VYPR

CWE-669

Incorrect Resource Transfer Between Spheres

ClassDraft

Description

The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.

Hierarchy (View 1000)

CVEs mapped to this weakness (116)

page 6 of 6
  • CVE-2023-37252LowSep 14, 2026
    risk 0.20cvss 3.1epss 0.00

    An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. Special:CheckUserLog shows usernames that have been hidden.

  • CVE-2025-45480LowSep 13, 2026
    risk 0.20cvss 3.0epss 0.00

    Floodlight 71fe8a7 allows disruption of host communication via link spoofing. A port is misclassified as a non-boundary.

  • CVE-2026-73574LowAug 13, 2026
    risk 0.20cvss 3.1epss 0.00

    In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper validation of the fu request parameter. An unauthenticated attacker can exploit this vulnerability by supplying a crafted path, potentially…

  • CVE-2026-40228LowApr 10, 2026
    risk 0.19cvss 2.9epss 0.00

    In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p emerg" command is executed, if ForwardToWall=yes is set.

  • CVE-2024-31573MedOct 17, 2025
    risk 0.19cvss 4.0epss 0.00

    XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT extension functions are enabled.

  • CVE-2025-26698LowFeb 26, 2025
    risk 0.18cvss 2.7epss 0.00

    Incorrect resource transfer between spheres issue exists in RevoWorks SCVX and RevoWorks Browser. If exploited, malicious files may be downloaded to the system where using the product.

  • CVE-2026-25832LowSep 14, 2026
    risk 0.17cvss 3.7epss 0.00

    In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group.

  • CVE-2026-48847LowMay 25, 2026
    risk 0.17cvss 3.7epss 0.00

    Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass.

  • CVE-2025-54352LowJul 21, 2025
    risk 0.17cvss 3.7epss 0.00

    WordPress 3.5 through 6.8.2 allows remote attackers to guess titles of private and draft posts via pingback.ping XML-RPC requests. NOTE: the Supplier is not changing this behavior.

  • CVE-2025-54956LowAug 3, 2025
    risk 0.14cvss 3.2epss 0.00

    The gh package before 1.5.0 for R delivers an HTTP response in a data structure that includes the Authorization header from the corresponding HTTP request.

  • CVE-2026-38924LowSep 14, 2026
    risk 0.12cvss 2.9epss 0.00

    In Oraios AI Serena before 1.0.0, the listen address of the MCP server in HTTP mode is 0.0.0.0. NOTE: the Supplier observed that 0.0.0.0 was a "potential security hazard" but the Serena documentation, at the time of the issue report proposing 127.0.0.1 instead of 0.0.0.0,…

  • CVE-2026-89162LowSep 11, 2026
    risk 0.12cvss 2.9epss 0.00

    In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.

  • CVE-2002-0055Mar 8, 2002
    risk 0.03cvss —epss 0.35

    SMTP service in Microsoft Windows 2000, Windows XP Professional, and Exchange 2000 allows remote attackers to cause a denial of service via a command with a malformed data transfer (BDAT) request.

  • CVE-2025-54310MedJul 18, 2025
    risk 0.00cvss 4.0epss 0.00

    qBittorrent before 5.1.2 does not prevent access to a local file that is referenced in a link URL. This affects rsswidget.cpp and searchjobwidget.cpp.

  • CVE-2022-4446CriDec 13, 2022
    risk 0.00cvss 9.8epss 0.01

    PHP Remote File Inclusion in GitHub repository tsolucio/corebos prior to 8.0.

  • CVE-2004-0872Sep 16, 2004
    risk 0.00cvss —epss 0.03

    Opera does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka "Cross Security Boundary Cookie…