CWE-668
Exposure of Resource to Wrong Sphere
Description
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Hierarchy (View 1000)
CVEs mapped to this weakness (784)
page 23 of 40| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-46906 | Med | 0.36 | 5.5 | 0.00 | Feb 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: HID: usbhid: fix info leak in hid_submit_ctrl In hid_submit_ctrl(), the way of calculating the report length doesn't take into account that report->size can be zero. When running the syzkaller reproducer, a… | ||
| CVE-2024-0443 | Med | 0.36 | 5.5 | 0.00 | Jan 12, 2024 | A flaw was found in the blkgs destruction path in block/blk-cgroup.c in the Linux kernel, leading to a cgroup blkio memory leakage problem. When a cgroup is being destroyed, cgroup_rstat_flush() is only called at css_release_work_fn(), which is called when the blkcg reference… | ||
| CVE-2024-20694 | Med | 0.36 | 5.5 | 0.01 | Jan 9, 2024 | Windows CoreMessaging Information Disclosure Vulnerability | ||
| CVE-2023-42718 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In dialer, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed | ||
| CVE-2023-42715 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed | ||
| CVE-2023-42551 | Med | 0.36 | 5.5 | 0.00 | Nov 7, 2023 | Use of implicit intent for sensitive communication vulnerability in startTncActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege. | ||
| CVE-2023-42549 | Med | 0.36 | 5.5 | 0.00 | Nov 7, 2023 | Use of implicit intent for sensitive communication vulnerability in startNameValidationActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege. | ||
| CVE-2023-42547 | Med | 0.36 | 5.5 | 0.00 | Nov 7, 2023 | Use of implicit intent for sensitive communication vulnerability in startEmailValidationActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege. | ||
| CVE-2023-42546 | Med | 0.36 | 5.5 | 0.00 | Nov 7, 2023 | Use of implicit intent for sensitive communication vulnerability in startAgreeToDisclaimerActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege. | ||
| CVE-2023-4910 | Med | 0.36 | 5.5 | 0.00 | Nov 6, 2023 | A flaw was found In 3Scale Admin Portal. If a user logs out from the personal tokens page and then presses the back button in the browser, the tokens page is rendered from the browser cache. | ||
| CVE-2023-32275 | Med | 0.36 | 5.5 | 0.00 | Oct 12, 2023 | An information disclosure vulnerability exists in the CtEnumCa() functionality of SoftEther VPN 4.41-9782-beta and 5.01.9674. Specially crafted network packets can lead to a disclosure of sensitive information. An attacker can send packets to trigger this vulnerability. | ||
| CVE-2023-43782 | Med | 0.36 | 5.5 | 0.00 | Sep 22, 2023 | Cadence through 0.9.2 2023-08-21 uses an Insecure /tmp/.cadence-aloop-daemon.x Temporary File. The file is used even if it has been created by a local adversary before Cadence started. The adversary can then delete the file, disrupting Cadence. | ||
| CVE-2023-38558 | Med | 0.36 | 5.5 | 0.00 | Sep 14, 2023 | A vulnerability has been identified in SIMATIC PCS neo (Administration Console) V4.0 (All versions), SIMATIC PCS neo (Administration Console) V4.0 Update 1 (All versions). The affected application leaks Windows admin credentials. An attacker with local access to the… | ||
| CVE-2023-38152 | Med | 0.36 | 5.3 | 0.24 | Sep 12, 2023 | DHCP Server Service Information Disclosure Vulnerability | ||
| CVE-2023-41745 | Med | 0.36 | 5.5 | 0.00 | Aug 31, 2023 | Sensitive information disclosure due to excessive collection of system information. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 30991, Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979. | ||
| CVE-2023-37645 | Med | 0.36 | 5.3 | 0.25 | Jul 20, 2023 | eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/recruit.filelist.txt. | ||
| CVE-2023-29820 | Med | 0.36 | 5.5 | 0.00 | May 12, 2023 | An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to access sensitive information via the EXE installer. NOTE: the vendor's perspective is that this is not a separate vulnerability relative to CVE-2023-29818 and… | ||
| CVE-2023-22307 | Med | 0.36 | 5.5 | 0.00 | Apr 18, 2023 | Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.4 allows local attacker to retrieve passwords via reading log files. | ||
| CVE-2023-25954 | Med | 0.36 | 5.5 | 0.00 | Apr 13, 2023 | KYOCERA Mobile Print' v3.2.0.230119 and earlier, 'UTAX/TA MobilePrint' v3.2.0.230119 and earlier, and 'Olivetti Mobile Print' v3.2.0.230119 and earlier are vulnerable to improper intent handling. When a malicious app is installed on the victim user's Android device, the app may… | ||
| CVE-2023-23409 | Med | 0.36 | 5.5 | 0.00 | Mar 14, 2023 | Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability |
- risk 0.36cvss 5.5epss 0.00
In the Linux kernel, the following vulnerability has been resolved: HID: usbhid: fix info leak in hid_submit_ctrl In hid_submit_ctrl(), the way of calculating the report length doesn't take into account that report->size can be zero. When running the syzkaller reproducer, a…
- risk 0.36cvss 5.5epss 0.00
A flaw was found in the blkgs destruction path in block/blk-cgroup.c in the Linux kernel, leading to a cgroup blkio memory leakage problem. When a cgroup is being destroyed, cgroup_rstat_flush() is only called at css_release_work_fn(), which is called when the blkcg reference…
- risk 0.36cvss 5.5epss 0.01
Windows CoreMessaging Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.00
In dialer, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
Use of implicit intent for sensitive communication vulnerability in startTncActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.
- risk 0.36cvss 5.5epss 0.00
Use of implicit intent for sensitive communication vulnerability in startNameValidationActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.
- risk 0.36cvss 5.5epss 0.00
Use of implicit intent for sensitive communication vulnerability in startEmailValidationActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.
- risk 0.36cvss 5.5epss 0.00
Use of implicit intent for sensitive communication vulnerability in startAgreeToDisclaimerActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.
- risk 0.36cvss 5.5epss 0.00
A flaw was found In 3Scale Admin Portal. If a user logs out from the personal tokens page and then presses the back button in the browser, the tokens page is rendered from the browser cache.
- risk 0.36cvss 5.5epss 0.00
An information disclosure vulnerability exists in the CtEnumCa() functionality of SoftEther VPN 4.41-9782-beta and 5.01.9674. Specially crafted network packets can lead to a disclosure of sensitive information. An attacker can send packets to trigger this vulnerability.
- risk 0.36cvss 5.5epss 0.00
Cadence through 0.9.2 2023-08-21 uses an Insecure /tmp/.cadence-aloop-daemon.x Temporary File. The file is used even if it has been created by a local adversary before Cadence started. The adversary can then delete the file, disrupting Cadence.
- risk 0.36cvss 5.5epss 0.00
A vulnerability has been identified in SIMATIC PCS neo (Administration Console) V4.0 (All versions), SIMATIC PCS neo (Administration Console) V4.0 Update 1 (All versions). The affected application leaks Windows admin credentials. An attacker with local access to the…
- risk 0.36cvss 5.3epss 0.24
DHCP Server Service Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.00
Sensitive information disclosure due to excessive collection of system information. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 30991, Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979.
- risk 0.36cvss 5.3epss 0.25
eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/recruit.filelist.txt.
- risk 0.36cvss 5.5epss 0.00
An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to access sensitive information via the EXE installer. NOTE: the vendor's perspective is that this is not a separate vulnerability relative to CVE-2023-29818 and…
- risk 0.36cvss 5.5epss 0.00
Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.4 allows local attacker to retrieve passwords via reading log files.
- risk 0.36cvss 5.5epss 0.00
KYOCERA Mobile Print' v3.2.0.230119 and earlier, 'UTAX/TA MobilePrint' v3.2.0.230119 and earlier, and 'Olivetti Mobile Print' v3.2.0.230119 and earlier are vulnerable to improper intent handling. When a malicious app is installed on the victim user's Android device, the app may…
- risk 0.36cvss 5.5epss 0.00
Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability