AppGuard Enterprise before 6.7.100.1 creates a Temporary File in a Directory with Insecure Permissions. Local users can
Dell PowerScale OneFS 8.2.2 and above contain an elevation of privilege vulnerability. A local attacker with ISI_PRIV_LO
Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.801 allows a local, low privileged, attacker
In IOBit Advanced System Care (AscService.exe) 15, an attacker with SEImpersonatePrivilege can create a named pipe with
Password vault has a External Control of System or Configuration Setting vulnerability.Successful exploitation of this v
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vul
Thinfinity VirtualUI 2.1.28.0, 2.1.32.1 and 2.5.26.2, fixed in version 3.0 is affected by an information disclosure vuln
Information Disclosure vulnerability in file module of Drupal Core allows an attacker to gain access to the file metadat
The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the "GitBlee
ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to acce
Insecure Temporary File in GitHub repository horovod/horovod prior to 0.24.0.
ownCloud owncloud/core before 10.10.0 Improperly Removes Sensitive Information Before Storage or Transfer.
A vulnerability in live_check.shtml of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to obtain sensitive router
A vulnerability in live_mfg.shtml of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to obtain sensitive router in
An issue was discovered in function sync_tree in hetero_decision_tree_guest.py in WeBank FATE (Federated AI Technology E
Under special integration scenario of SAP Business one and SAP HANA - version 10.0, an attacker can exploit HANA cockpit
An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows attackers to obtain usernames and passwords via v
A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This fl
In Keylime before 6.3.0, Revocation Notifier uses a fixed /tmp path for UNIX domain socket which can allow unprivileged
The deployment script in the unsupported "OpenShift Extras" set of add-on scripts, in Red Hat Openshift 1, installs a de
Token validation methods are susceptible to a timing side-channel during HMAC comparison. With a large enough number of
Windows OS can be configured to overlay a “language bar” on top of any application. When this OS functionality is enable
Unauthenticated Sensitive Information Disclosure vulnerability in WP Libre Form 2 plugin <= 2.0.8 at WordPress allows at
The package com.github.samtools:htsjdk before 3.0.1 are vulnerable to Creation of Temporary File in Directory with Insec
In a Junos Fusion scenario an External Control of Critical State Data vulnerability in the Satellite Device (SD) control
Information exposure vulnerability in ril property setting prior to SMR April-2022 Release 1 allows access to EF_RUIMID
Improper handling of resource allocation in virtual machines can lead to information exposure in Snapdragon Consumer IOT
Ericsson Network Manager (ENM) before 21.2 has incorrect access-control behavior (that only affects the level of access
Improper access control vulnerability in McAfee WebAdvisor Chrome and Edge browser extensions up to 8.1.0.1895 allows a
Jenkins Tests Selector Plugin 1.3.3 and earlier allows users with Item/Configure permission to read arbitrary files on t
An information disclosure vulnerability in UniverSIS-Students before v1.5.0 allows attackers to obtain sensitive informa
Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to in
Inappropriate implementation in Extensions in Google Chrome prior to 100.0.4896.60 allowed an attacker who convinced a u
Inappropriate implementation in iframe in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to leak cross-o
Insufficient policy enforcement in COOP in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to leak cross-
Insufficient policy enforcement in Background Fetch in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to
A credentials leak was found in the OpenShift Container Platform. The private key for the external cluster certificate w
Under certain conditions, BOE AdminTools/ BOE SDK allows an attacker to access information which would otherwise be rest
Teleport v3.2.2, Teleport v3.5.6-rc6, and Teleport v3.6.3-b2 was discovered to contain an information leak via the /user
Planet eStream before 6.72.10.07 discloses sensitive information, related to the ON cookie (findable in HTML source code
Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. Affected vers
A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.7.3). The affected application uses a
Under certain conditions, an attacker authenticated as a CMS administrator and with high privileges access to the Networ
Versions of IBM Spectrum Protect Plus prior to 10.1.12 (excluding 10.1.12) include the private key information for a cer
IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.3 could disclose sensitive information. An authenticate
Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mit
Remote Desktop Licensing Diagnoser Information Disclosure Vulnerability
Improper isolation of shared resources in network on chip for the Intel(R) 82599 Ethernet Controllers and Adapters may a
The check_alu_op() function in kernel/bpf/verifier.c in the Linux kernel through v5.16-rc5 did not properly update bound
On unix-like systems, the system temporary directory is shared between all users on that system. The root cause is File.
Frequently Asked Questions
What is CWE-668?
CWE-668 (CWE-668) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-668?
There are 817 CVE records associated with CWE-668 in our database. Of these, 64 are critical severity, 235 are high severity, and 360 are medium severity.
How can I protect against CWE-668 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-668 using AI-powered security agents.
Detect CWE-668 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-668 vulnerabilities across your infrastructure.
Get Started