Vulnerabilities > Exposure of Resource to Wrong Sphere

DATE CVE VULNERABILITY TITLE RISK
2024-02-02 CVE-2023-50328 Exposure of Resource to Wrong Sphere vulnerability in IBM Powersc 1.3/2.0/2.1
IBM PowerSC 1.3, 2.0, and 2.1 may allow a remote attacker to view session identifiers passed via URL query strings.
network
low complexity
ibm CWE-668
5.3
2024-01-31 CVE-2024-21626 Exposure of Resource to Wrong Sphere vulnerability in multiple products
runc is a CLI tool for spawning and running containers on Linux according to the OCI specification.
local
low complexity
linuxfoundation fedoraproject CWE-668
8.6
2024-01-29 CVE-2023-7204 Exposure of Resource to Wrong Sphere vulnerability in Wp-Staging WP Staging
The WP STAGING WordPress Backup plugin before 3.2.0 allows access to cache files during the cloning process which provides
network
low complexity
wp-staging CWE-668
7.5
2024-01-12 CVE-2024-21597 Exposure of Resource to Wrong Sphere vulnerability in Juniper Junos
An Exposure of Resource to Wrong Sphere vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to bypass the intended access restrictions. In an Abstracted Fabric (AF) scenario if routing-instances (RI) are configured, specific valid traffic destined to the device can bypass the configured lo0 firewall filters as it's received in the wrong RI context. This issue affects Juniper Networks Junos OS on MX Series: * All versions earlier than 20.4R3-S9; * 21.2 versions earlier than 21.2R3-S3; * 21.4 versions earlier than 21.4R3-S5; * 22.1 versions earlier than 22.1R3; * 22.2 versions earlier than 22.2R3; * 22.3 versions earlier than 22.3R2.
network
low complexity
juniper CWE-668
7.5
2024-01-12 CVE-2024-0443 Exposure of Resource to Wrong Sphere vulnerability in multiple products
A flaw was found in the blkgs destruction path in block/blk-cgroup.c in the Linux kernel, leading to a cgroup blkio memory leakage problem.
local
low complexity
linux redhat fedoraproject CWE-668
5.5
2024-01-09 CVE-2024-20692 Exposure of Resource to Wrong Sphere vulnerability in Microsoft products
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
network
low complexity
microsoft CWE-668
5.7
2024-01-04 CVE-2024-22049 Exposure of Resource to Wrong Sphere vulnerability in John Nunemaker Httparty
httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability.
network
low complexity
john-nunemaker CWE-668
5.3
2023-12-14 CVE-2023-49342 Exposure of Resource to Wrong Sphere vulnerability in Ubuntubudgie Budgie Extras
Temporary data passed between application components by Budgie Extras Clockworks applet could potentially be viewed or manipulated.
local
low complexity
ubuntubudgie CWE-668
7.8
2023-12-14 CVE-2023-49344 Exposure of Resource to Wrong Sphere vulnerability in Ubuntubudgie Budgie Extras
Temporary data passed between application components by Budgie Extras Window Shuffler applet could potentially be viewed or manipulated.
local
low complexity
ubuntubudgie CWE-668
7.8
2023-12-14 CVE-2023-49345 Exposure of Resource to Wrong Sphere vulnerability in Ubuntubudgie Budgie Extras
Temporary data passed between application components by Budgie Extras Takeabreak applet could potentially be viewed or manipulated.
local
low complexity
ubuntubudgie CWE-668
7.8