Vulnerabilities > Exposure of Resource to Wrong Sphere

DATE CVE VULNERABILITY TITLE RISK
2023-03-01 CVE-2023-24567 Exposure of Resource to Wrong Sphere vulnerability in Dell EMC Networker
Dell NetWorker versions 19.5 and earlier contain 'RabbitMQ' version disclosure vulnerability.
network
low complexity
dell CWE-668
6.5
2023-03-01 CVE-2023-25544 Exposure of Resource to Wrong Sphere vulnerability in Dell EMC Networker
Dell NetWorker versions 19.5 and earlier contain 'Apache Tomcat' version disclosure vulnerability.
network
low complexity
dell CWE-668
6.5
2023-03-01 CVE-2023-22775 Exposure of Resource to Wrong Sphere vulnerability in Arubanetworks Arubaos and Sd-Wan
A vulnerability exists which allows an authenticated attacker to access sensitive information on the ArubaOS command line interface.
network
low complexity
arubanetworks CWE-668
6.5
2023-03-01 CVE-2023-22777 Exposure of Resource to Wrong Sphere vulnerability in Arubanetworks Arubaos and Sd-Wan
An authenticated information disclosure vulnerability exists in the ArubaOS web-based management interface.
network
low complexity
arubanetworks CWE-668
6.5
2023-02-27 CVE-2023-26041 Exposure of Resource to Wrong Sphere vulnerability in Nextcloud Talk
Nextcloud Talk is a fully on-premises audio/video and chat communication service.
network
low complexity
nextcloud CWE-668
4.3
2023-02-27 CVE-2023-23501 Exposure of Resource to Wrong Sphere vulnerability in Apple Macos
The issue was addressed with improved memory handling This issue is fixed in macOS Ventura 13.2.
local
low complexity
apple CWE-668
5.5
2023-02-27 CVE-2023-27265 Exposure of Resource to Wrong Sphere vulnerability in Mattermost Server
Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the "Regenerate Invite Id" API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in the response.
network
low complexity
mattermost CWE-668
2.7
2023-02-24 CVE-2022-44310 Exposure of Resource to Wrong Sphere vulnerability in Ecdh Project Ecdh 0.0.0/0.1.0/0.1.1
In Development IL ecdh before 0.2.0, an attacker can send an invalid point (not on the curve) as the public key, and obtain the derived shared secret.
network
low complexity
ecdh-project CWE-668
7.5
2023-02-24 CVE-2023-0481 Exposure of Resource to Wrong Sphere vulnerability in Quarkus
In RestEasy Reactive implementation of Quarkus the insecure File.createTempFile() is used in the FileBodyHandler class which creates temp files with insecure permissions that could be read by a local user.
local
low complexity
quarkus CWE-668
3.3
2023-02-20 CVE-2023-26081 Exposure of Resource to Wrong Sphere vulnerability in multiple products
In Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating passwords, because autofill occurs in sandboxed contexts.
network
low complexity
gnome fedoraproject CWE-668
7.5