Vulnerabilities > Exposure of Resource to Wrong Sphere

DATE CVE VULNERABILITY TITLE RISK
2022-04-12 CVE-2022-24411 Exposure of Resource to Wrong Sphere vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS 8.2.2 and above contain an elevation of privilege vulnerability.
local
low complexity
dell CWE-668
7.8
2022-04-12 CVE-2021-42255 Exposure of Resource to Wrong Sphere vulnerability in Blueplanet-Works Appguard
AppGuard Enterprise before 6.7.100.1 creates a Temporary File in a Directory with Insecure Permissions.
local
low complexity
blueplanet-works CWE-668
7.8
2022-04-11 CVE-2022-27576 Exposure of Resource to Wrong Sphere vulnerability in Google Android 10.0/11.0/12.0
Information exposure vulnerability in Samsung DeX Home prior to SMR April-2022 Release 1 allows to access currently launched foreground app information without permission
local
low complexity
google CWE-668
3.3
2022-04-11 CVE-2022-27822 Exposure of Resource to Wrong Sphere vulnerability in Google Android 10.0/11.0/12.0
Information exposure vulnerability in ril property setting prior to SMR April-2022 Release 1 allows access to EF_RUIMID value without permission.
local
low complexity
google CWE-668
5.5
2022-04-07 CVE-2022-27818 Exposure of Resource to Wrong Sphere vulnerability in Waycrate Swhkd 1.1.5
SWHKD 1.1.5 unsafely uses the /tmp/swhkd.sock pathname.
network
low complexity
waycrate CWE-668
critical
9.1
2022-04-06 CVE-2022-26850 Exposure of Resource to Wrong Sphere vulnerability in Apache Nifi 1.14.0/1.15.0/1.15.3
When creating or updating credentials for single-user access, Apache NiFi wrote a copy of the Login Identity Providers configuration to the operating system temporary directory.
network
low complexity
apache CWE-668
4.3
2022-03-30 CVE-2022-27772 Exposure of Resource to Wrong Sphere vulnerability in VMWare Spring Boot
spring-boot versions prior to version v2.2.11.RELEASE was vulnerable to temporary directory hijacking.
local
low complexity
vmware CWE-668
7.8
2022-03-30 CVE-2021-39777 Exposure of Resource to Wrong Sphere vulnerability in Google Android 12.0
In Telephony, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check.
local
low complexity
google CWE-668
5.5
2022-03-29 CVE-2021-22572 Exposure of Resource to Wrong Sphere vulnerability in Google Data Transfer Project
On unix-like systems, the system temporary directory is shared between all users on that system.
local
low complexity
google CWE-668
5.5
2022-03-29 CVE-2022-28160 Exposure of Resource to Wrong Sphere vulnerability in Jenkins Tests Selector
Jenkins Tests Selector Plugin 1.3.3 and earlier allows users with Item/Configure permission to read arbitrary files on the Jenkins controller.
network
low complexity
jenkins CWE-668
6.5