Vulnerabilities > Exposure of Resource to Wrong Sphere

DATE CVE VULNERABILITY TITLE RISK
2023-02-09 CVE-2023-21445 Exposure of Resource to Wrong Sphere vulnerability in Samsung Android 11.0/12.0
Improper access control vulnerability in MyFiles prior to versions 12.2.09 in Android R(11), 13.1.03.501 in Android S(12) and 14.1.00.422 in Android T(13) allows local attacker to write file with MyFiles privilege via implicit intent.
local
low complexity
samsung CWE-668
7.8
2023-02-09 CVE-2023-21447 Exposure of Resource to Wrong Sphere vulnerability in Samsung Cloud 4.7.0.3/5.1.0.8/5.2.00.7
Improper access control vulnerabilities in Samsung Cloud prior to version 5.3.0.32 allows local attackers to access information with Samsung Cloud's privilege via implicit intent.
local
low complexity
samsung CWE-668
3.3
2023-02-01 CVE-2022-46756 Exposure of Resource to Wrong Sphere vulnerability in Dell Vxrail Manager
Dell VxRail, versions prior to 7.0.410, contain a Container Escape Vulnerability.
local
low complexity
dell CWE-668
6.7
2023-01-30 CVE-2022-22732 Exposure of Resource to Wrong Sphere vulnerability in Schneider-Electric Ecostruxure Power Commission
A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that could cause all remote domains to access the resources (data) supplied by the server when an attacker sends a fetch request from third-party site or malicious site.
network
low complexity
schneider-electric CWE-668
7.5
2023-01-26 CVE-2021-41988 Exposure of Resource to Wrong Sphere vulnerability in Qlik Nprinting Designer 21.14.3.0
Qlik NPrinting Designer through 21.14.3.0 creates a Temporary File in a Directory with Insecure Permissions.
local
low complexity
qlik CWE-668
7.8
2023-01-26 CVE-2021-41989 Exposure of Resource to Wrong Sphere vulnerability in Qlik Qlikview 12.60.20100.0
Qlik QlikView through 12.60.20100.0 creates a Temporary File in a Directory with Insecure Permissions.
local
low complexity
qlik CWE-668
7.8
2023-01-26 CVE-2022-26329 Exposure of Resource to Wrong Sphere vulnerability in Netiq Identity Manager
File existence disclosure vulnerability in NetIQ Identity Manager plugin prior to version 4.8.5 allows attacker to determine whether a file exists on the filesystem.
network
low complexity
netiq CWE-668
5.3
2023-01-18 CVE-2023-21611 Exposure of Resource to Wrong Sphere vulnerability in Adobe products
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Creation of Temporary File in Directory with Incorrect Permissions vulnerability that could result in privilege escalation in the context of the current user.
local
low complexity
adobe CWE-668
7.8
2023-01-16 CVE-2022-45438 Exposure of Resource to Wrong Sphere vulnerability in Apache Superset
When explicitly enabling the feature flag DASHBOARD_CACHE (disabled by default), the system allowed for an unauthenticated user to access dashboard configuration metadata using a REST API Get endpoint. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.
network
low complexity
apache CWE-668
5.3
2023-01-14 CVE-2023-22497 Exposure of Resource to Wrong Sphere vulnerability in Netdata
Netdata is an open source option for real-time infrastructure monitoring and troubleshooting.
network
low complexity
netdata CWE-668
critical
9.1