VYPR

CWE-668

Exposure of Resource to Wrong Sphere

ClassDraft

Description

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

Hierarchy (View 1000)

CVEs mapped to this weakness (784)

page 37 of 40
  • CVE-2024-42350LowAug 5, 2024
    risk 0.13cvss 3.0epss 0.00

    Biscuit is an authorization token with decentralized verification, offline attenuation and strong security policy enforcement based on a logic language. Third-party blocks can be generated without transferring the whole token to the third-party authority. Instead, a…

  • CVE-2022-33700LowJul 12, 2022
    risk 0.13cvss 2.0epss 0.00

    Exposure of Sensitive Information in putDsaSimImsi in TelephonyUI prior to SMR Jul-2022 Release 1 allows local attacker to access imsi via log.

  • CVE-2022-33699LowJul 12, 2022
    risk 0.13cvss 2.0epss 0.00

    Exposure of Sensitive Information in getDsaSimImsi in TelephonyUI prior to SMR Jul-2022 Release 1 allows local attacker to access imsi via log.

  • CVE-2020-36319LowApr 23, 2021
    risk 0.13cvss 3.1epss 0.01

    Insecure configuration of default ObjectMapper in com.vaadin:flow-server versions 3.0.0 through 3.0.5 (Vaadin 15.0.0 through 15.0.4) may expose sensitive data if the application also uses e.g. @RestController

  • CVE-2022-26329LowJan 26, 2023
    risk 0.12cvss 1.8epss 0.00

    File existence disclosure vulnerability in NetIQ Identity Manager plugin prior to version 4.8.5 allows attacker to determine whether a file exists on the filesystem. This issue affects: Micro Focus NetIQ Identity Manager NetIQ Identity Manager versions prior to 4.8.5 on ALL.

  • CVE-2022-30728LowJun 7, 2022
    risk 0.12cvss 1.9epss 0.00

    Information exposure vulnerability in ScanPool prior to SMR Jun-2022 Release 1 allows local attackers to get MAC address information.

  • CVE-2022-30714LowJun 7, 2022
    risk 0.12cvss 1.9epss 0.00

    Information exposure vulnerability in SemIWCMonitor prior to SMR Jun-2022 Release 1 allows local attackers to get MAC address information.

  • CVE-2022-3952LowNov 11, 2022
    risk 0.10cvss 2.6epss 0.01

    A vulnerability has been found in ManyDesigns Portofino 5.3.2 and classified as problematic. Affected by this vulnerability is the function createTempDir of the file WarFileLauncher.java. The manipulation leads to creation of temporary file in directory with insecure…

  • CVE-2022-41874LowNov 10, 2022
    risk 0.10cvss 2.6epss 0.00

    Tauri is a framework for building binaries for all major desktop platforms. In versions prior to 1.0.7 and 1.1.2, Tauri is vulnerable to an Incorrectly-Resolved Name. Due to incorrect escaping of special characters in paths selected via the file dialog and drag and drop…

  • CVE-2024-51755LowNov 6, 2024
    risk 0.07cvss 2.2epss 0.00

    Twig is a template language for PHP. In a sandbox, an attacker can access attributes of Array-like objects as they were not checked by the security policy. They are now checked via the property policy and the `__isset()` method is now called after the security check. This is a…

  • CVE-2024-51754LowNov 6, 2024
    risk 0.07cvss 2.2epss 0.00

    Twig is a template language for PHP. In a sandbox, an attacker can call `__toString()` on an object even if the `__toString()` method is not allowed by the security policy when the object is part of an array or an argument list (arguments to a function or a filter for instance).…

  • CVE-2022-25236CriFeb 16, 2022
    risk 0.03cvss 9.8epss 0.36

    xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.

  • CVE-2024-38368CriJul 1, 2024
    risk 0.01cvss 9.3epss 0.15

    trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. A vulnerability affected older pods which migrated from the pre-2014 pull request workflow to trunk. If the pods had never been claimed then it was still possible to do so. It was also…

  • CVE-2022-24900CriApr 29, 2022
    risk 0.01cvss 9.9epss 0.08

    Piano LED Visualizer is software that allows LED lights to light up as a person plays a piano connected to a computer. Version 1.3 and prior are vulnerable to a path traversal attack. The `os.path.join` call is unsafe for use with untrusted input. When the `os.path.join` call…

  • CVE-2018-8040MedAug 29, 2018
    risk 0.01cvss 5.3epss 0.07

    Pages that are rendered using the ESI plugin can have access to the cookie header when the plugin is configured not to allow access. This affects Apache Traffic Server (ATS) versions 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x should upgrade to…

  • CVE-2011-1960Aug 10, 2011
    risk 0.01cvss epss 0.18

    Microsoft Internet Explorer 6 through 9 does not properly implement JavaScript event handlers, which allows remote attackers to access content from a different (1) domain or (2) zone via unspecified script code, aka "Event Handlers Information Disclosure Vulnerability."

  • CVE-2011-1258Jun 16, 2011
    risk 0.01cvss epss 0.15

    Microsoft Internet Explorer 6 through 8 does not properly restrict web script, which allows user-assisted remote attackers to obtain sensitive information from a different (1) domain or (2) zone via vectors involving a drag-and-drop operation, aka "Drag and Drop Information…

  • CVE-2026-14960CriJul 15, 2026
    risk 0.00cvss 9.8epss 0.00

    Pegatron `Tdelo64.sys` improperly exposes privileged hardware access functionality through the `\\.\TdeIo` device interface. IOCTL handlers including `TDE_IOCTL_INDEXIO_READ` and `TDE_IOCTL_INDEXIO_WRITE` permit unprivileged user-mode callers to perform arbitrary hardware I/O…

  • CVE-2026-59835HigJul 14, 2026
    risk 0.00cvss 8.6epss 0.00

    A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via network requests.

  • CVE-2026-53648MedJul 7, 2026
    risk 0.00cvss epss 0.00

    FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.1, downloadable product files are stored using a deterministic filename-derived path. When an administrator uploads a file for a downloadable product, FOSSBilling stores the file as…