CWE-668— Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.— MITRE CWE catalog
1,140 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-668page 7 of 23
- CVE-2021-23958MEDIUMCVSS 6.5EG 6.52021-02-26
The browser could have been confused into transferring a screen sharing state into another tab, which would leak unintended information. This vulnerability affects Firefox < 85.
- CVE-2021-23985MEDIUMCVSS 6.5EG 6.52021-03-31
If an attacker is able to alter specific about:config values (for example malware running on the user's computer), the Devtools remote debugging feature could have been enabled in a way that was unnoticable to the user. This would have all…
- CVE-2021-24001MEDIUMCVSS 4.3EG 4.32021-06-24
A compromised content process could have performed session history manipulations it should not have been able to due to testing infrastructure that was not restricted to testing-only configurations. This vulnerability affects Firefox < 88.
- CVE-2021-24027HIGHCVSS 7.5EG 7.52021-04-06
A cache configuration issue prior to WhatsApp for Android v2.21.4.18 and WhatsApp Business for Android v2.21.4.18 may have allowed a third party with access to the device’s external storage to read cached TLS material.
- CVE-2021-24775MEDIUMCVSS 5.3EG 5.32022-02-01
The Document Embedder WordPress plugin before 1.7.5 contains a REST endpoint, which could allow unauthenticated users to enumerate the title of arbitrary private and draft posts.
- CVE-2021-24868MEDIUMCVSS 4.3EG 4.32022-02-01
The Document Embedder WordPress plugin before 1.7.9 contains a AJAX action endpoint, which could allow any authenticated user, such as subscriber to enumerate the title of arbitrary private and draft posts.
- CVE-2021-25314HIGHCVSS 7.8EG 7.82021-04-14
A Creation of Temporary File With Insecure Permissions vulnerability in hawk2 of SUSE Linux Enterprise High Availability 12-SP3, SUSE Linux Enterprise High Availability 12-SP5, SUSE Linux Enterprise High Availability 15-SP2 allows local at…
- CVE-2021-25352HIGHCVSS 5.5EG 7.82021-03-25
Using PendingIntent with implicit intent in Bixby Voice prior to version 3.0.52.14 allows attackers to execute privileged action by hijacking and modifying the intent.
- CVE-2021-25357MEDIUMCVSS 5.6EG 5.62021-04-09
A pendingIntent hijacking vulnerability in Create Movie prior to SMR APR-2021 Release 1 in Android O(8.x) and P(9.0), 3.4.81.1 in Android Q(10,0), and 3.6.80.7 in Android R(11.0) allows unprivileged applications to access contact informati…
- CVE-2021-25364MEDIUMCVSS 4.0EG 4.02021-04-09
A pendingIntent hijacking vulnerability in Secure Folder prior to SMR APR-2021 Release 1 allows unprivileged applications to access contact information.
- CVE-2021-25432LOWCVSS 3.3EG 3.32021-07-08
Information exposure vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above allows untrusted applications to access chat data.
- CVE-2021-25515MEDIUMCVSS 4.0EG 4.02021-12-08
An improper usage of implicit intent in SemRewardManager prior to SMR Dec-2021 Release 1 allows attackers to access BSSID.
- CVE-2021-25652MEDIUMCVSS 4.9EG 5.52021-06-24
An information disclosure vulnerability was discovered in the directory and file management of Avaya Aura Appliance Virtualization Platform Utilities (AVPU). This vulnerability may potentially allow any local user to access system function…
- CVE-2021-26027MEDIUMCVSS 5.3EG 5.32021-03-04
An issue was discovered in Joomla! 3.0.0 through 3.9.24. Incorrect ACL checks could allow unauthorized change of the category for an article.
- CVE-2021-26309LOWCVSS 3.3EG 3.32021-05-11
Information disclosure in the TeamCity plugin for IntelliJ before 2020.2.2.85899 was possible because a local temporary file had Insecure Permissions.
- CVE-2021-26312MEDIUMCVSS 5.5EG 5.52021-11-16
Failure to flush the Translation Lookaside Buffer (TLB) of the I/O memory management unit (IOMMU) may lead an IO device to write to memory it should not be able to access, resulting in a potential loss of integrity.
- CVE-2021-26313MEDIUMCVSS 5.5EG 5.52021-06-09
Potential speculative code store bypass in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution of overwritten instructions, may cause an incorrect speculation and could result in data …
- CVE-2021-26314MEDIUMCVSS 5.5EG 5.52021-06-09
Potential floating point value injection in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution with incorrect floating point results, may cause the use of incorrect data from FPVI and…
- CVE-2021-26317HIGHCVSS 7.8EG 7.82022-05-12
Failure to verify the protocol in SMM may allow an attacker to control the protocol and modify SPI flash resulting in a potential arbitrary code execution.
- CVE-2021-26327MEDIUMCVSS 5.5EG 5.52021-11-16
Insufficient validation of guest context in the SNP Firmware could lead to a potential loss of guest confidentiality.
- CVE-2021-26341MEDIUMCVSS 6.5EG 6.52022-03-11
Some AMD CPUs may transiently execute beyond unconditional direct branches, which may potentially result in data leakage.
- CVE-2021-26343MEDIUMCVSS 5.5EG 5.52023-01-11
Insufficient validation in ASP BIOS and DRTM commands may allow malicious supervisor x86 software to disclose the contents of sensitive memory which may result in information disclosure.
- CVE-2021-26361MEDIUMCVSS 5.5EG 5.52022-05-12
A malicious or compromised User Application (UApp) or AGESA Boot Loader (ABL) could be used by an attacker to exfiltrate arbitrary memory from the ASP stage 2 bootloader potentially leading to information disclosure.
- CVE-2021-26363MEDIUMCVSS 4.4EG 4.42022-05-12
A malicious or compromised UApp or ABL could potentially change the value that the ASP uses for its reserved DRAM, to one outside of the fenced area, potentially leading to data exposure.
- CVE-2021-26366HIGHCVSS 7.1EG 7.12022-05-12
An attacker, who gained elevated privileges via some other vulnerability, may be able to read data from Boot ROM resulting in a loss of system integrity.
- CVE-2021-26585MEDIUMCVSS 5.5EG 5.52021-06-24
A potential vulnerability has been identified in HPE OneView Global Dashboard release 2.31 which could lead to a local disclosure of privileged information. HPE has provided an update to OneView Global Dashboard. The issue is resolved in 2…
- CVE-2021-27001MEDIUMCVSS 5.5EG 5.52021-10-19
Clustered Data ONTAP versions 9.x prior to 9.5P18, 9.6P16, 9.7P16, 9.8P7 and 9.9.1P2 are susceptible to a vulnerability which could allow an authenticated privileged local attacker to arbitrarily modify Compliance-mode WORM data prior to t…
- CVE-2021-27043HIGHCVSS 7.8EG 7.82021-06-25
An Arbitrary Address Write issue in the Autodesk DWG application can allow a malicious user to leverage the application to write in unexpected paths. In order to exploit this the attacker would need the victim to enable full page heap in t…
- CVE-2021-27236CRITICALCVSS 9.8EG 9.82021-02-16
An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8. getfile.asp allows Unauthenticated Local File Inclusion, which can be leveraged to achieve Remote Code Execution.
- CVE-2021-27424MEDIUMCVSS 5.3EG 5.32022-03-23
GE UR firmware versions prior to version 8.1x shares MODBUS memory map as part of the communications guide. GE was made aware a “Last-key pressed” MODBUS register can be used to gain unauthorized information.
- CVE-2021-27621MEDIUMCVSS 4.9EG 4.92021-06-09
Information Disclosure vulnerability in UserAdmin application in SAP NetWeaver Application Server for Java, versions - 7.11,7.20,7.30,7.31,7.40 and 7.50 allows attackers to access restricted information by entering malicious server name.
- CVE-2021-27637MEDIUMCVSS 4.6EG 4.62021-06-09
Under certain conditions SAP Enable Now (SAP Workforce Performance Builder - Manager), versions - 1.0, 10 allows an attacker to access information which would otherwise be restricted leading to information disclosure.
- CVE-2021-27769MEDIUMCVSS 5.3EG 5.32022-05-12
Information leakage occurs when a website reveals information that could aid an attacker to further exploit the system. This information may or may not be sensitive and does not automatically mean a breach is likely to occur. Overall, any …
- CVE-2021-27770HIGHCVSS 6.8EG 8.82022-05-12
The vulnerability was discovered within the “FaviconService”. The service takes a base64-encoded URL which is then requested by the webserver. We assume this service is used by the “meetings”-function where users can specify an ext…
- CVE-2021-28168MEDIUMCVSS 6.2EG 6.22021-04-22
Eclipse Jersey 2.28 to 2.33 and Eclipse Jersey 3.0.0 to 3.0.1 contains a local information disclosure vulnerability. This is due to the use of the File.createTempFile which creates a file inside of the system temporary directory with the p…
- CVE-2021-28488MEDIUMCVSS 6.5EG 6.52022-03-10
Ericsson Network Manager (ENM) before 21.2 has incorrect access-control behavior (that only affects the level of access available to persons who were already granted a highly privileged role). Users in the same AMOS authorization group can…
- CVE-2021-28568MEDIUMCVSS 5.8EG 6.52021-09-08
Adobe Genuine Services version 7.1 (and earlier) is affected by an Insecure file permission vulnerability during installation process. A local authenticated attacker could leverage this vulnerability to achieve privilege escalation in the …
- CVE-2021-28597MEDIUMCVSS 5.5EG 5.52021-06-28
Adobe Photoshop Elements version 5.2 (and earlier) is affected by an insecure temporary file creation vulnerability. An unauthenticated attacker could leverage this vulnerability to call functions against the installer to perform high priv…
- CVE-2021-28623MEDIUMCVSS 5.5EG 5.52021-06-28
Adobe Premiere Elements version 5.2 (and earlier) is affected by an insecure temporary file creation vulnerability. An unauthenticated attacker could leverage this vulnerability to call functions against the installer to perform high privi…
- CVE-2021-28633MEDIUMCVSS 6.1EG 6.12021-08-24
Adobe Creative Cloud Desktop Application (installer) version 2.4 (and earlier) is affected by an Insecure temporary file creation vulnerability. An attacker could leverage this vulnerability to cause arbitrary file overwriting in the conte…
- CVE-2021-29115MEDIUMCVSS 5.3EG 5.32021-12-07
An information disclosure vulnerability in the ArcGIS Service Directory in Esri ArcGIS Enterprise versions 10.9.0 and below may allows a remote attacker to view hidden field names in feature layers. This issue may reveal field names, but n…
- CVE-2021-29280MEDIUMCVSS 6.4EG 6.42021-08-19
In TP-Link Wireless N Router WR840N an ARP poisoning attack can cause buffer overflow
- CVE-2021-29701MEDIUMCVSS 4.3EG 4.32022-01-11
IBM Engineering Workflow Management 7.0, 7.0.1, and 7.0.2 as well as IBM Rational Team Concert 6.0.6 and 6.0.6.1 could allow an authneticated attacker to obtain sensitive information from build definitions that could aid in further attacks…
- CVE-2021-29715CRITICALCVSS 9.1EG 9.12021-08-26
IBM API Connect 5.0.0.0 through 5.0.8.11 could alllow a remote user to obtain sensitive information or conduct denial of serivce attacks due to open ports. IBM X-Force ID: 201018.
- CVE-2021-29716MEDIUMCVSS 6.5EG 6.52021-12-03
IBM Cognos Analytics 11.1.7 and 11.2.0 could allow a low level user to reas of the application that privileged user should only be allowed to view. IBM X-Force ID: 201087.
- CVE-2021-29719MEDIUMCVSS 5.3EG 5.32021-12-03
IBM Cognos Analytics 11.1.7 and 11.2.0 could be vulnerable to client side vulnerabilties due to a web response specifying an incorrect content type. IBM X-Force ID: 201091
- CVE-2021-29768MEDIUMCVSS 6.5EG 6.52022-06-24
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a low level user to obtain sensitive information from the details of the 'Cloud Storage' page for which they should not have access. IBM X-Force ID: 202682.
- CVE-2021-29867MEDIUMCVSS 5.4EG 5.42021-12-03
IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated to view or edit a Jupyter notebook that they should not have access to. IBM X-Force ID: 206212.
- CVE-2021-29873HIGHCVSS 8.1EG 8.12021-10-21
IBM Flash System 900 could allow an authenticated attacker to obtain sensitive information and cause a denial of service due to a restricted shell escape vulnerability. IBM X-Force ID: 206229.
- CVE-2021-29880MEDIUMCVSS 6.5EG 6.52021-08-13
IBM QRadar SIEM 7.4.3 GA - 7.4.3 Fix Pack 1 when using domains or multi-tenancy could be vulnerable to information disclosure between tenants by routing SIEM data to the incorrect domain. IBM X-Force ID: 206979.
Map vulnerabilities like CWE-668 to your infrastructure
EchelonGraph correlates every CVE — across CWE-668 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →