CWE-668
Exposure of Resource to Wrong Sphere
Description
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Hierarchy (View 1000)
CVEs mapped to this weakness (784)
page 31 of 40| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-34364 | Med | 0.29 | 4.4 | 0.00 | Feb 10, 2023 | Dell BSAFE SSL-J, versions before 6.5 and version 7.0 contain a debug message revealing unnecessary information vulnerability. This may lead to disclosing sensitive information to a locally privileged user. . | ||
| CVE-2022-24913 | Med | 0.29 | 5.5 | 0.00 | Jan 12, 2023 | Versions of the package com.fasterxml.util:java-merge-sort before 1.1.0 are vulnerable to Insecure Temporary File in the StdTempFileProvider() function in StdTempFileProvider.java, which uses the permissive File.createTempFile() function, exposing temporary file contents. | ||
| CVE-2022-45935 | Med | 0.29 | 5.5 | 0.00 | Jan 6, 2023 | Usage of temporary files with insecure permissions by the Apache James server allows an attacker with local access to access private user data in transit. Vulnerable components includes the SMTP stack and IMAP APPEND command. This issue affects Apache James server version… | ||
| CVE-2022-24823 | Med | 0.29 | 5.5 | 0.01 | May 6, 2022 | Netty is an open-source, asynchronous event-driven network application framework. The package `io.netty:netty-codec-http` prior to version 4.1.77.Final contains an insufficient fix for CVE-2021-21290. When Netty's multipart decoders are used local information disclosure can… | ||
| CVE-2022-27817 | Med | 0.29 | 4.4 | 0.00 | Apr 14, 2022 | SWHKD 1.1.5 consumes the keyboard events of unintended users. This could potentially cause an information leak, but is usually a denial of functionality. | ||
| CVE-2022-26355 | Med | 0.29 | 4.4 | 0.00 | Mar 10, 2022 | Citrix Federated Authentication Service (FAS) 7.17 - 10.6 causes deployments that have been configured to store a registration authority certificate's private key in a Trusted Platform Module (TPM) to incorrectly store that key in the Microsoft Software Key Storage Provider… | ||
| CVE-2022-0762 | Med | 0.29 | 5.5 | 0.01 | Feb 26, 2022 | Incorrect Authorization in GitHub repository microweber/microweber prior to 1.3. | ||
| CVE-2021-34761 | Med | 0.29 | 4.4 | 0.00 | Oct 27, 2021 | A vulnerability in Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to overwrite or append arbitrary data to system files using root-level privileges. The attacker must have administrative credentials on the device. This vulnerability is… | ||
| CVE-2021-37704 | Med | 0.29 | 5.4 | 0.06 | Aug 12, 2021 | PhpFastCache is a high-performance backend cache system (packagist package phpfastcache/phpfastcache). In versions before 6.1.5, 7.1.2, and 8.0.7 the `phpinfo()` can be exposed if the `/vendor` is not protected from public access. This is a rare situation today since the vendor… | ||
| CVE-2021-1423 | Med | 0.29 | 4.4 | 0.00 | Mar 24, 2021 | A vulnerability in the implementation of a CLI command in Cisco Aironet Access Points (AP) could allow an authenticated, local attacker to overwrite files in the flash memory of the device. This vulnerability is due to insufficient input validation for a specific command. An… | ||
| CVE-2014-2387 | Med | 0.29 | 4.4 | 0.00 | Dec 13, 2019 | Pen 0.18.0 has Insecure Temporary File Creation vulnerabilities | ||
| CVE-2023-45357 | Med | 0.28 | 4.3 | 0.00 | Oct 17, 2023 | Archer Platform 6.x before 6.13 P2 HF2 (6.13.0.2.2) contains a sensitive information disclosure vulnerability. An authenticated attacker could potentially obtain access to sensitive information via a popup warning message. 6.14 (6.14.0) is also a fixed release. | ||
| CVE-2022-20917 | Med | 0.28 | 4.3 | 0.01 | Sep 15, 2023 | A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) message processing feature of Cisco Jabber could allow an authenticated, remote attacker to manipulate the content of XMPP messages that are used by the affected application. This vulnerability is due to… | ||
| CVE-2023-30960 | Med | 0.28 | 4.3 | 0.00 | Jul 10, 2023 | A security defect was discovered in Foundry job-tracker that enabled users to query metadata related to builds on resources they did not have access to. This defect was resolved with the release of job-tracker 4.645.0. The service was rolled out to all affected Foundry… | ||
| CVE-2023-29538 | Med | 0.28 | 4.3 | 0.00 | Jun 2, 2023 | Under specific circumstances a WebExtension may have received a jar:file:/// URI instead of a moz-extension:/// URI during a load request. This leaked directory paths on the user's machine. This vulnerability affects Firefox for Android < 112, Firefox <… | ||
| CVE-2023-25750 | Med | 0.28 | 4.3 | 0.00 | Jun 2, 2023 | Under certain circumstances, a ServiceWorker's offline cache may have leaked to the file system when using private browsing mode. This vulnerability affects Firefox < 111. | ||
| CVE-2021-30153 | Med | 0.28 | 4.3 | 0.01 | Apr 15, 2023 | An issue was discovered in the VisualEditor extension in MediaWiki before 1.31.13, and 1.32.x through 1.35.x before 1.35.2. . When using VisualEditor to edit a MediaWiki user page belonging to an existing, but hidden, user, VisualEditor will disclose that the user exists. (It… | ||
| CVE-2023-1775 | Med | 0.28 | 4.3 | 0.01 | Mar 31, 2023 | When running in a High Availability configuration, Mattermost fails to sanitize some of the user_updated and post_deleted events broadcast to all users, leading to disclosure of sensitive information to some of the users with currently connected Websocket clients. | ||
| CVE-2022-46257 | Med | 0.28 | 4.3 | 0.01 | Mar 7, 2023 | An information disclosure vulnerability was identified in GitHub Enterprise Server that allowed private repositories to be added to a GitHub Actions runner group via the API by a user who did not have access to those repositories, resulting in the repository names being shown in… | ||
| CVE-2022-38474 | Med | 0.28 | 4.3 | 0.00 | Dec 22, 2022 | A website that had permission to access the microphone could record audio without the audio notification being shown. This bug does not allow the attacker to bypass the permission prompt - it only affects the notification shown once permission has been granted.*This bug… |
- risk 0.29cvss 4.4epss 0.00
Dell BSAFE SSL-J, versions before 6.5 and version 7.0 contain a debug message revealing unnecessary information vulnerability. This may lead to disclosing sensitive information to a locally privileged user. .
- risk 0.29cvss 5.5epss 0.00
Versions of the package com.fasterxml.util:java-merge-sort before 1.1.0 are vulnerable to Insecure Temporary File in the StdTempFileProvider() function in StdTempFileProvider.java, which uses the permissive File.createTempFile() function, exposing temporary file contents.
- risk 0.29cvss 5.5epss 0.00
Usage of temporary files with insecure permissions by the Apache James server allows an attacker with local access to access private user data in transit. Vulnerable components includes the SMTP stack and IMAP APPEND command. This issue affects Apache James server version…
- risk 0.29cvss 5.5epss 0.01
Netty is an open-source, asynchronous event-driven network application framework. The package `io.netty:netty-codec-http` prior to version 4.1.77.Final contains an insufficient fix for CVE-2021-21290. When Netty's multipart decoders are used local information disclosure can…
- risk 0.29cvss 4.4epss 0.00
SWHKD 1.1.5 consumes the keyboard events of unintended users. This could potentially cause an information leak, but is usually a denial of functionality.
- risk 0.29cvss 4.4epss 0.00
Citrix Federated Authentication Service (FAS) 7.17 - 10.6 causes deployments that have been configured to store a registration authority certificate's private key in a Trusted Platform Module (TPM) to incorrectly store that key in the Microsoft Software Key Storage Provider…
- risk 0.29cvss 5.5epss 0.01
Incorrect Authorization in GitHub repository microweber/microweber prior to 1.3.
- risk 0.29cvss 4.4epss 0.00
A vulnerability in Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to overwrite or append arbitrary data to system files using root-level privileges. The attacker must have administrative credentials on the device. This vulnerability is…
- risk 0.29cvss 5.4epss 0.06
PhpFastCache is a high-performance backend cache system (packagist package phpfastcache/phpfastcache). In versions before 6.1.5, 7.1.2, and 8.0.7 the `phpinfo()` can be exposed if the `/vendor` is not protected from public access. This is a rare situation today since the vendor…
- risk 0.29cvss 4.4epss 0.00
A vulnerability in the implementation of a CLI command in Cisco Aironet Access Points (AP) could allow an authenticated, local attacker to overwrite files in the flash memory of the device. This vulnerability is due to insufficient input validation for a specific command. An…
- risk 0.29cvss 4.4epss 0.00
Pen 0.18.0 has Insecure Temporary File Creation vulnerabilities
- risk 0.28cvss 4.3epss 0.00
Archer Platform 6.x before 6.13 P2 HF2 (6.13.0.2.2) contains a sensitive information disclosure vulnerability. An authenticated attacker could potentially obtain access to sensitive information via a popup warning message. 6.14 (6.14.0) is also a fixed release.
- risk 0.28cvss 4.3epss 0.01
A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) message processing feature of Cisco Jabber could allow an authenticated, remote attacker to manipulate the content of XMPP messages that are used by the affected application. This vulnerability is due to…
- risk 0.28cvss 4.3epss 0.00
A security defect was discovered in Foundry job-tracker that enabled users to query metadata related to builds on resources they did not have access to. This defect was resolved with the release of job-tracker 4.645.0. The service was rolled out to all affected Foundry…
- risk 0.28cvss 4.3epss 0.00
Under specific circumstances a WebExtension may have received a jar:file:/// URI instead of a moz-extension:/// URI during a load request. This leaked directory paths on the user's machine. This vulnerability affects Firefox for Android < 112, Firefox <…
- risk 0.28cvss 4.3epss 0.00
Under certain circumstances, a ServiceWorker's offline cache may have leaked to the file system when using private browsing mode. This vulnerability affects Firefox < 111.
- risk 0.28cvss 4.3epss 0.01
An issue was discovered in the VisualEditor extension in MediaWiki before 1.31.13, and 1.32.x through 1.35.x before 1.35.2. . When using VisualEditor to edit a MediaWiki user page belonging to an existing, but hidden, user, VisualEditor will disclose that the user exists. (It…
- risk 0.28cvss 4.3epss 0.01
When running in a High Availability configuration, Mattermost fails to sanitize some of the user_updated and post_deleted events broadcast to all users, leading to disclosure of sensitive information to some of the users with currently connected Websocket clients.
- risk 0.28cvss 4.3epss 0.01
An information disclosure vulnerability was identified in GitHub Enterprise Server that allowed private repositories to be added to a GitHub Actions runner group via the API by a user who did not have access to those repositories, resulting in the repository names being shown in…
- risk 0.28cvss 4.3epss 0.00
A website that had permission to access the microphone could record audio without the audio notification being shown. This bug does not allow the attacker to bypass the permission prompt - it only affects the notification shown once permission has been granted.*This bug…