CWE-668— Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.— MITRE CWE catalog
1,151 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-668page 2 of 24
- CVE-2017-16606HIGHCVSS 8.8EG 8.82018-01-23
This vulnerability allows remote attackers to execute code by creating arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability,…
- CVE-2017-16610CRITICALCVSS 9.8EG 9.82018-01-23
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within upload_save_do.js…
- CVE-2017-16660HIGHCVSS 7.2EG 7.22017-11-08
Cacti 1.1.27 allows remote authenticated administrators to conduct Remote Code Execution attacks by placing the Log Path under the web root, and then making a remote_agent.php request containing PHP code in a Client-ip header.
- CVE-2017-17087MEDIUMCVSS 5.5EG 5.52017-12-01
fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group ownership of the original file), which allows local users to obtain sensitive information by lev…
- CVE-2017-18073HIGHCVSS 7.5EG 7.52018-04-11
In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 820, SD 820A, SD 835, the HLOS can gain access to unauthorized …
- CVE-2017-18129CRITICALCVSS 9.8EG 9.82018-04-11
In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile and Snapdragon Mobile MDM9206, MDM9607, SD 845, MSM8996, MSM8998, it is possible for IPA (internet protocol accelerator) channels owned by one security dom…
- CVE-2017-5634MEDIUMCVSS 6.6EG 6.62017-02-09
The Norwegian Air Shuttle (aka norwegian.com) airline kiosk allows physically proximate attackers to bypass the intended "Please select booking identification" UI step, and obtain administrative privileges and network access on the underly…
- CVE-2017-5648CRITICALCVSS 9.1EG 9.12017-04-17
While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0.RC1 to 8.0.41, and 7.0.0 to 7.0.75 did not use the appropriate facade object. When runnin…
- CVE-2017-6100HIGHCVSS 7.5EG 7.52017-02-23
tcpdf before 6.2.0 uploads files from the server generating PDF-files to an external FTP.
- CVE-2017-6872MEDIUMCVSS 6.5EG 6.52017-08-08
A vulnerability was discovered in Siemens OZW672 (all versions) and OZW772 (all versions) that could allow an attacker with access to port 21/tcp to access or alter historical measurement data stored on the device.
- CVE-2017-7490MEDIUMCVSS 5.3EG 5.32017-05-15
In Moodle 2.x and 3.x, searching of arbitrary blogs is possible because a capability check is missing.
- CVE-2017-8161MEDIUMCVSS 4.6EG 4.62017-11-22
EVA-L09 smartphones with software Earlier than EVA-L09C25B150CUSTC25D003 versions,Earlier than EVA-L09C440B140 versions,Earlier than EVA-L09C464B361 versions,Earlier than EVA-L09C675B320CUSTC675D004 versions have Factory Reset Protection (…
- CVE-2017-8171MEDIUMCVSS 4.6EG 4.62017-11-22
Huawei smart phones with software earlier than Vicky-AL00AC00B172D versions have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an att…
- CVE-2017-8185HIGHCVSS 7.8EG 7.82017-11-22
ME906s-158 earlier than ME906S_Installer_13.1805.10.3 versions has a privilege elevation vulnerability. An attacker could exploit this vulnerability to modify the configuration information containing malicious files and trick users into ex…
- CVE-2017-8418LOWCVSS 3.3EG 3.32017-05-02
RuboCop 0.48.1 and earlier does not use /tmp in safe way, allowing local users to exploit this to tamper with cache files belonging to other users.
- CVE-2018-10361HIGHCVSS 7.8EG 7.82018-04-25
An issue was discovered in KTextEditor 5.34.0 through 5.45.0. Insecure handling of temporary files in the KTextEditor's kauth_ktexteditor_helper service (as utilized in the Kate text editor) can allow other unprivileged users on the local …
- CVE-2018-15591HIGHCVSS 7.8EG 7.82018-10-15
An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace. A local authenticated user can bypass Application Whitelisting restrictions to execute arbitrary code by leveraging multiple unspecified attack vec…
- CVE-2018-16494HIGHCVSS 8.8EG 8.82021-05-26
In VOS and overly permissive "umask" may allow for authorized users of the server to gain unauthorized access through insecure file permissions that can result in an arbitrary read, write, or execution of newly created files and directorie…
- CVE-2018-18068CRITICALCVSS 9.8EG 9.82019-04-04
The ARM-based hardware debugging feature on Raspberry Pi 3 module B+ and possibly other devices allows non-secure EL1 code to read/write any EL3 (the highest privilege level in ARMv8) memory/register via inter-processor debugging. With a d…
- CVE-2018-1840HIGHCVSS 6.0EG 8.12018-12-03
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to gain elevated privileges on the system, caused when a security domain is configured to use a federated repository other than global federated repository and then…
- CVE-2018-20237MEDIUMCVSS 6.5EG 6.52019-02-13
Atlassian Confluence Server and Data Center before version 6.13.1 allows an authenticated user to download a deleted page via the word export feature.
- CVE-2018-20321HIGHCVSS 8.8EG 8.82019-04-10
An issue was discovered in Rancher 2 through 2.1.5. Any project member with access to the default namespace can mount the netes-default service account in a pod, and then use that pod to execute administrative privileged commands against t…
- CVE-2018-20947MEDIUMCVSS 5.5EG 5.52019-08-01
cPanel before 68.0.27 allows certain file-write operations via the telnetcrt script (SEC-356).
- CVE-2018-25068MEDIUMCVSS 6.3EG 6.32023-01-06
A vulnerability has been found in devent globalpom-utils up to 4.5.0 and classified as critical. This vulnerability affects the function createTmpDir of the file globalpomutils-fileresources/src/main/java/com/anrisoftware/globalpom/fileres…
- CVE-2018-4048HIGHCVSS 7.8EG 7.82019-05-30
An exploitable local privilege elevation vulnerability exists in the file system permissions of the `Temp` directory in GOG Galaxy 1.2.48.36 (Windows 64-bit Installer). An attacker can overwrite executables of the Desktop Galaxy Updater to…
- CVE-2018-6880MEDIUMCVSS 5.3EG 5.32018-02-12
EmpireCMS 6.6 through 7.2 allows remote attackers to discover the full path via an array value for a parameter to class/connect.php.
- CVE-2018-6910HIGHCVSS 7.5EG 7.52018-02-13
DedeCMS 5.7 allows remote attackers to discover the full path via a direct request for include/downmix.inc.php or inc/inc_archives_functions.php.
- CVE-2018-7072CRITICALCVSS 9.8EG 9.82018-08-06
A remote bypass of security restrictions vulnerability was identified in HPE Moonshot Provisioning Manager prior to v1.24.
- CVE-2018-7073MEDIUMCVSS 5.5EG 5.52018-08-06
A local arbitrary file modification vulnerability was identified in HPE Moonshot Provisioning Manager prior to v1.24.
- CVE-2018-7479MEDIUMCVSS 5.3EG 5.32018-02-26
YzmCMS 3.6 allows remote attackers to discover the full path via a direct request to application/install/templates/s1.php.
- CVE-2018-7846CRITICALCVSS 9.8EG 9.82019-05-22
A CWE-501: Trust Boundary Violation vulnerability on connection to the Controller exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum and Modicon Premium which could cause unauthorized access by conducting a brute for…
- CVE-2018-8040MEDIUMCVSS 5.3EG 5.32018-08-29
Pages that are rendered using the ESI plugin can have access to the cookie header when the plugin is configured not to allow access. This affects Apache Traffic Server (ATS) versions 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue…
- CVE-2018-8861HIGHCVSS 8.7EG 8.72018-05-04
Vulnerabilities within the Philips Brilliance CT kiosk environment (Brilliance 64 version 2.6.2 and prior, Brilliance iCT versions 4.1.6 and prior, Brillance iCT SP versions 3.2.4 and prior, and Brilliance CT Big Bore 2.3.5 and prior) coul…
- CVE-2019-10365MEDIUMCVSS 4.3EG 4.32019-07-31
Jenkins Google Kubernetes Engine Plugin 0.6.2 and earlier created a temporary file containing a temporary access token in the project workspace, where it could be accessed by users with Job/Read permission.
- CVE-2019-10781CRITICALCVSS 9.8EG 9.82020-01-22
In schema-inspector before 1.6.9, a maliciously crafted JavaScript object can bypass the `sanitize()` and the `validate()` function used within schema-inspector.
- CVE-2019-10790HIGHCVSS 7.5EG 7.52020-02-17
taffydb npm module, vulnerable in all versions up to and including 2.7.3, allows attackers to forge adding additional properties into user-input processed by taffy which can allow access to any data items in the DB. taffy sets an internal …
- CVE-2019-10805HIGHCVSS 7.5EG 7.52020-02-28
valib through 2.0.0 allows Internal Property Tampering. A maliciously crafted JavaScript object can bypass several inspection functions provided by valib. Valib uses a built-in function (hasOwnProperty) from the unsafe user-input to examin…
- CVE-2019-11728MEDIUMCVSS 4.7EG 4.72019-07-23
The HTTP Alternative Services header, Alt-Svc, can be used by a malicious site to scan all TCP ports of any host that the accessible to a user when web content is loaded. This vulnerability affects Firefox < 68.
- CVE-2019-11784MEDIUMCVSS 6.5EG 6.52020-12-22
Improper access control in mail module (notifications) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users to obtain access to arbitrary messages in conversations they were not a party…
- CVE-2019-11785MEDIUMCVSS 4.3EG 4.32020-12-22
Improper access control in mail module (followers) in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote authenticated users to obtain access to messages posted on business records there were not given acce…
- CVE-2019-12274HIGHCVSS 8.8EG 8.82019-06-06
In Rancher 1 and 2 through 2.2.3, unprivileged users (if allowed to deploy nodes) can gain admin access to the Rancher management plane because node driver options intentionally allow posting certain data to the cloud. The problem is that …
- CVE-2019-12660MEDIUMCVSS 5.5EG 5.52019-09-25
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to write values to the underlying memory of an affected device. The vulnerability is due to improper input validation and authorization of spe…
- CVE-2019-12875MEDIUMCVSS 6.5EG 6.52019-06-18
Alpine Linux abuild through 3.4.0 allows an unprivileged member of the abuild group to add an untrusted package via a --keys-dir option that causes acceptance of an untrusted signing key.
- CVE-2019-12904MEDIUMCVSS 5.9EG 5.92019-06-20
In Libgcrypt 1.8.4, the C implementation of AES is vulnerable to a flush-and-reload side-channel attack because physical addresses are available to other processes. (The C implementation is used on platforms where an assembly-language impl…
- CVE-2019-12928CRITICALCVSS 9.8EG 9.82019-06-24
The QMP migrate command in QEMU version 4.0.0 and earlier is vulnerable to OS command injection, which allows the remote attacker to achieve code execution, denial of service, or information disclosure by sending a crafted QMP command to t…
- CVE-2019-12929CRITICALCVSS 9.8EG 9.82019-06-24
The QMP guest_exec command in QEMU 4.0.0 and earlier is prone to OS command injection, which allows the attacker to achieve code execution, denial of service, or information disclosure by sending a crafted QMP command to the listening serv…
- CVE-2019-13379HIGHCVSS 8.8EG 8.82019-07-07
On AVTECH Room Alert 3E devices before 2.2.5, an attacker with access to the device's web interface may escalate privileges from an unauthenticated user to administrator by performing a cmd.cgi?action=ResetDefaults&src=RA reset and using t…
- CVE-2019-13546MEDIUMCVSS 6.8EG 6.82019-10-25
In IntelliSpace Perinatal, Versions K and prior, a vulnerability within the IntelliSpace Perinatal application environment could enable an unauthorized attacker with physical access to a locked application screen, or an authorized remote d…
- CVE-2019-13927MEDIUMCVSS 5.3EG 5.32019-12-12
A vulnerability has been identified in Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.D with Desigo PX Web modules PXA40-W0, PXA40-W1, PXA40-W2 (All firmware versions < V6.00.320), Desigo PX automation controll…
- CVE-2019-14905MEDIUMCVSS 5.6EG 5.62020-03-31
A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malic…
Map vulnerabilities like CWE-668 to your infrastructure
EchelonGraph correlates every CVE — across CWE-668 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →