Vulnerabilities > Incorrect Resource Transfer Between Spheres

DATE CVE VULNERABILITY TITLE RISK
2021-01-19 CVE-2020-27268 Incorrect Resource Transfer Between Spheres vulnerability in Sooil products
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a client-side control vulnerability in the insulin pump and its AnyDana-i and AnyDana-A mobile applications allows physically proximate attackers to bypass checks for default PINs via Bluetooth Low Energy.
low complexity
sooil CWE-669
6.5
2020-12-22 CVE-2020-24683 Incorrect Resource Transfer Between Spheres vulnerability in ABB Symphony + Historian and Symphony + Operations
The affected versions of S+ Operations (version 2.1 SP1 and earlier) used an approach for user authentication which relies on validation at the client node (client-side authentication).
network
low complexity
abb CWE-669
critical
9.8
2020-12-18 CVE-2020-26177 Incorrect Resource Transfer Between Spheres vulnerability in Tangro Business Workflow 1.17.5
In tangro Business Workflow before 1.18.1, a user's profile contains some items that are greyed out and thus are not intended to be edited by regular users.
network
low complexity
tangro CWE-669
4.3
2020-12-07 CVE-2020-5800 Incorrect Resource Transfer Between Spheres vulnerability in EAT Spray Love Project EAT Spray Love 2.0.20
The Eat Spray Love mobile app for both iOS and Android contains logic that allows users to bypass authentication and retrieve or modify information that they would not normally have access to.
network
low complexity
eat-spray-love-project CWE-669
critical
9.8
2020-08-11 CVE-2020-10778 Incorrect Resource Transfer Between Spheres vulnerability in Redhat Cloudforms 4.7/5.0.0
In Red Hat CloudForms 4.7 and 5, the read only widgets can be edited by inspecting the forms and dropping the disabled attribute from the fields since there is no server-side validation.
network
low complexity
redhat CWE-669
6.0
2020-07-22 CVE-2020-15892 Incorrect Resource Transfer Between Spheres vulnerability in Dlink Dap-1520 Firmware 1.0.8/1.10B04
An issue was discovered in apply.cgi on D-Link DAP-1520 devices before 1.10b04Beta02.
network
low complexity
dlink CWE-669
critical
9.8
2020-05-21 CVE-2020-1048 Incorrect Resource Transfer Between Spheres vulnerability in Microsoft products
An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system, aka 'Windows Print Spooler Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-669
7.8
2020-01-17 CVE-2020-6862 Incorrect Resource Transfer Between Spheres vulnerability in ZTE F6X2W Firmware 6.0.10P2T2/6.0.10P2T5
V6.0.10P2T2 and V6.0.10P2T5 of F6x2W product are impacted by Information leak vulnerability.
network
low complexity
zte CWE-669
5.3
2019-11-01 CVE-2012-2979 Incorrect Resource Transfer Between Spheres vulnerability in Freebsd Name Server Daemon
FreeBSD NSD before 3.2.13 allows remote attackers to crash a NSD child server process (SIGSEGV) and cause a denial of service in the NSD server.
network
low complexity
freebsd CWE-669
7.5
2019-10-02 CVE-2019-13025 Incorrect Resource Transfer Between Spheres vulnerability in Compal Ch7465Lg Firmware Ch7465Lgncip6.12.18.245P8Nosh
Compal CH7465LG CH7465LG-NCIP-6.12.18.24-5p8-NOSH devices have Incorrect Access Control because of Improper Input Validation.
network
low complexity
compal CWE-669
critical
9.8