Vulnerabilities > Exposure of Resource to Wrong Sphere

DATE CVE VULNERABILITY TITLE RISK
2021-04-22 CVE-2021-28168 Exposure of Resource to Wrong Sphere vulnerability in multiple products
Eclipse Jersey 2.28 to 2.33 and Eclipse Jersey 3.0.0 to 3.0.1 contains a local information disclosure vulnerability.
local
low complexity
eclipse oracle CWE-668
5.5
2021-04-16 CVE-2021-22539 Exposure of Resource to Wrong Sphere vulnerability in Google Bazel
An attacker can place a crafted JSON config file into the project folder pointing to a custom executable.
local
low complexity
google CWE-668
7.8
2021-04-09 CVE-2021-25364 Exposure of Resource to Wrong Sphere vulnerability in Google Android 11.0
A pendingIntent hijacking vulnerability in Secure Folder prior to SMR APR-2021 Release 1 allows unprivileged applications to access contact information.
local
low complexity
google CWE-668
3.3
2021-04-09 CVE-2021-25357 Exposure of Resource to Wrong Sphere vulnerability in Google Android 8.1/9.0
A pendingIntent hijacking vulnerability in Create Movie prior to SMR APR-2021 Release 1 in Android O(8.x) and P(9.0), 3.4.81.1 in Android Q(10,0), and 3.6.80.7 in Android R(11.0) allows unprivileged applications to access contact information.
local
low complexity
google CWE-668
5.5
2021-03-25 CVE-2020-10581 Exposure of Resource to Wrong Sphere vulnerability in Invigo Automatic Device Management 5.0
Multiple session validity check issues in several administration functionalities of Invigo Automatic Device Management (ADM) through 5.0 allow remote attackers to read potentially sensitive data hosted by the application.
network
low complexity
invigo CWE-668
7.5
2021-03-25 CVE-2021-25352 Exposure of Resource to Wrong Sphere vulnerability in Samsung Bixby Voice
Using PendingIntent with implicit intent in Bixby Voice prior to version 3.0.52.14 allows attackers to execute privileged action by hijacking and modifying the intent.
local
low complexity
samsung CWE-668
7.8
2021-03-24 CVE-2021-1423 Exposure of Resource to Wrong Sphere vulnerability in Cisco products
A vulnerability in the implementation of a CLI command in Cisco Aironet Access Points (AP) could allow an authenticated, local attacker to overwrite files in the flash memory of the device.
local
low complexity
cisco CWE-668
4.4
2021-02-26 CVE-2021-23958 Exposure of Resource to Wrong Sphere vulnerability in Mozilla Firefox
The browser could have been confused into transferring a screen sharing state into another tab, which would leak unintended information.
network
low complexity
mozilla CWE-668
6.5
2021-02-16 CVE-2021-27236 Exposure of Resource to Wrong Sphere vulnerability in Mutare Voice 3.0.0/3.2.6/3.3.7
An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8.
network
low complexity
mutare CWE-668
critical
9.8
2021-02-04 CVE-2020-27872 Exposure of Resource to Wrong Sphere vulnerability in Netgear products
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7450 1.2.0.62_1.0.1 routers.
low complexity
netgear CWE-668
8.8