VYPR

CWE-668

Exposure of Resource to Wrong Sphere

ClassDraft

Description

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

Hierarchy (View 1000)

CVEs mapped to this weakness (796)

page 8 of 40
  • CVE-2022-28226HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.00

    Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.801 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating temporary files in directory with insecure permissions during Yandex Browser update…

  • CVE-2022-24411HigApr 12, 2022
    risk 0.51cvss 7.8epss 0.00

    Dell PowerScale OneFS 8.2.2 and above contain an elevation of privilege vulnerability. A local attacker with ISI_PRIV_LOGIN_SSH and/or ISI_PRIV_LOGIN_CONSOLE could potentially exploit this vulnerability, leading to elevation of privilege. This could potentially allow users to…

  • CVE-2021-42255HigApr 12, 2022
    risk 0.51cvss 7.8epss 0.00

    AppGuard Enterprise before 6.7.100.1 creates a Temporary File in a Directory with Insecure Permissions. Local users can gain SYSTEM privileges because a repair operation relies on the %TEMP% directory of an unprivileged user.

  • CVE-2022-24986HigFeb 26, 2022
    risk 0.51cvss 7.8epss 0.00

    KDE KCron through 21.12.2 uses a temporary file in /tmp when saving, but reuses the filename during an editing session. Thus, someone watching it be created the first time could potentially intercept the file the following time, enabling that person to run unauthorized commands.

  • CVE-2021-42714HigFeb 15, 2022
    risk 0.51cvss 7.8epss 0.00

    Splashtop Remote Client (Business Edition) through 3.4.8.3 creates a Temporary File in a Directory with Insecure Permissions.

  • CVE-2021-42713HigFeb 15, 2022
    risk 0.51cvss 7.8epss 0.00

    Splashtop Remote Client (Personal Edition) through 3.4.6.1 creates a Temporary File in a Directory with Insecure Permissions.

  • CVE-2021-42712HigFeb 15, 2022
    risk 0.51cvss 7.8epss 0.00

    Splashtop Streamer through 3.4.8.3 creates a Temporary File in a Directory with Insecure Permissions.

  • CVE-2021-44049HigJan 15, 2022
    risk 0.51cvss 7.8epss 0.00

    CyberArk Endpoint Privilege Manager (EPM) through 11.5.3.328 before 2021-12-20 allows a local user to gain elevated privileges via a Trojan horse Procmon64.exe in the user's Temp directory.

  • CVE-2021-42254HigNov 19, 2021
    risk 0.51cvss 7.8epss 0.00

    BeyondTrust Privilege Management prior to version 21.6 creates a Temporary File in a Directory with Insecure Permissions.

  • CVE-2021-22385HigAug 10, 2021
    risk 0.51cvss 7.8epss 0.00

    A component of the Huawei smartphone has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause Kernel Code Execution.

  • CVE-2021-22420HigAug 3, 2021
    risk 0.51cvss 7.8epss 0.00

    A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause the underlying trust of the application trustlist mechanism is missing..

  • CVE-2021-33669HigJun 9, 2021
    risk 0.51cvss 7.8epss 0.00

    Under certain conditions, SAP Mobile SDK Certificate Provider allows a local unprivileged attacker to exploit an insecure temporary file storage. For a successful exploitation user interaction from another user is required and could lead to complete impact of confidentiality…

  • CVE-2021-31154HigMay 27, 2021
    risk 0.51cvss 7.8epss 0.00

    pleaseedit in please before 0.4 uses predictable temporary filenames in /tmp and the target directory. This allows a local attacker to gain full root privileges by staging a symlink attack.

  • CVE-2021-25314HigApr 14, 2021
    risk 0.51cvss 7.8epss 0.00

    A Creation of Temporary File With Insecure Permissions vulnerability in hawk2 of SUSE Linux Enterprise High Availability 12-SP3, SUSE Linux Enterprise High Availability 12-SP5, SUSE Linux Enterprise High Availability 15-SP2 allows local attackers to escalate to root. This issue…

  • CVE-2019-5159HigMar 11, 2020
    risk 0.51cvss 7.8epss 0.02

    An exploitable improper input validation vulnerability exists in the firmware update functionality of WAGO e!COCKPIT automation software v1.6.0.7. A specially crafted firmware update file can allow an attacker to write arbitrary files to arbitrary locations on WAGO controllers…

  • CVE-2014-0023HigNov 15, 2019
    risk 0.51cvss 7.8epss 0.00

    OpenShift: Install script has temporary file creation vulnerability which can result in arbitrary code execution

  • CVE-2019-15350HigNov 14, 2019
    risk 0.51cvss 7.8epss 0.00

    The Tecno Camon Android device with a build fingerprint of TECNO/H622/TECNO-ID5b:8.1.0/O11019/G-180829V31:user/release-keys contains a pre-installed platform app with a package name of com.lovelyfont.defcontainer (versionCode=7, versionName=7.0.11). This app contains an exported…

  • CVE-2019-15349HigNov 14, 2019
    risk 0.51cvss 7.8epss 0.00

    The Tecno Camon Android device with a build fingerprint of TECNO/H612/TECNO-ID5a:8.1.0/O11019/F-180828V106:user/release-keys contains a pre-installed platform app with a package name of com.lovelyfont.defcontainer (versionCode=7, versionName=7.0.11). This app contains an…

  • CVE-2019-15346HigNov 14, 2019
    risk 0.51cvss 7.8epss 0.00

    The Tecno Camon iClick 2 Android device with a build fingerprint of TECNO/H622/TECNO-ID6:8.1.0/O11019/F-180824V116:user/release-keys contains a pre-installed platform app with a package name of com.lovelyfont.defcontainer (versionCode=7, versionName=7.0.11). This app contains an…

  • CVE-2019-15345HigNov 14, 2019
    risk 0.51cvss 7.8epss 0.00

    The Tecno Camon iClick Android device with a build fingerprint of TECNO/H633/TECNO-IN6:8.1.0/O11019/A-180409V96:user/release-keys contains a pre-installed platform app with a package name of com.lovelyfont.defcontainer (versionCode=7, versionName=7.0.8). This app contains an…