CWE-668
Exposure of Resource to Wrong Sphere
Description
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Hierarchy (View 1000)
CVEs mapped to this weakness (784)
page 24 of 40| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-23394 | Med | 0.36 | 5.5 | 0.00 | Mar 14, 2023 | Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability | ||
| CVE-2023-23501 | Med | 0.36 | 5.5 | 0.00 | Feb 27, 2023 | The issue was addressed with improved memory handling This issue is fixed in macOS Ventura 13.2. An app may be able to disclose kernel memory. | ||
| CVE-2023-21714 | Med | 0.36 | 5.5 | 0.01 | Feb 14, 2023 | Microsoft Office Information Disclosure Vulnerability | ||
| CVE-2023-21687 | Med | 0.36 | 5.5 | 0.00 | Feb 14, 2023 | HTTP.sys Information Disclosure Vulnerability | ||
| CVE-2023-21445 | Med | 0.36 | 5.5 | 0.00 | Feb 9, 2023 | Improper access control vulnerability in MyFiles prior to versions 12.2.09 in Android R(11), 13.1.03.501 in Android S(12) and 14.1.00.422 in Android T(13) allows local attacker to write file with MyFiles privilege via implicit intent. | ||
| CVE-2021-26343 | Med | 0.36 | 5.5 | 0.00 | Jan 11, 2023 | Insufficient validation in ASP BIOS and DRTM commands may allow malicious supervisor x86 software to disclose the contents of sensitive memory which may result in information disclosure. | ||
| CVE-2022-2882 | Med | 0.36 | 5.5 | 0.01 | Oct 28, 2022 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. A malicious maintainer could exfiltrate a GitHub integration's access token by… | ||
| CVE-2021-0734 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2022 | In Settings, there is a possible way to determine whether an app is installed without query permissions, due to side channel information disclosure. This could lead to local information disclosure of an installed package, without proper query permissions, with no additional… | ||
| CVE-2022-34765 | Med | 0.36 | 5.5 | 0.01 | Jul 13, 2022 | A CWE-73: External Control of File Name or Path vulnerability exists that could cause loading of unauthorized firmware images when user-controlled data is written to the file path. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V2.01 and later), OPC UA… | ||
| CVE-2022-30732 | Med | 0.36 | 5.5 | 0.01 | Jun 7, 2022 | Exposure of Sensitive Information vulnerability in Samsung Account prior to version 13.2.00.6 allows attacker to access sensitive information via onActivityResult. | ||
| CVE-2021-39777 | Med | 0.36 | 5.5 | 0.00 | Mar 30, 2022 | In Telephony, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2021-33096 | Med | 0.36 | 5.5 | 0.00 | Feb 9, 2022 | Improper isolation of shared resources in network on chip for the Intel(R) 82599 Ethernet Controllers and Adapters may allow an authenticated user to potentially enable denial of service via local access. | ||
| CVE-2022-21964 | Med | 0.36 | 5.5 | 0.01 | Jan 11, 2022 | Remote Desktop Licensing Diagnoser Information Disclosure Vulnerability | ||
| CVE-2019-8702 | Med | 0.36 | 5.5 | 0.00 | Dec 23, 2021 | This issue was addressed with a new entitlement. This issue is fixed in macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra, iOS 12.4, tvOS 12.4. A local user may be able to read a persistent account identifier. | ||
| CVE-2021-26327 | Med | 0.36 | 5.5 | 0.00 | Nov 16, 2021 | Insufficient validation of guest context in the SNP Firmware could lead to a potential loss of guest confidentiality. | ||
| CVE-2021-26312 | Med | 0.36 | 5.5 | 0.00 | Nov 16, 2021 | Failure to flush the Translation Lookaside Buffer (TLB) of the I/O memory management unit (IOMMU) may lead an IO device to write to memory it should not be able to access, resulting in a potential loss of integrity. | ||
| CVE-2020-12488 | Med | 0.36 | 5.5 | 0.00 | Nov 10, 2021 | The attacker can access the sensitive information stored within the jovi Smart Scene module by entering carefully constructed commands without requesting permission. | ||
| CVE-2021-22454 | Med | 0.36 | 5.5 | 0.00 | Oct 28, 2021 | A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause core dump. | ||
| CVE-2020-18972 | Med | 0.36 | 5.5 | 0.01 | Aug 25, 2021 | Exposure of Sensitive Information to an Unauthorized Actor in PoDoFo v0.9.6 allows attackers to obtain sensitive information via 'IsNextToken' in the component 'src/base/PdfToenizer.cpp'. | ||
| CVE-2021-30921 | Med | 0.36 | 5.5 | 0.00 | Aug 24, 2021 | A logic issue was addressed with improved state management. This issue is fixed in iOS 14.5 and iPadOS 14.5. A user's password may be visible onscreen. |
- risk 0.36cvss 5.5epss 0.00
Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.00
The issue was addressed with improved memory handling This issue is fixed in macOS Ventura 13.2. An app may be able to disclose kernel memory.
- risk 0.36cvss 5.5epss 0.01
Microsoft Office Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.00
HTTP.sys Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.00
Improper access control vulnerability in MyFiles prior to versions 12.2.09 in Android R(11), 13.1.03.501 in Android S(12) and 14.1.00.422 in Android T(13) allows local attacker to write file with MyFiles privilege via implicit intent.
- risk 0.36cvss 5.5epss 0.00
Insufficient validation in ASP BIOS and DRTM commands may allow malicious supervisor x86 software to disclose the contents of sensitive memory which may result in information disclosure.
- risk 0.36cvss 5.5epss 0.01
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. A malicious maintainer could exfiltrate a GitHub integration's access token by…
- risk 0.36cvss 5.5epss 0.00
In Settings, there is a possible way to determine whether an app is installed without query permissions, due to side channel information disclosure. This could lead to local information disclosure of an installed package, without proper query permissions, with no additional…
- risk 0.36cvss 5.5epss 0.01
A CWE-73: External Control of File Name or Path vulnerability exists that could cause loading of unauthorized firmware images when user-controlled data is written to the file path. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V2.01 and later), OPC UA…
- risk 0.36cvss 5.5epss 0.01
Exposure of Sensitive Information vulnerability in Samsung Account prior to version 13.2.00.6 allows attacker to access sensitive information via onActivityResult.
- risk 0.36cvss 5.5epss 0.00
In Telephony, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for…
- risk 0.36cvss 5.5epss 0.00
Improper isolation of shared resources in network on chip for the Intel(R) 82599 Ethernet Controllers and Adapters may allow an authenticated user to potentially enable denial of service via local access.
- risk 0.36cvss 5.5epss 0.01
Remote Desktop Licensing Diagnoser Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.00
This issue was addressed with a new entitlement. This issue is fixed in macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra, iOS 12.4, tvOS 12.4. A local user may be able to read a persistent account identifier.
- risk 0.36cvss 5.5epss 0.00
Insufficient validation of guest context in the SNP Firmware could lead to a potential loss of guest confidentiality.
- risk 0.36cvss 5.5epss 0.00
Failure to flush the Translation Lookaside Buffer (TLB) of the I/O memory management unit (IOMMU) may lead an IO device to write to memory it should not be able to access, resulting in a potential loss of integrity.
- risk 0.36cvss 5.5epss 0.00
The attacker can access the sensitive information stored within the jovi Smart Scene module by entering carefully constructed commands without requesting permission.
- risk 0.36cvss 5.5epss 0.00
A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause core dump.
- risk 0.36cvss 5.5epss 0.01
Exposure of Sensitive Information to an Unauthorized Actor in PoDoFo v0.9.6 allows attackers to obtain sensitive information via 'IsNextToken' in the component 'src/base/PdfToenizer.cpp'.
- risk 0.36cvss 5.5epss 0.00
A logic issue was addressed with improved state management. This issue is fixed in iOS 14.5 and iPadOS 14.5. A user's password may be visible onscreen.