CWE-668
Exposure of Resource to Wrong Sphere
Description
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Hierarchy (View 1000)
CVEs mapped to this weakness (796)
page 37 of 40| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-68467 | Low | 0.15 | 3.4 | 0.00 | Mar 4, 2026 | Dark Reader is an accessibility browser extension that makes web pages colors dark. The dynamic dark mode feature of the extension works by analyzing the colors of web pages found in CSS style sheet files. In order to analyze cross-origin style sheets (stored on websites… | ||
| CVE-2023-35013 | Low | 0.15 | 2.3 | 0.00 | Oct 16, 2023 | IBM Security Verify Governance 10.0, Identity Manager could allow a local privileged user to obtain sensitive information from source code. IBM X-Force ID: 257769. | ||
| CVE-2026-6830 | Low | 0.14 | 3.3 | 0.00 | Apr 21, 2026 | nesquena hermes-webui contains an environment variable leakage vulnerability where profile switching does not clear environment variables from the previously active profile before loading the next profile. Attackers or users can exploit additive dotenv reload behavior to access… | ||
| CVE-2023-5545 | Low | 0.14 | 3.3 | 0.01 | Nov 9, 2023 | H5P metadata automatically populated the author with the user's username, which could be sensitive information. | ||
| CVE-2023-5542 | Low | 0.14 | 3.3 | 0.00 | Nov 9, 2023 | Students in "Only see own membership" groups could see other students in the group, which should be hidden. | ||
| CVE-2023-0481 | Low | 0.14 | 3.3 | 0.00 | Feb 24, 2023 | In RestEasy Reactive implementation of Quarkus the insecure File.createTempFile() is used in the FileBodyHandler class which creates temp files with insecure permissions that could be read by a local user. | ||
| CVE-2023-21438 | Low | 0.14 | 2.1 | 0.00 | Feb 9, 2023 | Improper logic in HomeScreen prior to SMR Feb-2023 Release 1 allows physical attacker to access App preview protected by Secure Folder. | ||
| CVE-2022-41954 | Low | 0.14 | 3.3 | 0.00 | Nov 25, 2022 | MPXJ is an open source library to read and write project plans from a variety of file formats and databases. On Unix-like operating systems (not Windows or macos), MPXJ's use of `File.createTempFile(..)` results in temporary files being created with the permissions `-rw-r--r--`.… | ||
| CVE-2022-29247 | Low | 0.14 | 2.2 | 0.01 | Jun 13, 2022 | Electron is a framework for writing cross-platform desktop applications using JavaScript (JS), HTML, and CSS. A vulnerability in versions prior to 18.0.0-beta.6, 17.2.0, 16.2.6, and 15.5.5 allows a renderer with JS execution to obtain access to a new renderer process with… | ||
| CVE-2022-28794 | Low | 0.14 | 2.2 | 0.00 | Jun 7, 2022 | Sensitive information exposure in low-battery dumpstate log prior to SMR Jun-2022 Release 1 allows local attackers to get SIM card information. | ||
| CVE-2017-8418 | Low | 0.14 | 3.3 | 0.00 | May 2, 2017 | RuboCop 0.48.1 and earlier does not use /tmp in safe way, allowing local users to exploit this to tamper with cache files belonging to other users. | ||
| CVE-2024-42350 | Low | 0.13 | 3.0 | 0.00 | Aug 5, 2024 | Biscuit is an authorization token with decentralized verification, offline attenuation and strong security policy enforcement based on a logic language. Third-party blocks can be generated without transferring the whole token to the third-party authority. Instead, a… | ||
| CVE-2022-33700 | Low | 0.13 | 2.0 | 0.00 | Jul 12, 2022 | Exposure of Sensitive Information in putDsaSimImsi in TelephonyUI prior to SMR Jul-2022 Release 1 allows local attacker to access imsi via log. | ||
| CVE-2022-33699 | Low | 0.13 | 2.0 | 0.00 | Jul 12, 2022 | Exposure of Sensitive Information in getDsaSimImsi in TelephonyUI prior to SMR Jul-2022 Release 1 allows local attacker to access imsi via log. | ||
| CVE-2020-36319 | Low | 0.13 | 3.1 | 0.01 | Apr 23, 2021 | Insecure configuration of default ObjectMapper in com.vaadin:flow-server versions 3.0.0 through 3.0.5 (Vaadin 15.0.0 through 15.0.4) may expose sensitive data if the application also uses e.g. @RestController | ||
| CVE-2022-26329 | Low | 0.12 | 1.8 | 0.00 | Jan 26, 2023 | File existence disclosure vulnerability in NetIQ Identity Manager plugin prior to version 4.8.5 allows attacker to determine whether a file exists on the filesystem. This issue affects: Micro Focus NetIQ Identity Manager NetIQ Identity Manager versions prior to 4.8.5 on ALL. | ||
| CVE-2022-30728 | Low | 0.12 | 1.9 | 0.00 | Jun 7, 2022 | Information exposure vulnerability in ScanPool prior to SMR Jun-2022 Release 1 allows local attackers to get MAC address information. | ||
| CVE-2022-30714 | Low | 0.12 | 1.9 | 0.00 | Jun 7, 2022 | Information exposure vulnerability in SemIWCMonitor prior to SMR Jun-2022 Release 1 allows local attackers to get MAC address information. | ||
| CVE-2022-3952 | Low | 0.10 | 2.6 | 0.01 | Nov 11, 2022 | A vulnerability has been found in ManyDesigns Portofino 5.3.2 and classified as problematic. Affected by this vulnerability is the function createTempDir of the file WarFileLauncher.java. The manipulation leads to creation of temporary file in directory with insecure… | ||
| CVE-2022-41874 | Low | 0.10 | 2.6 | 0.00 | Nov 10, 2022 | Tauri is a framework for building binaries for all major desktop platforms. In versions prior to 1.0.7 and 1.1.2, Tauri is vulnerable to an Incorrectly-Resolved Name. Due to incorrect escaping of special characters in paths selected via the file dialog and drag and drop… |
- risk 0.15cvss 3.4epss 0.00
Dark Reader is an accessibility browser extension that makes web pages colors dark. The dynamic dark mode feature of the extension works by analyzing the colors of web pages found in CSS style sheet files. In order to analyze cross-origin style sheets (stored on websites…
- risk 0.15cvss 2.3epss 0.00
IBM Security Verify Governance 10.0, Identity Manager could allow a local privileged user to obtain sensitive information from source code. IBM X-Force ID: 257769.
- risk 0.14cvss 3.3epss 0.00
nesquena hermes-webui contains an environment variable leakage vulnerability where profile switching does not clear environment variables from the previously active profile before loading the next profile. Attackers or users can exploit additive dotenv reload behavior to access…
- risk 0.14cvss 3.3epss 0.01
H5P metadata automatically populated the author with the user's username, which could be sensitive information.
- risk 0.14cvss 3.3epss 0.00
Students in "Only see own membership" groups could see other students in the group, which should be hidden.
- risk 0.14cvss 3.3epss 0.00
In RestEasy Reactive implementation of Quarkus the insecure File.createTempFile() is used in the FileBodyHandler class which creates temp files with insecure permissions that could be read by a local user.
- risk 0.14cvss 2.1epss 0.00
Improper logic in HomeScreen prior to SMR Feb-2023 Release 1 allows physical attacker to access App preview protected by Secure Folder.
- risk 0.14cvss 3.3epss 0.00
MPXJ is an open source library to read and write project plans from a variety of file formats and databases. On Unix-like operating systems (not Windows or macos), MPXJ's use of `File.createTempFile(..)` results in temporary files being created with the permissions `-rw-r--r--`.…
- risk 0.14cvss 2.2epss 0.01
Electron is a framework for writing cross-platform desktop applications using JavaScript (JS), HTML, and CSS. A vulnerability in versions prior to 18.0.0-beta.6, 17.2.0, 16.2.6, and 15.5.5 allows a renderer with JS execution to obtain access to a new renderer process with…
- risk 0.14cvss 2.2epss 0.00
Sensitive information exposure in low-battery dumpstate log prior to SMR Jun-2022 Release 1 allows local attackers to get SIM card information.
- risk 0.14cvss 3.3epss 0.00
RuboCop 0.48.1 and earlier does not use /tmp in safe way, allowing local users to exploit this to tamper with cache files belonging to other users.
- risk 0.13cvss 3.0epss 0.00
Biscuit is an authorization token with decentralized verification, offline attenuation and strong security policy enforcement based on a logic language. Third-party blocks can be generated without transferring the whole token to the third-party authority. Instead, a…
- risk 0.13cvss 2.0epss 0.00
Exposure of Sensitive Information in putDsaSimImsi in TelephonyUI prior to SMR Jul-2022 Release 1 allows local attacker to access imsi via log.
- risk 0.13cvss 2.0epss 0.00
Exposure of Sensitive Information in getDsaSimImsi in TelephonyUI prior to SMR Jul-2022 Release 1 allows local attacker to access imsi via log.
- risk 0.13cvss 3.1epss 0.01
Insecure configuration of default ObjectMapper in com.vaadin:flow-server versions 3.0.0 through 3.0.5 (Vaadin 15.0.0 through 15.0.4) may expose sensitive data if the application also uses e.g. @RestController
- risk 0.12cvss 1.8epss 0.00
File existence disclosure vulnerability in NetIQ Identity Manager plugin prior to version 4.8.5 allows attacker to determine whether a file exists on the filesystem. This issue affects: Micro Focus NetIQ Identity Manager NetIQ Identity Manager versions prior to 4.8.5 on ALL.
- risk 0.12cvss 1.9epss 0.00
Information exposure vulnerability in ScanPool prior to SMR Jun-2022 Release 1 allows local attackers to get MAC address information.
- risk 0.12cvss 1.9epss 0.00
Information exposure vulnerability in SemIWCMonitor prior to SMR Jun-2022 Release 1 allows local attackers to get MAC address information.
- risk 0.10cvss 2.6epss 0.01
A vulnerability has been found in ManyDesigns Portofino 5.3.2 and classified as problematic. Affected by this vulnerability is the function createTempDir of the file WarFileLauncher.java. The manipulation leads to creation of temporary file in directory with insecure…
- risk 0.10cvss 2.6epss 0.00
Tauri is a framework for building binaries for all major desktop platforms. In versions prior to 1.0.7 and 1.1.2, Tauri is vulnerable to an Incorrectly-Resolved Name. Due to incorrect escaping of special characters in paths selected via the file dialog and drag and drop…