Vulnerabilities > Exposure of Resource to Wrong Sphere

DATE CVE VULNERABILITY TITLE RISK
2018-08-29 CVE-2018-8040 Exposure of Resource to Wrong Sphere vulnerability in multiple products
Pages that are rendered using the ESI plugin can have access to the cookie header when the plugin is configured not to allow access.
network
low complexity
apache debian CWE-668
5.3
2018-08-24 CVE-2017-12576 Exposure of Resource to Wrong Sphere vulnerability in Planex Cs-Qr20 Firmware 1.30
An issue was discovered on the PLANEX CS-QR20 1.30.
network
low complexity
planex CWE-668
7.2
2018-08-06 CVE-2018-7073 Exposure of Resource to Wrong Sphere vulnerability in multiple products
A local arbitrary file modification vulnerability was identified in HPE Moonshot Provisioning Manager prior to v1.24.
local
low complexity
hp canonical CWE-668
5.5
2018-08-06 CVE-2018-7072 Exposure of Resource to Wrong Sphere vulnerability in HP Moonshot Provisioning Manager 1.20
A remote bypass of security restrictions vulnerability was identified in HPE Moonshot Provisioning Manager prior to v1.24.
network
low complexity
hp CWE-668
critical
9.8
2018-04-25 CVE-2018-10361 Exposure of Resource to Wrong Sphere vulnerability in KDE Ktexteditor
An issue was discovered in KTextEditor 5.34.0 through 5.45.0.
local
low complexity
kde CWE-668
7.8
2018-04-13 CVE-2017-0367 Exposure of Resource to Wrong Sphere vulnerability in multiple products
Mediawiki before 1.28.1 / 1.27.2 contains an unsafe use of temporary directory, where having LocalisationCache directory default to system tmp directory is insecure.
network
low complexity
mediawiki debian CWE-668
8.8
2018-04-11 CVE-2017-18129 Exposure of Resource to Wrong Sphere vulnerability in Qualcomm products
In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile and Snapdragon Mobile MDM9206, MDM9607, SD 845, MSM8996, MSM8998, it is possible for IPA (internet protocol accelerator) channels owned by one security domain to be controlled from other domains.
network
low complexity
qualcomm CWE-668
critical
9.8
2018-04-11 CVE-2017-18073 Exposure of Resource to Wrong Sphere vulnerability in Qualcomm products
In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 820, SD 820A, SD 835, the HLOS can gain access to unauthorized memory.
network
low complexity
qualcomm CWE-668
7.5
2018-02-26 CVE-2018-7479 Exposure of Resource to Wrong Sphere vulnerability in Yzmcms 3.6
YzmCMS 3.6 allows remote attackers to discover the full path via a direct request to application/install/templates/s1.php.
network
low complexity
yzmcms CWE-668
5.3
2018-02-13 CVE-2018-6910 Exposure of Resource to Wrong Sphere vulnerability in Dedecms 5.7
DedeCMS 5.7 allows remote attackers to discover the full path via a direct request for include/downmix.inc.php or inc/inc_archives_functions.php.
network
low complexity
dedecms CWE-668
7.5