Vulnerabilities > Exposure of Resource to Wrong Sphere

DATE CVE VULNERABILITY TITLE RISK
2021-06-22 CVE-2020-18646 Exposure of Resource to Wrong Sphere vulnerability in 5None Nonecms 1.3.0
Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/public/index.php".
network
low complexity
5none CWE-668
7.5
2021-06-22 CVE-2020-18647 Exposure of Resource to Wrong Sphere vulnerability in 5None Nonecms 1.3.0
Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/nonecms/vendor".
network
low complexity
5none CWE-668
7.5
2021-06-22 CVE-2021-0542 Exposure of Resource to Wrong Sphere vulnerability in Google Android 11.0
In updateNotification of BeamTransferManager.java, there is a missing permission check.
local
low complexity
google CWE-668
5.5
2021-06-11 CVE-2019-9475 Exposure of Resource to Wrong Sphere vulnerability in Google Android 10.0
In /proc/net of the kernel filesystem, there is a possible information leak due to a permissions bypass.
local
low complexity
google CWE-668
5.5
2021-06-11 CVE-2021-22897 Exposure of Resource to Wrong Sphere vulnerability in multiple products
curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake in the code for CURLOPT_SSL_CIPHER_LIST when libcurl is built to use the Schannel TLS library.
network
low complexity
haxx oracle netapp siemens splunk CWE-668
5.3
2021-06-10 CVE-2021-34539 Exposure of Resource to Wrong Sphere vulnerability in Cubecoders AMP
An issue was discovered in CubeCoders AMP before 2.1.1.8.
network
low complexity
cubecoders CWE-668
7.2
2021-06-09 CVE-2020-24511 Exposure of Resource to Wrong Sphere vulnerability in multiple products
Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
local
low complexity
intel debian netapp CWE-668
6.5
2021-06-09 CVE-2021-33669 Exposure of Resource to Wrong Sphere vulnerability in SAP Mobile SDK Certificate Provider 3.0.7
Under certain conditions, SAP Mobile SDK Certificate Provider allows a local unprivileged attacker to exploit an insecure temporary file storage.
local
low complexity
sap CWE-668
7.8
2021-06-08 CVE-2021-22549 Exposure of Resource to Wrong Sphere vulnerability in Google Asylo
An attacker can modify the address to point to trusted memory to overwrite arbitrary trusted memory.
local
low complexity
google CWE-668
7.8
2021-06-08 CVE-2021-22550 Exposure of Resource to Wrong Sphere vulnerability in Google Asylo
An attacker can modify the pointers in enclave memory to overwrite arbitrary memory addresses within the secure enclave.
local
low complexity
google CWE-668
7.8