaging Information Disclosure Vulnerability

  • CVE-2023-42718MedDec 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In dialer, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed

  • CVE-2023-42715MedDec 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

  • CVE-2023-42551MedNov 7, 2023
    risk 0.36cvss 5.5epss 0.00

    Use of implicit intent for sensitive communication vulnerability in startTncActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.

  • CVE-2023-42549MedNov 7, 2023
    risk 0.36cvss 5.5epss 0.00

    Use of implicit intent for sensitive communication vulnerability in startNameValidationActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.

  • CVE-2023-42547MedNov 7, 2023
    risk 0.36cvss 5.5epss 0.00

    Use of implicit intent for sensitive communication vulnerability in startEmailValidationActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.

  • CVE-2023-42546MedNov 7, 2023
    risk 0.36cvss 5.5epss 0.00

    Use of implicit intent for sensitive communication vulnerability in startAgreeToDisclaimerActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.

  • CVE-2023-4910MedNov 6, 2023
    risk 0.36cvss 5.5epss 0.00

    A flaw was found In 3Scale Admin Portal. If a user logs out from the personal tokens page and then presses the back button in the browser, the tokens page is rendered from the browser cache.

  • CVE-2023-32275MedOct 12, 2023
    risk 0.36cvss 5.5epss 0.00

    An information disclosure vulnerability exists in the CtEnumCa() functionality of SoftEther VPN 4.41-9782-beta and 5.01.9674. Specially crafted network packets can lead to a disclosure of sensitive information. An attacker can send packets to trigger this vulnerability.

  • CVE-2023-43782MedSep 22, 2023
    risk 0.36cvss 5.5epss 0.00

    Cadence through 0.9.2 2023-08-21 uses an Insecure /tmp/.cadence-aloop-daemon.x Temporary File. The file is used even if it has been created by a local adversary before Cadence started. The adversary can then delete the file, disrupting Cadence.

  • CVE-2023-38558MedSep 14, 2023
    risk 0.36cvss 5.5epss 0.00

    A vulnerability has been identified in SIMATIC PCS neo (Administration Console) V4.0 (All versions), SIMATIC PCS neo (Administration Console) V4.0 Update 1 (All versions). The affected application leaks Windows admin credentials. An attacker with local access to the…

  • CVE-2023-38152MedSep 12, 2023
    risk 0.36cvss 5.3epss 0.24

    DHCP Server Service Information Disclosure Vulnerability

  • CVE-2023-41745MedAug 31, 2023
    risk 0.36cvss 5.5epss 0.00

    Sensitive information disclosure due to excessive collection of system information. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 30991, Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979.

  • CVE-2023-37645MedJul 20, 2023
    risk 0.36cvss 5.3epss 0.25

    eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/recruit.filelist.txt.

  • CVE-2023-29820MedMay 12, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to access sensitive information via the EXE installer. NOTE: the vendor's perspective is that this is not a separate vulnerability relative to CVE-2023-29818 and…

  • CVE-2023-22307MedApr 18, 2023
    risk 0.36cvss 5.5epss 0.00

    Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.4 allows local attacker to retrieve passwords via reading log files.

  • CVE-2023-25954MedApr 13, 2023
    risk 0.36cvss 5.5epss 0.00

    KYOCERA Mobile Print' v3.2.0.230119 and earlier, 'UTAX/TA MobilePrint' v3.2.0.230119 and earlier, and 'Olivetti Mobile Print' v3.2.0.230119 and earlier are vulnerable to improper intent handling. When a malicious app is installed on the victim user's Android device, the app may…

  • CVE-2023-23409MedMar 14, 2023
    risk 0.36cvss 5.5epss 0.00

    Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability