VYPR

CWE-668

Exposure of Resource to Wrong Sphere

ClassDraft

Description

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

Hierarchy (View 1000)

CVEs mapped to this weakness (784)

page 8 of 40
  • CVE-2022-24986HigFeb 26, 2022
    risk 0.51cvss 7.8epss 0.00

    KDE KCron through 21.12.2 uses a temporary file in /tmp when saving, but reuses the filename during an editing session. Thus, someone watching it be created the first time could potentially intercept the file the following time, enabling that person to run unauthorized commands.

  • CVE-2021-42714HigFeb 15, 2022
    risk 0.51cvss 7.8epss 0.00

    Splashtop Remote Client (Business Edition) through 3.4.8.3 creates a Temporary File in a Directory with Insecure Permissions.

  • CVE-2021-42713HigFeb 15, 2022
    risk 0.51cvss 7.8epss 0.00

    Splashtop Remote Client (Personal Edition) through 3.4.6.1 creates a Temporary File in a Directory with Insecure Permissions.

  • CVE-2021-42712HigFeb 15, 2022
    risk 0.51cvss 7.8epss 0.00

    Splashtop Streamer through 3.4.8.3 creates a Temporary File in a Directory with Insecure Permissions.

  • CVE-2021-44049HigJan 15, 2022
    risk 0.51cvss 7.8epss 0.00

    CyberArk Endpoint Privilege Manager (EPM) through 11.5.3.328 before 2021-12-20 allows a local user to gain elevated privileges via a Trojan horse Procmon64.exe in the user's Temp directory.

  • CVE-2021-42254HigNov 19, 2021
    risk 0.51cvss 7.8epss 0.00

    BeyondTrust Privilege Management prior to version 21.6 creates a Temporary File in a Directory with Insecure Permissions.

  • CVE-2021-22385HigAug 10, 2021
    risk 0.51cvss 7.8epss 0.00

    A component of the Huawei smartphone has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause Kernel Code Execution.

  • CVE-2021-22420HigAug 3, 2021
    risk 0.51cvss 7.8epss 0.00

    A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause the underlying trust of the application trustlist mechanism is missing..

  • CVE-2021-33669HigJun 9, 2021
    risk 0.51cvss 7.8epss 0.00

    Under certain conditions, SAP Mobile SDK Certificate Provider allows a local unprivileged attacker to exploit an insecure temporary file storage. For a successful exploitation user interaction from another user is required and could lead to complete impact of confidentiality…

  • CVE-2021-31154HigMay 27, 2021
    risk 0.51cvss 7.8epss 0.00

    pleaseedit in please before 0.4 uses predictable temporary filenames in /tmp and the target directory. This allows a local attacker to gain full root privileges by staging a symlink attack.

  • CVE-2021-25314HigApr 14, 2021
    risk 0.51cvss 7.8epss 0.00

    A Creation of Temporary File With Insecure Permissions vulnerability in hawk2 of SUSE Linux Enterprise High Availability 12-SP3, SUSE Linux Enterprise High Availability 12-SP5, SUSE Linux Enterprise High Availability 15-SP2 allows local attackers to escalate to root. This issue…

  • CVE-2019-5159HigMar 11, 2020
    risk 0.51cvss 7.8epss 0.02

    An exploitable improper input validation vulnerability exists in the firmware update functionality of WAGO e!COCKPIT automation software v1.6.0.7. A specially crafted firmware update file can allow an attacker to write arbitrary files to arbitrary locations on WAGO controllers…

  • CVE-2014-0023HigNov 15, 2019
    risk 0.51cvss 7.8epss 0.00

    OpenShift: Install script has temporary file creation vulnerability which can result in arbitrary code execution

  • CVE-2019-15350HigNov 14, 2019
    risk 0.51cvss 7.8epss 0.00

    The Tecno Camon Android device with a build fingerprint of TECNO/H622/TECNO-ID5b:8.1.0/O11019/G-180829V31:user/release-keys contains a pre-installed platform app with a package name of com.lovelyfont.defcontainer (versionCode=7, versionName=7.0.11). This app contains an exported…

  • CVE-2019-15349HigNov 14, 2019
    risk 0.51cvss 7.8epss 0.00

    The Tecno Camon Android device with a build fingerprint of TECNO/H612/TECNO-ID5a:8.1.0/O11019/F-180828V106:user/release-keys contains a pre-installed platform app with a package name of com.lovelyfont.defcontainer (versionCode=7, versionName=7.0.11). This app contains an…

  • CVE-2019-15346HigNov 14, 2019
    risk 0.51cvss 7.8epss 0.00

    The Tecno Camon iClick 2 Android device with a build fingerprint of TECNO/H622/TECNO-ID6:8.1.0/O11019/F-180824V116:user/release-keys contains a pre-installed platform app with a package name of com.lovelyfont.defcontainer (versionCode=7, versionName=7.0.11). This app contains an…

  • CVE-2019-15345HigNov 14, 2019
    risk 0.51cvss 7.8epss 0.00

    The Tecno Camon iClick Android device with a build fingerprint of TECNO/H633/TECNO-IN6:8.1.0/O11019/A-180409V96:user/release-keys contains a pre-installed platform app with a package name of com.lovelyfont.defcontainer (versionCode=7, versionName=7.0.8). This app contains an…

  • CVE-2019-15341HigNov 14, 2019
    risk 0.51cvss 7.8epss 0.00

    The Tecno Camon iAir 2 Plus Android device with a build fingerprint of TECNO/H622/TECNO-ID3k:8.1.0/O11019/E-180914V83:user/release-keys contains a pre-installed platform app with a package name of com.lovelyfont.defcontainer (versionCode=7, versionName=7.0.11). This app contains…

  • CVE-2018-4048HigMay 30, 2019
    risk 0.51cvss 7.8epss 0.01

    An exploitable local privilege elevation vulnerability exists in the file system permissions of the `Temp` directory in GOG Galaxy 1.2.48.36 (Windows 64-bit Installer). An attacker can overwrite executables of the Desktop Galaxy Updater to exploit this vulnerability and execute…

  • CVE-2018-15591HigOct 15, 2018
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace. A local authenticated user can bypass Application Whitelisting restrictions to execute arbitrary code by leveraging multiple unspecified attack vectors.