CWE-669
Incorrect Resource Transfer Between Spheres
Description
The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.
Hierarchy (View 1000)
CVEs mapped to this weakness (116)
page 6 of 6| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-37252 | Low | 0.20 | 3.1 | 0.00 | Sep 14, 2026 | An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. Special:CheckUserLog shows usernames that have been hidden. | ||
| CVE-2025-45480 | Low | 0.20 | 3.0 | 0.00 | Sep 13, 2026 | Floodlight 71fe8a7 allows disruption of host communication via link spoofing. A port is misclassified as a non-boundary. | ||
| CVE-2026-73574 | Low | 0.20 | 3.1 | 0.00 | Aug 13, 2026 | In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper validation of the fu request parameter. An unauthenticated attacker can exploit this vulnerability by supplying a crafted path, potentially… | ||
| CVE-2026-40228 | Low | 0.19 | 2.9 | 0.00 | Apr 10, 2026 | In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p emerg" command is executed, if ForwardToWall=yes is set. | ||
| CVE-2024-31573 | Med | 0.19 | 4.0 | 0.00 | Oct 17, 2025 | XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT extension functions are enabled. | ||
| CVE-2025-26698 | Low | 0.18 | 2.7 | 0.00 | Feb 26, 2025 | Incorrect resource transfer between spheres issue exists in RevoWorks SCVX and RevoWorks Browser. If exploited, malicious files may be downloaded to the system where using the product. | ||
| CVE-2026-25832 | Low | 0.17 | 3.7 | 0.00 | Sep 14, 2026 | In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group. | ||
| CVE-2026-48847 | Low | 0.17 | 3.7 | 0.00 | May 25, 2026 | Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass. | ||
| CVE-2025-54352 | Low | 0.17 | 3.7 | 0.00 | Jul 21, 2025 | WordPress 3.5 through 6.8.2 allows remote attackers to guess titles of private and draft posts via pingback.ping XML-RPC requests. NOTE: the Supplier is not changing this behavior. | ||
| CVE-2025-54956 | Low | 0.14 | 3.2 | 0.00 | Aug 3, 2025 | The gh package before 1.5.0 for R delivers an HTTP response in a data structure that includes the Authorization header from the corresponding HTTP request. | ||
| CVE-2026-38924 | Low | 0.12 | 2.9 | 0.00 | Sep 14, 2026 | In Oraios AI Serena before 1.0.0, the listen address of the MCP server in HTTP mode is 0.0.0.0. NOTE: the Supplier observed that 0.0.0.0 was a "potential security hazard" but the Serena documentation, at the time of the issue report proposing 127.0.0.1 instead of 0.0.0.0,… | ||
| CVE-2026-89162 | Low | 0.12 | 2.9 | 0.00 | Sep 11, 2026 | In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe. | ||
| CVE-2002-0055 | 0.03 | — | 0.35 | Mar 8, 2002 | SMTP service in Microsoft Windows 2000, Windows XP Professional, and Exchange 2000 allows remote attackers to cause a denial of service via a command with a malformed data transfer (BDAT) request. | |||
| CVE-2025-54310 | Med | 0.00 | 4.0 | 0.00 | Jul 18, 2025 | qBittorrent before 5.1.2 does not prevent access to a local file that is referenced in a link URL. This affects rsswidget.cpp and searchjobwidget.cpp. | ||
| CVE-2022-4446 | Cri | 0.00 | 9.8 | 0.01 | Dec 13, 2022 | PHP Remote File Inclusion in GitHub repository tsolucio/corebos prior to 8.0. | ||
| CVE-2004-0872 | 0.00 | — | 0.03 | Sep 16, 2004 | Opera does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka "Cross Security Boundary Cookie… |
- risk 0.20cvss 3.1epss 0.00
An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. Special:CheckUserLog shows usernames that have been hidden.
- risk 0.20cvss 3.0epss 0.00
Floodlight 71fe8a7 allows disruption of host communication via link spoofing. A port is misclassified as a non-boundary.
- risk 0.20cvss 3.1epss 0.00
In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper validation of the fu request parameter. An unauthenticated attacker can exploit this vulnerability by supplying a crafted path, potentially…
- risk 0.19cvss 2.9epss 0.00
In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p emerg" command is executed, if ForwardToWall=yes is set.
- risk 0.19cvss 4.0epss 0.00
XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT extension functions are enabled.
- risk 0.18cvss 2.7epss 0.00
Incorrect resource transfer between spheres issue exists in RevoWorks SCVX and RevoWorks Browser. If exploited, malicious files may be downloaded to the system where using the product.
- risk 0.17cvss 3.7epss 0.00
In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group.
- risk 0.17cvss 3.7epss 0.00
Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass.
- risk 0.17cvss 3.7epss 0.00
WordPress 3.5 through 6.8.2 allows remote attackers to guess titles of private and draft posts via pingback.ping XML-RPC requests. NOTE: the Supplier is not changing this behavior.
- risk 0.14cvss 3.2epss 0.00
The gh package before 1.5.0 for R delivers an HTTP response in a data structure that includes the Authorization header from the corresponding HTTP request.
- risk 0.12cvss 2.9epss 0.00
In Oraios AI Serena before 1.0.0, the listen address of the MCP server in HTTP mode is 0.0.0.0. NOTE: the Supplier observed that 0.0.0.0 was a "potential security hazard" but the Serena documentation, at the time of the issue report proposing 127.0.0.1 instead of 0.0.0.0,…
- risk 0.12cvss 2.9epss 0.00
In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.
- CVE-2002-0055Mar 8, 2002risk 0.03cvss —epss 0.35
SMTP service in Microsoft Windows 2000, Windows XP Professional, and Exchange 2000 allows remote attackers to cause a denial of service via a command with a malformed data transfer (BDAT) request.
- risk 0.00cvss 4.0epss 0.00
qBittorrent before 5.1.2 does not prevent access to a local file that is referenced in a link URL. This affects rsswidget.cpp and searchjobwidget.cpp.
- risk 0.00cvss 9.8epss 0.01
PHP Remote File Inclusion in GitHub repository tsolucio/corebos prior to 8.0.
- CVE-2004-0872Sep 16, 2004risk 0.00cvss —epss 0.03
Opera does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka "Cross Security Boundary Cookie…