Vulnerabilities > Exposure of Resource to Wrong Sphere

DATE CVE VULNERABILITY TITLE RISK
2021-04-09 CVE-2021-25364 Exposure of Resource to Wrong Sphere vulnerability in Google Android 11.0
A pendingIntent hijacking vulnerability in Secure Folder prior to SMR APR-2021 Release 1 allows unprivileged applications to access contact information.
local
low complexity
google CWE-668
3.3
2021-04-09 CVE-2021-25357 Exposure of Resource to Wrong Sphere vulnerability in Google Android 8.1/9.0
A pendingIntent hijacking vulnerability in Create Movie prior to SMR APR-2021 Release 1 in Android O(8.x) and P(9.0), 3.4.81.1 in Android Q(10,0), and 3.6.80.7 in Android R(11.0) allows unprivileged applications to access contact information.
local
low complexity
google CWE-668
5.5
2021-03-25 CVE-2020-10581 Exposure of Resource to Wrong Sphere vulnerability in Invigo Automatic Device Management 5.0
Multiple session validity check issues in several administration functionalities of Invigo Automatic Device Management (ADM) through 5.0 allow remote attackers to read potentially sensitive data hosted by the application.
network
low complexity
invigo CWE-668
7.5
2021-03-25 CVE-2021-25352 Exposure of Resource to Wrong Sphere vulnerability in Samsung Bixby Voice
Using PendingIntent with implicit intent in Bixby Voice prior to version 3.0.52.14 allows attackers to execute privileged action by hijacking and modifying the intent.
local
low complexity
samsung CWE-668
7.8
2021-03-24 CVE-2021-1423 Exposure of Resource to Wrong Sphere vulnerability in Cisco products
A vulnerability in the implementation of a CLI command in Cisco Aironet Access Points (AP) could allow an authenticated, local attacker to overwrite files in the flash memory of the device.
local
low complexity
cisco CWE-668
4.4
2021-02-26 CVE-2021-23958 Exposure of Resource to Wrong Sphere vulnerability in Mozilla Firefox
The browser could have been confused into transferring a screen sharing state into another tab, which would leak unintended information.
network
low complexity
mozilla CWE-668
6.5
2021-02-16 CVE-2021-27236 Exposure of Resource to Wrong Sphere vulnerability in Mutare Voice 3.0.0/3.2.6/3.3.7
An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8.
network
low complexity
mutare CWE-668
critical
9.8
2021-02-04 CVE-2020-27872 Exposure of Resource to Wrong Sphere vulnerability in Netgear products
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7450 1.2.0.62_1.0.1 routers.
low complexity
netgear CWE-668
8.8
2021-01-08 CVE-2020-26186 Exposure of Resource to Wrong Sphere vulnerability in Dell Inspiron 5675 Firmware
Dell Inspiron 5675 BIOS versions prior to 1.4.1 contain a UEFI BIOS RuntimeServices overwrite vulnerability.
low complexity
dell CWE-668
6.8
2020-12-29 CVE-2020-16268 Exposure of Resource to Wrong Sphere vulnerability in 1E Client 4.1.0.267/5.0.0.745
The MSI installer in 1E Client 4.1.0.267 and 5.0.0.745 allows remote authenticated users and local users to gain elevated privileges via the repair option.
network
low complexity
1e CWE-668
8.8