Information disclosure in Kernel due to indirect branch misprediction.
Information disclosure in Linux Networking Firmware due to unauthorized information leak during side channel analysis.
An information disclosure vulnerability exists in SAP Landscape Management - version 3.0, enterprise edition. It allows
Exposure of data element to wrong session in the Intel DCM software before version 5.0.1 may allow an authenticated user
An issue was discovered in TechView LA-5570 Wireless Gateway 1.0.19_T53, allows physical attackers to gain escalated pri
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pandora FMS on all allows File Discovery. Th
Dell PowerScale OneFS 9.4.0.x contains exposure of sensitive information to an unauthorized actor. A malicious authenti
Inappropriate implementation in File System API in Google Chrome on Windows prior to 97.0.4692.71 allowed a remote attac
Netdata is an open source option for real-time infrastructure monitoring and troubleshooting. Each Netdata Agent has an
A vulnerability exists which allows an authenticated attacker to access sensitive information on the ArubaOS command lin
Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect s
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Mattermost allows an attacker to request a preview of an existing message when creating a new message via the createPost
An issue has been discovered in GitLab affecting all versions starting from 13.11 before 15.8.5, all versions starting f
Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache
Some API routes exists in Control ID IDSecure 4.7.26.0 and prior, exfiltrating sensitive information and passwords to us
An information leak in Camp Style Project Line v13.6.1 allows attackers to obtain the channel access token and send craf
An information leak in Cheese Cafe Line v13.6.1 allows attackers to obtain the channel access token and send crafted mes
An information leak in YKC Tokushima_awayokocho Line v13.6.1 allows attackers to obtain the channel access token and sen
An information leak in THE_B_members card v13.6.1 allows attackers to obtain the channel access token and send crafted m
An information leak in TonTon-Tei_waiting Line v13.6.1 allows attackers to obtain the channel access token and send craf
An information leak in youmart-tokunaga v13.6.1 allows attackers to obtain the channel access token and send crafted mes
An information leak in Coffee-jumbo v13.6.1 allows attackers to obtain the channel access token and send crafted message
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
Apache Airflow, in versions prior to 2.7.2, contains a security vulnerability that allows an authenticated user with lim
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in ver
Open Management Infrastructure Information Disclosure Vulnerability
PowerShell Information Disclosure Vulnerability
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x befo
Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and pri
An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting fr
A vulnerability has been found in devent globalpom-utils up to 4.5.0 and classified as critical. This vulnerability affe
Missing Password Field Masking vulnerability in Mitsubishi Electric Corporation EtherNet/IP configuration tools SW1DNN-E
An information disclosure vulnerability in the faye endpoint in Proofpoint Threat Response / Threat Response Auto-Pull (
The vulnerability is to theft of arbitrary files with system privilege in the LockScreenSettings ("com.lge.lockscreenset
The vulnerability is to theft of arbitrary files with system privilege in the Screen recording ("com.lge.gametools.gamer
Temporary data passed between application components by Budgie Extras Clockworks applet could potentially be viewed or m
Temporary data passed between application components by Budgie Extras Dropby applet could potentially be viewed or manip
Temporary data passed between application components by Budgie Extras Window Shuffler applet could potentially be viewed
Temporary data passed between application components by Budgie Extras Takeabreak applet could potentially be viewed or m
Temporary data passed between application components by Budgie Extras WeatherShow applet could potentially be viewed or
Temporary data passed between application components by Budgie Extras Windows Previews could potentially be viewed or ma
IBM Aspera Faspex 5.0.5 does not restrict or incorrectly restricts access to a resource from an unauthorized actor. IBM
Usage of temporary files with insecure permissions by the Apache James server allows an attacker with local access to ac
Insufficient validation in ASP BIOS and DRTM commands may allow malicious supervisor x86 software to disclose the conten
Versions of the package com.fasterxml.util:java-merge-sort before 1.1.0 are vulnerable to Insecure Temporary File in the
Improper access control vulnerability in MyFiles prior to versions 12.2.09 in Android R(11), 13.1.03.501 in Android S(12
Frequently Asked Questions
What is CWE-668?
CWE-668 (CWE-668) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-668?
There are 817 CVE records associated with CWE-668 in our database. Of these, 64 are critical severity, 235 are high severity, and 360 are medium severity.
How can I protect against CWE-668 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-668 using AI-powered security agents.
Detect CWE-668 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-668 vulnerabilities across your infrastructure.
Get Started