CWE-610
Externally Controlled Reference to a Resource in Another Sphere
The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.
239 vulnerabilities with CWE-610
CVE-2021-39765
MEDIUM
Android 12L - Local Information Disclosure via Gallery Permission Bypass
CVSS 5.5
CVE-2021-39707
HIGH
Android - Local Privilege Escalation via Confused Deputy in AppRestrictionsFragment
CVSS 7.8
CVE-2021-39703
HIGH
Android 12 - Unauthorized File Access via UsbDeviceManager Confused Deputy
CVSS 7.8
CVE-2021-39668
HIGH
Android -11/12 - Privilege Escalation
CVSS 7.8
CVE-2021-39663
HIGH
Android 10 - Local Privilege Escalation via MediaProvider Path Permission Bypass
CVSS 7.8
CVE-2021-39626
HIGH
Android - Local Privilege Escalation via Bluetooth Settings Permission Bypass
CVSS 7.8
CVE-2021-1035
HIGH
Android - Local Privilege Escalation via BluetoothDevicePickerPreferenceController
CVSS 7.8
CVE-2021-3845
HIGH
ws_scrcpy < 0.7.1 - Path Traversal
CVSS 7.5
CVE-2021-43844
HIGH
MSEdgeRedirect < 0.5.0.1 - Remote Code Execution via Crafted URL Prompt
CVSS 8.8
CVE-2021-1003
HIGH
Android 12 - Unauthenticated Local Privilege Escalation via AudioService Volume Adjustment
CVSS 7.8
CVE-2021-44041
CRITICAL
UiPath Assistant 21.4.4 - Code Injection
CVSS 9.8
CVE-2021-43794
MEDIUM
Discourse < 2.7.11 - Cache Poisoning Denial of Service for Anonymous Users
CVSS 5.3
CVE-2021-43685
CRITICAL
libretime hv3.0.0-alpha.10 - Path Traversal
CVSS 9.8
CVE-2021-41244
CRITICAL
Grafana 8.0.0-8.2.3 - Unauthorized Role Modification via Fine-Grained Access Control
CVSS 9.1
CVE-2021-0708
HIGH
Android 8.1-11 - Unauthenticated System File Deletion via ActivityManagerShellCommand
CVSS 7.8
CVE-2021-25740
LOW
Kubernetes - Confused Deputy Network Access
CVSS 3.1
CVE-2021-0593
HIGH
Android - Local Privilege Escalation via Confused Deputy in DevicePickerFragment
CVSS 7.8
CVE-2021-0591
HIGH
Android 8.1-11 - Authenticated Privileged Broadcast Receiver Invocation via BluetoothPermissionActivity
CVSS 7.3
CVE-2021-32578
HIGH
Acronis True Image - Local Privilege Escalation via Improper Soft Link Handling
CVSS 7.8
CVE-2021-32576
HIGH
Acronis True Image - Local Privilege Escalation via Soft Link Handling
CVSS 7.8
CVE-2021-32783
HIGH
Contour < 1.17.1 and >= 0 < 1.14.2 - Unauthenticated Denial of Service via ExternalName Service
CVSS 8.5
CVE-2021-32773
MEDIUM
Racket < 8.2 - Unintended Proxy or Intermediary via Sandbox Module Dependency Confusion
CVSS 6.1
CVE-2021-0599
MEDIUM
Android 8.1-11 - Local Information Disclosure via Confused Deputy in NotificationRecord
CVSS 5.5
CVE-2021-26920
MEDIUM
Apache Druid < 0.22.0 and druid-core < 0.21.0 - Authenticated Arbitrary File Read via HTTP InputSource
CVSS 6.5
CVE-2021-29965
MEDIUM
Firefox < 89.0 - Password Manager Spoofing via HTTP Authentication Dialog
CVSS 5.3
Details
Vulnerabilities
239