Vulnerabilities > Exposure of Resource to Wrong Sphere

DATE CVE VULNERABILITY TITLE RISK
2023-01-14 CVE-2023-22497 Exposure of Resource to Wrong Sphere vulnerability in Netdata
Netdata is an open source option for real-time infrastructure monitoring and troubleshooting.
network
low complexity
netdata CWE-668
critical
9.1
2023-01-12 CVE-2022-24913 Exposure of Resource to Wrong Sphere vulnerability in Java-Merge-Sort Project Java-Merge-Sort
Versions of the package com.fasterxml.util:java-merge-sort before 1.1.0 are vulnerable to Insecure Temporary File in the StdTempFileProvider() function in StdTempFileProvider.java, which uses the permissive File.createTempFile() function, exposing temporary file contents.
local
low complexity
java-merge-sort-project CWE-668
5.5
2023-01-11 CVE-2021-26343 Exposure of Resource to Wrong Sphere vulnerability in AMD products
Insufficient validation in ASP BIOS and DRTM commands may allow malicious supervisor x86 software to disclose the contents of sensitive memory which may result in information disclosure.
local
low complexity
amd CWE-668
5.5
2023-01-06 CVE-2018-25068 Exposure of Resource to Wrong Sphere vulnerability in Globalpom-Utils Project Globalpom-Utils
A vulnerability has been found in devent globalpom-utils up to 4.5.0 and classified as critical.
network
low complexity
globalpom-utils-project CWE-668
critical
9.8
2023-01-02 CVE-2022-0337 Exposure of Resource to Wrong Sphere vulnerability in Google Chrome
Inappropriate implementation in File System API in Google Chrome on Windows prior to 97.0.4692.71 allowed a remote attacker to obtain potentially sensitive information via a crafted HTML page.
network
low complexity
google CWE-668
6.5
2023-01-01 CVE-2022-48198 Exposure of Resource to Wrong Sphere vulnerability in Ntpd Driver Project Ntpd Driver
The ntpd_driver component before 1.3.0 and 2.x before 2.2.0 for Robot Operating System (ROS) allows attackers, who control the source code of a different node in the same ROS application, to change a robot's behavior.
network
low complexity
ntpd-driver-project CWE-668
critical
9.8
2022-12-28 CVE-2022-4817 Exposure of Resource to Wrong Sphere vulnerability in Jgit-Cookbook Project Jgit-Cookbook
A vulnerability was found in centic9 jgit-cookbook.
local
low complexity
jgit-cookbook-project CWE-668
7.8
2022-12-27 CVE-2015-10004 Exposure of Resource to Wrong Sphere vulnerability in Json web Token Project Json web Token
Token validation methods are susceptible to a timing side-channel during HMAC comparison.
network
low complexity
json-web-token-project CWE-668
7.5
2022-12-26 CVE-2019-9011 Exposure of Resource to Wrong Sphere vulnerability in Pilz PMC 3.0.0
In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), an attacker can identify valid usernames.
network
low complexity
pilz CWE-668
5.3
2022-12-25 CVE-2022-45895 Exposure of Resource to Wrong Sphere vulnerability in Planetestream Planet Estream
Planet eStream before 6.72.10.07 discloses sensitive information, related to the ON cookie (findable in HTML source code for Default.aspx in some situations) and the WhoAmI endpoint (e.g., path disclosure).
network
low complexity
planetestream CWE-668
6.5