CWE-610

Externally Controlled Reference to a Resource in Another Sphere

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.

220 vulnerabilities with CWE-610
CVE-2023-34982 MEDIUM
Aveva Batch Management < 2020 - Denial of Service
CVSS 5.5
CVE-2023-40139 MEDIUM
Google Android - Information Disclosure
CVSS 5.5
CVE-2023-4089 LOW
Wago - Info Disclosure
CVSS 2.7
CVE-2023-44209 HIGH
Acronis Agent - Privilege Escalation
CVSS 7.8
CVE-2023-32615 MEDIUM
Open Automation Software OAS Platform <18.00.0072 - File Write
CVSS 6.5
CVE-2023-4704 MEDIUM
instantsoft/icms2 <2.16.1 - Elevation of Privilege
CVSS 4.9
CVE-2023-35838 MEDIUM
WireGuard 0.5.3 - Privilege Escalation
CVSS 5.7
CVE-2023-37856 MEDIUM
PHOENIX CONTACT WP 6xxx - Info Disclosure
CVSS 4.3
CVE-2023-37855 MEDIUM
PHOENIX CONTACT WP 6xxx - Info Disclosure
CVSS 4.3
CVE-2023-38046 MEDIUM
Palo Alto Networks PAN-OS - Info Disclosure
CVSS 5.5
CVE-2023-3256 HIGH
Advantech R-SeeNet <2.4.22 - Info Disclosure
CVSS 8.8
CVE-2023-33188 MEDIUM
Omni-notes - Path Traversal
CVSS 6.3
CVE-2023-32076 MEDIUM
in-toto <1.4.0 - Info Disclosure
CVSS 5.5
CVE-2023-0008 MEDIUM
Palo Alto Networks PAN-OS - Info Disclosure
CVSS 4.4
CVE-2023-30943 MEDIUM
Moodle - Path Traversal
CVSS 6.5
CVE-2023-0045 MEDIUM
prctl - Use After Free
CVSS 4.7
CVE-2023-21097 HIGH
Android - Privilege Escalation
CVSS 7.8
CVE-2023-2152 MEDIUM
SourceCodester Student Study Center Desk Management System 1.0 - Fi...
CVSS 5.3
CVE-2023-22616 HIGH
InsydeH2O <5.5 - Memory Corruption
CVSS 7.8
CVE-2023-20964 HIGH
Google Android - Denial of Service
CVSS 7.8
CVE-2023-0003 MEDIUM
Palo Alto Networks Cortex XSOAR - Info Disclosure
CVSS 6.5
CVE-2022-23439 MEDIUM
Fortinet - SSRF
CVSS 4.7
CVE-2022-46869 HIGH
Acronis Cyber Protect Home Office <build 40278 - Privilege Escalation
CVSS 7.8
CVE-2022-46868 HIGH
Acronis Cyber Protect Home Office <40173 - Privilege Escalation
CVSS 7.8
CVE-2022-43513 HIGH
Automation License Manager - Unauth RCE
CVSS 8.2
Details
Vulnerabilities 220