VYPR

CWE-668

Exposure of Resource to Wrong Sphere

ClassDraft

Description

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

Hierarchy (View 1000)

CVEs mapped to this weakness (796)

page 25 of 40
  • CVE-2020-12488MedNov 10, 2021
    risk 0.36cvss 5.5epss 0.00

    The attacker can access the sensitive information stored within the jovi Smart Scene module by entering carefully constructed commands without requesting permission.

  • CVE-2021-22454MedOct 28, 2021
    risk 0.36cvss 5.5epss 0.00

    A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause core dump.

  • CVE-2020-18972MedAug 25, 2021
    risk 0.36cvss 5.5epss 0.01

    Exposure of Sensitive Information to an Unauthorized Actor in PoDoFo v0.9.6 allows attackers to obtain sensitive information via 'IsNextToken' in the component 'src/base/PdfToenizer.cpp'.

  • CVE-2021-30921MedAug 24, 2021
    risk 0.36cvss 5.5epss 0.00

    A logic issue was addressed with improved state management. This issue is fixed in iOS 14.5 and iPadOS 14.5. A user's password may be visible onscreen.

  • CVE-2021-0588MedJul 14, 2021
    risk 0.36cvss 5.5epss 0.00

    In processInboundMessage of MceStateMachine.java, there is a possible SMS disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-28623MedJun 28, 2021
    risk 0.36cvss 5.5epss 0.00

    Adobe Premiere Elements version 5.2 (and earlier) is affected by an insecure temporary file creation vulnerability. An unauthenticated attacker could leverage this vulnerability to call functions against the installer to perform high privileged actions. Exploitation of this…

  • CVE-2021-28597MedJun 28, 2021
    risk 0.36cvss 5.5epss 0.00

    Adobe Photoshop Elements version 5.2 (and earlier) is affected by an insecure temporary file creation vulnerability. An unauthenticated attacker could leverage this vulnerability to call functions against the installer to perform high privileged actions. Exploitation of this…

  • CVE-2021-0542MedJun 22, 2021
    risk 0.36cvss 5.5epss 0.00

    In updateNotification of BeamTransferManager.java, there is a missing permission check. This could lead to local information disclosure of paired Bluetooth addresses with no additional execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2019-9475MedJun 11, 2021
    risk 0.36cvss 5.5epss 0.00

    In /proc/net of the kernel filesystem, there is a possible information leak due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2008-2544MedMay 27, 2021
    risk 0.36cvss 5.5epss 0.00

    Mounting /proc filesystem via chroot command silently mounts it in read-write mode. The user could bypass the chroot environment and gain write access to files, he would never have otherwise.

  • CVE-2021-1438MedMay 6, 2021
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in Cisco Wide Area Application Services (WAAS) Software could allow an authenticated, local attacker to gain access to sensitive information on an affected device. The vulnerability is due to improper input validation and authorization of specific commands that a…

  • CVE-2021-25357MedApr 9, 2021
    risk 0.36cvss 5.6epss 0.00

    A pendingIntent hijacking vulnerability in Create Movie prior to SMR APR-2021 Release 1 in Android O(8.x) and P(9.0), 3.4.81.1 in Android Q(10,0), and 3.6.80.7 in Android R(11.0) allows unprivileged applications to access contact information.

  • CVE-2021-25352MedMar 25, 2021
    risk 0.36cvss 5.5epss 0.00

    Using PendingIntent with implicit intent in Bixby Voice prior to version 3.0.52.14 allows attackers to execute privileged action by hijacking and modifying the intent.

  • CVE-2020-8698MedNov 12, 2020
    risk 0.36cvss 5.5epss 0.01

    Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2020-15215MedOct 6, 2020
    risk 0.36cvss 5.6epss 0.01

    Electron before versions 11.0.0-beta.6, 10.1.2, 9.3.1 or 8.5.2 is vulnerable to a context isolation bypass. Apps using both `contextIsolation` and `sandbox: true` are affected. Apps using both `contextIsolation` and `nodeIntegrationInSubFrames: true` are affected. This is a…

  • CVE-2019-14905MedMar 31, 2020
    risk 0.36cvss 5.6epss 0.01

    A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename…

  • CVE-2013-0163MedDec 5, 2019
    risk 0.36cvss 5.5epss 0.00

    OpenShift haproxy cartridge: predictable /tmp in set-proxy connection hook which could facilitate DoS

  • CVE-2013-4280MedNov 4, 2019
    risk 0.36cvss 5.5epss 0.00

    Insecure temporary file vulnerability in RedHat vsdm 4.9.6.

  • CVE-2005-2351MedNov 1, 2019
    risk 0.36cvss 5.5epss 0.00

    Mutt before 1.5.20 patch 7 allows an attacker to cause a denial of service via a series of requests to mutt temporary files.

  • CVE-2019-12660MedSep 25, 2019
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to write values to the underlying memory of an affected device. The vulnerability is due to improper input validation and authorization of specific commands that a user can execute…