HTTP.sys Information Disclosure Vulnerability
Microsoft Office Information Disclosure Vulnerability
The issue was addressed with improved memory handling This issue is fixed in macOS Ventura 13.2. An app may be able to d
Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability
Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability
KYOCERA Mobile Print' v3.2.0.230119 and earlier, 'UTAX/TA MobilePrint' v3.2.0.230119 and earlier, and 'Olivetti Mobile P
Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.4 allows local attacker to retrieve passwords
An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to a
Sensitive information disclosure due to excessive collection of system information. The following products are affected:
A vulnerability has been identified in SIMATIC PCS neo (Administration Console) V4.0 (All versions), SIMATIC PCS neo (Ad
Cadence through 0.9.2 2023-08-21 uses an Insecure /tmp/.cadence-aloop-daemon.x Temporary File. The file is used even if
An information disclosure vulnerability exists in the CtEnumCa() functionality of SoftEther VPN 4.41-9782-beta and 5.01.
A flaw was found In 3Scale Admin Portal. If a user logs out from the personal tokens page and then presses the back butt
Use of implicit intent for sensitive communication vulnerability in startAgreeToDisclaimerActivity in Samsung Account pr
Use of implicit intent for sensitive communication vulnerability in startEmailValidationActivity in Samsung Account prio
Use of implicit intent for sensitive communication vulnerability in startNameValidationActivity in Samsung Account prior
Use of implicit intent for sensitive communication vulnerability in startTncActivity in Samsung Account prior to version
In telephony service, there is a possible missing permission check. This could lead to local information disclosure with
In dialer, there is a possible way to write permission usage records of an app due to a missing permission check. This c
When explicitly enabling the feature flag DASHBOARD_CACHE (disabled by default), the system allowed for an unauthenticat
AMI MegaRAC SPX devices allow User Enumeration through Redfish. The fixed versions are SPx12-update-7.00 and SPx13-updat
Inclusion of Sensitive Information in Source Code in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 110021
An issue was discovered in KaiOS 3.0 and 3.1. The binary /system/kaios/api-daemon exposes a local web server on *.localh
emoncms v11 and later was discovered to contain an information disclosure vulnerability which allows attackers to obtain
DHCP Server Service Information Disclosure Vulnerability
Vulnerability of kernel raw address leakage in the hang detector module. Successful exploitation of this vulnerability
eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/re
Jenkins Chef Identity Plugin 2.0.3 and earlier does not mask the user.pem key form field, increasing the potential for a
Exposure of Sensitive Information vulnerability in AcyMailing Enterprise component for Joomla. It allows unauthorized ac
A vulnerability has been identified in ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, which has t
DHCP Server Service Information Disclosure Vulnerability
SpringBlade <=V3.6.0 is vulnerable to Incorrect Access Control due to incorrect configuration in the default gateway res
The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to a source code disclosure vulnerability. A
Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability can cau
A vulnerability was found in CodenameOne 7.0.70. It has been classified as problematic. Affected is an unknown function.
OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 may expose sensitive information to an unauthorize
An authenticated information disclosure vulnerability exists in the ArubaOS web-based management interface. Successful e
Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 o
Event Tracing for Windows Information Disclosure Vulnerability
Windows Kernel Information Disclosure Vulnerability
Dell BSAFE SSL-J, versions before 6.5 and version 7.0 contain a debug message revealing unnecessary information vulne
An information disclosure vulnerability was identified in GitHub Enterprise Server that allowed private repositories to
The course participation report required additional checks to prevent roles being displayed which the user did not have
Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not
When running in a High Availability configuration, Mattermost fails to sanitize some of the user_updated and post_delete
An issue was discovered in the VisualEditor extension in MediaWiki before 1.31.13, and 1.32.x through 1.35.x before 1.35
Under certain circumstances, a ServiceWorker's offline cache may have leaked to the file system when using private brows
Under specific circumstances a WebExtension may have received a <code>jar:file:///</code> URI instead of a <code>moz-ext
A security defect was discovered in Foundry job-tracker that enabled users to query metadata related to builds on resour
A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) message processing feature of Cisco Jabber coul
Frequently Asked Questions
What is CWE-668?
CWE-668 (CWE-668) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-668?
There are 817 CVE records associated with CWE-668 in our database. Of these, 64 are critical severity, 235 are high severity, and 360 are medium severity.
How can I protect against CWE-668 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-668 using AI-powered security agents.
Detect CWE-668 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-668 vulnerabilities across your infrastructure.
Get Started