Vulnerabilities > Exposure of Resource to Wrong Sphere

DATE CVE VULNERABILITY TITLE RISK
2023-01-12 CVE-2022-24913 Exposure of Resource to Wrong Sphere vulnerability in Java-Merge-Sort Project Java-Merge-Sort
Versions of the package com.fasterxml.util:java-merge-sort before 1.1.0 are vulnerable to Insecure Temporary File in the StdTempFileProvider() function in StdTempFileProvider.java, which uses the permissive File.createTempFile() function, exposing temporary file contents.
local
low complexity
java-merge-sort-project CWE-668
5.5
2023-01-11 CVE-2021-26343 Exposure of Resource to Wrong Sphere vulnerability in AMD products
Insufficient validation in ASP BIOS and DRTM commands may allow malicious supervisor x86 software to disclose the contents of sensitive memory which may result in information disclosure.
local
low complexity
amd CWE-668
5.5
2023-01-10 CVE-2023-21536 Exposure of Resource to Wrong Sphere vulnerability in Microsoft products
Event Tracing for Windows Information Disclosure Vulnerability
local
high complexity
microsoft CWE-668
4.7
2023-01-06 CVE-2018-25068 Exposure of Resource to Wrong Sphere vulnerability in Globalpom-Utils Project Globalpom-Utils
A vulnerability has been found in devent globalpom-utils up to 4.5.0 and classified as critical.
network
low complexity
globalpom-utils-project CWE-668
critical
9.8
2023-01-06 CVE-2022-45935 Exposure of Resource to Wrong Sphere vulnerability in Apache James
Usage of temporary files with insecure permissions by the Apache James server allows an attacker with local access to access private user data in transit.
local
low complexity
apache CWE-668
5.5
2023-01-02 CVE-2022-0337 Exposure of Resource to Wrong Sphere vulnerability in Google Chrome
Inappropriate implementation in File System API in Google Chrome on Windows prior to 97.0.4692.71 allowed a remote attacker to obtain potentially sensitive information via a crafted HTML page.
network
low complexity
google CWE-668
6.5
2023-01-01 CVE-2022-48198 Exposure of Resource to Wrong Sphere vulnerability in Ntpd Driver Project Ntpd Driver
The ntpd_driver component before 1.3.0 and 2.x before 2.2.0 for Robot Operating System (ROS) allows attackers, who control the source code of a different node in the same ROS application, to change a robot's behavior.
network
low complexity
ntpd-driver-project CWE-668
critical
9.8
2022-12-28 CVE-2022-4817 Exposure of Resource to Wrong Sphere vulnerability in Jgit-Cookbook Project Jgit-Cookbook
A vulnerability was found in centic9 jgit-cookbook.
local
low complexity
jgit-cookbook-project CWE-668
7.8
2022-12-27 CVE-2015-10004 Exposure of Resource to Wrong Sphere vulnerability in Json web Token Project Json web Token
Token validation methods are susceptible to a timing side-channel during HMAC comparison.
network
low complexity
json-web-token-project CWE-668
7.5
2022-12-26 CVE-2019-9011 Exposure of Resource to Wrong Sphere vulnerability in Pilz PMC 3.0.0
In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), an attacker can identify valid usernames.
network
low complexity
pilz CWE-668
5.3