VYPR

CWE-668

Exposure of Resource to Wrong Sphere

ClassDraft

Description

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

Hierarchy (View 1000)

CVEs mapped to this weakness (784)

page 24 of 40
  • CVE-2023-23394MedMar 14, 2023
    risk 0.36cvss 5.5epss 0.00

    Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability

  • CVE-2023-23501MedFeb 27, 2023
    risk 0.36cvss 5.5epss 0.00

    The issue was addressed with improved memory handling This issue is fixed in macOS Ventura 13.2. An app may be able to disclose kernel memory.

  • CVE-2023-21714MedFeb 14, 2023
    risk 0.36cvss 5.5epss 0.01

    Microsoft Office Information Disclosure Vulnerability

  • CVE-2023-21687MedFeb 14, 2023
    risk 0.36cvss 5.5epss 0.00

    HTTP.sys Information Disclosure Vulnerability

  • CVE-2023-21445MedFeb 9, 2023
    risk 0.36cvss 5.5epss 0.00

    Improper access control vulnerability in MyFiles prior to versions 12.2.09 in Android R(11), 13.1.03.501 in Android S(12) and 14.1.00.422 in Android T(13) allows local attacker to write file with MyFiles privilege via implicit intent.

  • CVE-2021-26343MedJan 11, 2023
    risk 0.36cvss 5.5epss 0.00

    Insufficient validation in ASP BIOS and DRTM commands may allow malicious supervisor x86 software to disclose the contents of sensitive memory which may result in information disclosure.

  • CVE-2022-2882MedOct 28, 2022
    risk 0.36cvss 5.5epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. A malicious maintainer could exfiltrate a GitHub integration's access token by…

  • CVE-2021-0734MedAug 11, 2022
    risk 0.36cvss 5.5epss 0.00

    In Settings, there is a possible way to determine whether an app is installed without query permissions, due to side channel information disclosure. This could lead to local information disclosure of an installed package, without proper query permissions, with no additional…

  • CVE-2022-34765MedJul 13, 2022
    risk 0.36cvss 5.5epss 0.01

    A CWE-73: External Control of File Name or Path vulnerability exists that could cause loading of unauthorized firmware images when user-controlled data is written to the file path. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V2.01 and later), OPC UA…

  • CVE-2022-30732MedJun 7, 2022
    risk 0.36cvss 5.5epss 0.01

    Exposure of Sensitive Information vulnerability in Samsung Account prior to version 13.2.00.6 allows attacker to access sensitive information via onActivityResult.

  • CVE-2021-39777MedMar 30, 2022
    risk 0.36cvss 5.5epss 0.00

    In Telephony, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-33096MedFeb 9, 2022
    risk 0.36cvss 5.5epss 0.00

    Improper isolation of shared resources in network on chip for the Intel(R) 82599 Ethernet Controllers and Adapters may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2022-21964MedJan 11, 2022
    risk 0.36cvss 5.5epss 0.01

    Remote Desktop Licensing Diagnoser Information Disclosure Vulnerability

  • CVE-2019-8702MedDec 23, 2021
    risk 0.36cvss 5.5epss 0.00

    This issue was addressed with a new entitlement. This issue is fixed in macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra, iOS 12.4, tvOS 12.4. A local user may be able to read a persistent account identifier.

  • CVE-2021-26327MedNov 16, 2021
    risk 0.36cvss 5.5epss 0.00

    Insufficient validation of guest context in the SNP Firmware could lead to a potential loss of guest confidentiality.

  • CVE-2021-26312MedNov 16, 2021
    risk 0.36cvss 5.5epss 0.00

    Failure to flush the Translation Lookaside Buffer (TLB) of the I/O memory management unit (IOMMU) may lead an IO device to write to memory it should not be able to access, resulting in a potential loss of integrity.

  • CVE-2020-12488MedNov 10, 2021
    risk 0.36cvss 5.5epss 0.00

    The attacker can access the sensitive information stored within the jovi Smart Scene module by entering carefully constructed commands without requesting permission.

  • CVE-2021-22454MedOct 28, 2021
    risk 0.36cvss 5.5epss 0.00

    A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause core dump.

  • CVE-2020-18972MedAug 25, 2021
    risk 0.36cvss 5.5epss 0.01

    Exposure of Sensitive Information to an Unauthorized Actor in PoDoFo v0.9.6 allows attackers to obtain sensitive information via 'IsNextToken' in the component 'src/base/PdfToenizer.cpp'.

  • CVE-2021-30921MedAug 24, 2021
    risk 0.36cvss 5.5epss 0.00

    A logic issue was addressed with improved state management. This issue is fixed in iOS 14.5 and iPadOS 14.5. A user's password may be visible onscreen.