VYPR

CWE-668

Exposure of Resource to Wrong Sphere

ClassDraft

Description

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

Hierarchy (View 1000)

CVEs mapped to this weakness (784)

page 25 of 40
  • CVE-2021-0588MedJul 14, 2021
    risk 0.36cvss 5.5epss 0.00

    In processInboundMessage of MceStateMachine.java, there is a possible SMS disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-28623MedJun 28, 2021
    risk 0.36cvss 5.5epss 0.00

    Adobe Premiere Elements version 5.2 (and earlier) is affected by an insecure temporary file creation vulnerability. An unauthenticated attacker could leverage this vulnerability to call functions against the installer to perform high privileged actions. Exploitation of this…

  • CVE-2021-28597MedJun 28, 2021
    risk 0.36cvss 5.5epss 0.00

    Adobe Photoshop Elements version 5.2 (and earlier) is affected by an insecure temporary file creation vulnerability. An unauthenticated attacker could leverage this vulnerability to call functions against the installer to perform high privileged actions. Exploitation of this…

  • CVE-2021-0542MedJun 22, 2021
    risk 0.36cvss 5.5epss 0.00

    In updateNotification of BeamTransferManager.java, there is a missing permission check. This could lead to local information disclosure of paired Bluetooth addresses with no additional execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2019-9475MedJun 11, 2021
    risk 0.36cvss 5.5epss 0.00

    In /proc/net of the kernel filesystem, there is a possible information leak due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2008-2544MedMay 27, 2021
    risk 0.36cvss 5.5epss 0.00

    Mounting /proc filesystem via chroot command silently mounts it in read-write mode. The user could bypass the chroot environment and gain write access to files, he would never have otherwise.

  • CVE-2021-1438MedMay 6, 2021
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in Cisco Wide Area Application Services (WAAS) Software could allow an authenticated, local attacker to gain access to sensitive information on an affected device. The vulnerability is due to improper input validation and authorization of specific commands that a…

  • CVE-2021-25357MedApr 9, 2021
    risk 0.36cvss 5.6epss 0.00

    A pendingIntent hijacking vulnerability in Create Movie prior to SMR APR-2021 Release 1 in Android O(8.x) and P(9.0), 3.4.81.1 in Android Q(10,0), and 3.6.80.7 in Android R(11.0) allows unprivileged applications to access contact information.

  • CVE-2021-25352MedMar 25, 2021
    risk 0.36cvss 5.5epss 0.00

    Using PendingIntent with implicit intent in Bixby Voice prior to version 3.0.52.14 allows attackers to execute privileged action by hijacking and modifying the intent.

  • CVE-2020-8698MedNov 12, 2020
    risk 0.36cvss 5.5epss 0.01

    Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2020-15215MedOct 6, 2020
    risk 0.36cvss 5.6epss 0.01

    Electron before versions 11.0.0-beta.6, 10.1.2, 9.3.1 or 8.5.2 is vulnerable to a context isolation bypass. Apps using both `contextIsolation` and `sandbox: true` are affected. Apps using both `contextIsolation` and `nodeIntegrationInSubFrames: true` are affected. This is a…

  • CVE-2019-14905MedMar 31, 2020
    risk 0.36cvss 5.6epss 0.01

    A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename…

  • CVE-2013-0163MedDec 5, 2019
    risk 0.36cvss 5.5epss 0.00

    OpenShift haproxy cartridge: predictable /tmp in set-proxy connection hook which could facilitate DoS

  • CVE-2013-4280MedNov 4, 2019
    risk 0.36cvss 5.5epss 0.00

    Insecure temporary file vulnerability in RedHat vsdm 4.9.6.

  • CVE-2005-2351MedNov 1, 2019
    risk 0.36cvss 5.5epss 0.00

    Mutt before 1.5.20 patch 7 allows an attacker to cause a denial of service via a series of requests to mutt temporary files.

  • CVE-2019-12660MedSep 25, 2019
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to write values to the underlying memory of an affected device. The vulnerability is due to improper input validation and authorization of specific commands that a user can execute…

  • CVE-2018-20947MedAug 1, 2019
    risk 0.36cvss 5.5epss 0.00

    cPanel before 68.0.27 allows certain file-write operations via the telnetcrt script (SEC-356).

  • CVE-2019-3970MedJul 17, 2019
    risk 0.36cvss 5.5epss 0.00

    Comodo Antivirus versions up to 12.0.0.6810 are vulnerable to Arbitrary File Write due to Cavwp.exe handling of Comodo's Antivirus database. Cavwp.exe loads Comodo antivirus definition database in unsecured global section objects, allowing a local low privileged process to…

  • CVE-2018-7073MedAug 6, 2018
    risk 0.36cvss 5.5epss 0.01

    A local arbitrary file modification vulnerability was identified in HPE Moonshot Provisioning Manager prior to v1.24.

  • CVE-2017-17087MedDec 1, 2017
    risk 0.36cvss 5.5epss 0.00

    fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group ownership of the original file), which allows local users to obtain sensitive information by leveraging an applicable group membership,…