VYPR

CWE-668

Exposure of Resource to Wrong Sphere

ClassDraft

Description

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

Hierarchy (View 1000)

CVEs mapped to this weakness (784)

page 7 of 40
  • CVE-2025-32428CriApr 15, 2025
    risk 0.52cvss epss 0.01

    Jupyter Remote Desktop Proxy allows you to run a Linux Desktop on a JupyterHub. jupyter-remote-desktop-proxy was meant to rely on UNIX sockets readable only by the current user since version 3.0.0, but when used with TigerVNC, the VNC server started by…

  • CVE-2013-4561CriJun 30, 2022
    risk 0.52cvss 9.1epss 0.01

    In a openshift node, there is a cron job to update mcollective facts that mishandles a temporary file. This may lead to loss of confidentiality and integrity.

  • CVE-2022-27818CriApr 7, 2022
    risk 0.52cvss 9.1epss 0.02

    SWHKD 1.1.5 unsafely uses the /tmp/swhkd.sock pathname. There can be an information leak or denial of service.

  • CVE-2021-42536HigOct 22, 2021
    risk 0.52cvss 8.0epss 0.01

    The affected product is vulnerable to a disclosure of peer username and password by allowing all users access to read global variables.

  • CVE-2021-26919HigMar 30, 2021
    risk 0.52cvss 8.8epss 0.23

    Apache Druid allows users to read data from other database systems using JDBC. This functionality is to allow trusted users with the proper permissions to set up lookups or submit ingestion tasks. The MySQL JDBC driver supports certain properties, which, if left unmitigated, can…

  • CVE-2025-38670HigAug 22, 2025
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: arm64/entry: Mask DAIF in cpu_switch_to(), call_on_irq_stack() `cpu_switch_to()` and `call_on_irq_stack()` manipulate SP to change to different stacks along with the Shadow Call Stack if it is enabled. Those…

  • CVE-2023-5751HigJun 4, 2024
    risk 0.51cvss 7.8epss 0.00

    A local attacker with low privileges can read and modify any users files and cause a DoS in the working directory of the affected products due to exposure of resource to wrong sphere. 

  • CVE-2024-21813HigMay 16, 2024
    risk 0.51cvss 7.9epss 0.00

    Exposure of resource to wrong sphere in some Intel(R) DTT software installers may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-46921HigFeb 27, 2024
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: locking/qrwlock: Fix ordering in queued_write_lock_slowpath() While this code is executed with the wait_lock held, a reader can acquire the lock without holding wait_lock. The writer side loops checking the…

  • CVE-2023-38994HigOct 31, 2023
    risk 0.51cvss 7.9epss 0.00

    The 'check_univention_joinstatus' prometheus monitoring script (and other scripts) in UCS 5.0-5 revealed the LDAP plaintext password of the machine account in the process list allowing attackers with local ssh access to gain higher privileges and perform followup attacks. By…

  • CVE-2023-39250HigAug 16, 2023
    risk 0.51cvss 7.8epss 0.00

    Dell Storage Integration Tools for VMware (DSITV) and Dell Storage vSphere Client Plugin (DSVCP) versions prior to 6.1.1 and Replay Manager for VMware (RMSV) versions prior to 3.1.2 contain an information disclosure vulnerability. A local low-privileged malicious user could…

  • CVE-2023-29403HigJun 8, 2023
    risk 0.51cvss 7.8epss 0.00

    On Unix platforms, the Go runtime does not behave differently when a binary is run with the setuid/setgid bits. This can be dangerous in certain cases, such as when dumping memory state, or assuming the status of standard i/o file descriptors. If a setuid/setgid binary is…

  • CVE-2023-26243HigApr 27, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The decryption binary used to decrypt firmware files has an information leak that allows an attacker to read the AES key and initialization vector from memory. An…

  • CVE-2021-41989HigJan 26, 2023
    risk 0.51cvss 7.8epss 0.00

    Qlik QlikView through 12.60.20100.0 creates a Temporary File in a Directory with Insecure Permissions.

  • CVE-2021-41988HigJan 26, 2023
    risk 0.51cvss 7.8epss 0.00

    Qlik NPrinting Designer through 21.14.3.0 creates a Temporary File in a Directory with Insecure Permissions.

  • CVE-2023-21611HigJan 18, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Creation of Temporary File in Directory with Incorrect Permissions vulnerability that could result in privilege escalation in the context of the…

  • CVE-2022-24139HigJul 6, 2022
    risk 0.51cvss 7.8epss 0.00

    In IOBit Advanced System Care (AscService.exe) 15, an attacker with SEImpersonatePrivilege can create a named pipe with the same name as one of ASCService's named pipes. ASCService first tries to connect before trying to create the named pipes, because of that during login the…

  • CVE-2022-28226HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.00

    Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.801 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating temporary files in directory with insecure permissions during Yandex Browser update…

  • CVE-2022-24411HigApr 12, 2022
    risk 0.51cvss 7.8epss 0.00

    Dell PowerScale OneFS 8.2.2 and above contain an elevation of privilege vulnerability. A local attacker with ISI_PRIV_LOGIN_SSH and/or ISI_PRIV_LOGIN_CONSOLE could potentially exploit this vulnerability, leading to elevation of privilege. This could potentially allow users to…

  • CVE-2021-42255HigApr 12, 2022
    risk 0.51cvss 7.8epss 0.00

    AppGuard Enterprise before 6.7.100.1 creates a Temporary File in a Directory with Insecure Permissions. Local users can gain SYSTEM privileges because a repair operation relies on the %TEMP% directory of an unprivileged user.