Vulnerabilities > Incorrect Resource Transfer Between Spheres

DATE CVE VULNERABILITY TITLE RISK
2020-05-21 CVE-2020-1048 Incorrect Resource Transfer Between Spheres vulnerability in Microsoft products
An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system, aka 'Windows Print Spooler Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-669
7.8
2020-01-17 CVE-2020-6862 Incorrect Resource Transfer Between Spheres vulnerability in ZTE F6X2W Firmware 6.0.10P2T2/6.0.10P2T5
V6.0.10P2T2 and V6.0.10P2T5 of F6x2W product are impacted by Information leak vulnerability.
network
low complexity
zte CWE-669
5.3
2019-11-01 CVE-2012-2979 Incorrect Resource Transfer Between Spheres vulnerability in Freebsd Name Server Daemon
FreeBSD NSD before 3.2.13 allows remote attackers to crash a NSD child server process (SIGSEGV) and cause a denial of service in the NSD server.
network
low complexity
freebsd CWE-669
7.5
2019-10-02 CVE-2019-13025 Incorrect Resource Transfer Between Spheres vulnerability in Compal Ch7465Lg Firmware Ch7465Lgncip6.12.18.245P8Nosh
Compal CH7465LG CH7465LG-NCIP-6.12.18.24-5p8-NOSH devices have Incorrect Access Control because of Improper Input Validation.
network
low complexity
compal CWE-669
critical
9.8
2019-09-05 CVE-2019-10753 Incorrect Resource Transfer Between Spheres vulnerability in Diffplug Eclipse-Cdt, Eclipse-Groovy and Eclipse-Wtp
In all versions prior to version 3.9.6 for eclipse-wtp, all versions prior to version 9.4.4 for eclipse-cdt, and all versions prior to version 3.0.1 for eclipse-groovy, Spotless was resolving dependencies over an insecure channel (http).
network
high complexity
diffplug CWE-669
5.9
2019-08-27 CVE-2019-13266 Incorrect Resource Transfer Between Spheres vulnerability in Tp-Link Archer C2 V1 Firmware and Archer C3200 V1 Firmware
TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device.
low complexity
tp-link CWE-669
8.8
2019-08-27 CVE-2019-13263 Incorrect Resource Transfer Between Spheres vulnerability in Dlink Dir-825/Ac G1 Firmware
D-link DIR-825AC G1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device.
low complexity
dlink CWE-669
8.8
2019-08-21 CVE-2018-17791 Incorrect Resource Transfer Between Spheres vulnerability in Newgensoft Omniflow Intelligent Business Process Suite 7.0
Newgen OmniFlow Intelligent Business Process Suite (iBPS) 7.0 has an "improper server side validation" vulnerability where client-side validations are tampered, and inappropriate information is stored on the server side and fetched from the server every time the user visits the D, creating business confusion.
network
low complexity
newgensoft CWE-669
7.5
2019-07-29 CVE-2019-1020011 Incorrect Resource Transfer Between Spheres vulnerability in Charcoal-Se Smokedetector
SmokeDetector intentionally does automatic deployments of updated copies of SmokeDetector without server operator authority.
network
low complexity
charcoal-se CWE-669
7.2
2019-06-14 CVE-2019-11770 Incorrect Resource Transfer Between Spheres vulnerability in Eclipse Buildship
In Eclipse Buildship versions prior to 3.1.1, the build files indicate that this project is resolving dependencies over HTTP instead of HTTPS.
network
high complexity
eclipse CWE-669
8.1