Skip to main content

Threats Tagged 'cwe-668'

View all threats tagged with 'cwe-668'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-668

Threats Tagged 'cwe-668'

Click on any threat for detailed analysis and mitigation recommendations

Improper Exposure of Resource to Wrong Sphere in the host file helper (gofer) in Google gVisor prior to commit 573a9e73cf844f on Linux platforms with CUSE enabled allows a local attacker with container image deployment privileges to achieve root code execution on the host system. By including a /dev/cuse character device node in a container image, opening the device passes through to the host, allowing the sandboxed attacker to register a host device and exploit CUSE unrestricted ioctl handling to overwrite root udev helper memory.

Join the discussion

When implementing the JavaScript interface, Foxit PDF Editor/Reader did not perform the attribute authorization checks required by the specification. As a result, a trusted malicious PDF could potentially access sensitive content from other documents within the same process and transmit it externally.

Join the discussion

CVE-2026-86551 is a low-severity vulnerability in the ZTE NX741J (Z80Ultra) device where non-privileged applications can access the Wi-Fi MAC address by querying a read-only field in the Settings.Secure database. This exposure is classified under CWE-668, indicating exposure of a resource to an unintended sphere. The vulnerability does not allow modification or denial of service and requires user interaction to exploit.

Join the discussion

CVE-2026-54495 is a medium-severity vulnerability in the open-feature-operator (version 0.9.2 and earlier) that allows a tenant with permission to create a controller-owned workload to reference feature flag resources in other namespaces. This can lead to exposure of environment variables, bearer tokens, sync URIs, and ConfigMaps from other tenants in multi-tenant Kubernetes clusters that use namespaces as trust boundaries. Single-tenant clusters are not affected, and secretKeyRef and configMapKeyRef values remain namespace-local.

Join the discussion

MCP Documentation Server is a local-first document management and semantic search server for AI coding agents. From 1.13.0 until 1.13.1, the automatically started Web UI in src/server.ts calls startWebServer in src/web-server.ts with START_WEB_UI enabled by default and WEB_PORT set to 3080. startWebServer uses app.listen(PORT) without a host, which binds the unauthenticated document-management API to all interfaces rather than localhost. A network-reachable client can invoke GET /api/documents, GET /api/documents/:id, POST /api/documents, POST /api/search-all, DELETE /api/documents/:id, and GET /api/config without credentials to enumerate and read documents, search the corpus, insert or delete documents, and tamper with the MCP assistant's knowledge base. The service must be reachable from the attacker's LAN, VM network, container bridge, VPN, or another routed network, and the issue does not provide remote code execution. This issue is fixed in 1.13.1.

Join the discussion

mport is the MidnightBSD Package Manager. Prior to 2.7.8, package installation lacked a preflight check for incoming non-directory assets that already existed on disk. The affected logic across libmport/check_preconditions.c, libmport/install_primative.c, and libmport/mport_private.h did not apply MPORT_PRECHECK_FILE_CONFLICTS, so a crafted or conflicting package could overwrite a file owned by another package or unmanaged by mport. The check is bypassed only when the operator explicitly enables mport->force. Privileged installation without that override could compromise local filesystem integrity and package database consistency. This issue is fixed in version 2.7.8.

Join the discussion

A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. A WebSocket service was configured to listen on all network interfaces, which may expose the service to unintended network access.

Join the discussion

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, djust's observability endpoints expose live view/session state and a remote method-invocation surface (`eval_handler`). The localhost restriction was an opt-in middleware that the documented setup omits; the views themselves enforced only `DEBUG`. In the misconfigured-but-documented scenario (DEBUG on, middleware not installed) a non-localhost client could read live application state and invoke handlers remotely. This issue is fixed in djust 1.0.7. The localhost restriction is enforced in-view on every observability endpoint (no longer dependent on a separately-installed middleware), and `eval_handler` is restricted; gated requests receive a non-disclosing response. As a workaround, ensure `DEBUG=False` in production, and do not expose the observability endpoints to untrusted networks.

Join the discussion

CVE-2026-47844 is a medium severity vulnerability in Spring's Reactor Netty HTTP Server where exception details may be leaked across unrelated requests when the server is configured with Brave Tracing. This affects certain versions of Reactor Netty including 1.3.0 to 1.3.6, 1.1.0 to 1.2.18, and 1.0.52 and earlier. The vulnerability is classified under CWE-668, which involves exposure of resources to the wrong sphere. No official patch or remediation guidance has been provided yet.

Join the discussion

CVE-2026-53657 is a vulnerability in lima-vm's lima product versions prior to 2.1.3. When running with the qemu driver and the guest agent enabled, an arbitrary user inside the VM can access the guest agent socket (/run/lima-guestagent.sock), potentially allowing execution of arbitrary commands with root privileges inside the VM. This issue does not affect the vz driver, which uses vsocks instead of Unix sockets. The vulnerability is patched in version 2.1.3. The default user in the VM can already run commands as root via sudo, so this behavior is not considered a vulnerability by design. Workarounds include using the vz driver or disabling the guest agent.

Join the discussion

Showing 1 to 10 of 61 results

Filters:Tag: cwe-668
Page 1 of 7
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses