runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and e
Software installed and run as a non-privileged user may conduct improper GPU system calls to gain access to the graphics
TorchServe is a flexible and easy-to-use tool for serving and scaling PyTorch models in production. In affected versions
DIRAC is an interware, meaning a software framework for distributed computing. Prior to version 8.0.41, during the proxy
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: qca: fix info leak when fetching fw buil
Exposure of resource to wrong sphere in some Intel(R) DTT software installers may allow an authenticated user to potenti
In the Linux kernel, the following vulnerability has been resolved: locking/qrwlock: Fix ordering in queued_write_lock_
A local attacker with low privileges can read and modify any users files and cause a DoS in the working directory of the
The WP STAGING WordPress Backup plugin before 3.2.0 allows access to cache files during the cloning process which provid
** UNSUPPORTED WHEN ASSIGNED ** The Apache Helix Front (UI) component contained a hard-coded secret, allowing an attacke
Vladimir Kononovich, a Security Researcher has found a flaw that using a inappropriate encryption logic on the DVR. fir
Exposure of resource to wrong sphere in some Intel(R) processors with Intel(R) ACTM may allow a privileged user to poten
In the Linux kernel, the following vulnerability has been resolved: ipack: ipoctal: fix stack information leak The tty
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: qca: fix info leak when fetching board i
In the Linux kernel, the following vulnerability has been resolved: net: fix information leakage in /proc/net/ptype In
In the Linux kernel, the following vulnerability has been resolved: vmci: prevent speculation leaks by sanitizing event
An Exposure of Resource to Wrong Sphere vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS
CWE-668: Exposure of the Resource Wrong Sphere vulnerability exists that exposes a SSH interface over the product networ
An Exposure of Resource to Wrong Sphere vulnerability in the sampling service of Juniper Networks Junos OS Evolved allow
Dell NativeEdge, version(s) 2.1.0.0, contain(s) a Creation of Temporary File With Insecure Permissions vulnerability. A
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
Windows CoreMessaging Information Disclosure Vulnerability
A flaw was found in the blkgs destruction path in block/blk-cgroup.c in the Linux kernel, leading to a cgroup blkio memo
In the Linux kernel, the following vulnerability has been resolved: HID: usbhid: fix info leak in hid_submit_ctrl In h
In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix wq cleanup of WQCFG registers
In the Linux kernel, the following vulnerability has been resolved: fs/mount_setattr: always cleanup mount_kattr Make
In the Linux kernel, the following vulnerability has been resolved: binder: fix async_free_space accounting for empty p
In the Linux kernel, the following vulnerability has been resolved: mm/damon/dbgfs: fix 'struct pid' leaks in 'dbgfs_ta
In the Linux kernel, the following vulnerability has been resolved: tipc: fix kernel warning when sending SYN message
vantage6-UI is the official user interface for the vantage6 server. In affected versions a number of security headers ar
An Exposure of Resource to Wrong Sphere vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos O
The Author Box, Guest Author and Co-Authors for Your Posts – Molongui plugin for WordPress is vulnerable to Sensitive In
A partial fix for CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type b
Moby is an open source container framework that is a key component of Docker Engine, Docker Desktop, and other distribut
wolfictl is a command line tool for working with Wolfi. A git authentication issue in versions prior to 0.16.10 allows a
IBM PowerSC 1.3, 2.0, and 2.1 may allow a remote attacker to view session identifiers passed via URL query strings. IBM
IBM Maximo Asset Management 7.6.1.3 and IBM Maximo Application Suite 8.10 and 8.11 allows web pages to be stored locally
Biscuit is an authorization token with decentralized verification, offline attenuation and strong security policy enforc
Twig is a template language for PHP. In a sandbox, an attacker can call `__toString()` on an object even if the `__toStr
Twig is a template language for PHP. In a sandbox, an attacker can access attributes of Array-like objects as they were
ServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core
The ntpd_driver component before 1.3.0 and 2.x before 2.2.0 for Robot Operating System (ROS) allows attackers, who contr
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8
An issue in WIPOTEC GmbH ComScale v4.3.29.21344 and v4.4.12.723 allows unauthenticated attackers to login as any user wi
Landscape's server-status page exposed sensitive system information. This data leak included GET requests which contain
An issue found in DepositGame v.1.0 allows an attacker to gain sensitive information via the GetBonusWithdraw and withdr
Key management vulnerability on system. Successful exploitation of this vulnerability may affect service availability an
An attacker authenticated as a non-admin user with local access to a server port assigned to the SAP Host Agent (Start S
Minio is a Multi-Cloud Object Storage framework. All users on Windows prior to version RELEASE.2023-03-20T20-16-18Z are
A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that could cause remote code execution when a vali
Frequently Asked Questions
What is CWE-668?
CWE-668 (CWE-668) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-668?
There are 817 CVE records associated with CWE-668 in our database. Of these, 64 are critical severity, 235 are high severity, and 360 are medium severity.
How can I protect against CWE-668 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-668 using AI-powered security agents.
Detect CWE-668 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-668 vulnerabilities across your infrastructure.
Get Started