CWE-706

Use of Incorrectly-Resolved Name or Reference

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.

105 vulnerabilities with CWE-706
CVE-2022-30257 CRITICAL
Technitium DNS Server <8.0.2 - Info Disclosure
CVSS 9.8
CVE-2022-41874 LOW
Tauri <1.0.7-1.1.2 - Info Disclosure
CVSS 2.6
CVE-2022-30621 HIGH
Camera OS - Info Disclosure
CVSS 7.6
CVE-2022-31089 HIGH
Parse Server <4.10.12, <5.2.3 - DoS
CVSS 7.5
CVE-2022-27778 HIGH
cURL - Use of Incorrectly Resolved Name
CVSS 8.1
CVE-2022-29448 MEDIUM
Herd Effects <5.2 - LFI
CVSS 6.8
CVE-2022-29445 MEDIUM
Wow-Company's Popup Box <2.1.2 - LFI
CVSS 6.8
CVE-2022-28198 MEDIUM
NVIDIA Omniverse - RCE
CVSS 6.6
CVE-2022-0855 MEDIUM
microweber-dev/whmcs_plugin <0.0.4 - Path Traversal
CVSS 6.1
CVE-2021-47276 MEDIUM
Linux kernel - DoS
CVSS 5.5
CVE-2021-47261 HIGH
Linux kernel - Buffer Overflow
CVSS 7.8
CVE-2021-37315 CRITICAL
ASUS RT-AC68U <3.0.0.4.386.41634 - Info Disclosure
CVSS 9.1
CVE-2021-40856 HIGH
Auerswald COMfortel <2.8G - Auth Bypass
CVSS 7.5
CVE-2021-40539 CRITICAL KEV
ManageEngine ADSelfService Plus CVE-2021-40539
CVSS 9.8
CVE-2021-39156 HIGH
Istio < 1.9.8 - Incorrect Authorization
CVSS 8.1
CVE-2021-37215 MEDIUM
Flygo - Privilege Escalation
CVSS 4.3
CVE-2021-37214 HIGH
Flygo - Privilege Escalation
CVSS 8.8
CVE-2021-37213 MEDIUM
Flygo - Info Disclosure
CVSS 4.3
CVE-2021-37212 MEDIUM
Flygo - Info Disclosure
CVSS 5.4
CVE-2021-22924 LOW
libcurl - Info Disclosure
CVSS 3.7
CVE-2021-37144 CRITICAL
CSZ CMS 1.2.9 - Privilege Escalation
CVSS 9.1
CVE-2021-31920 MEDIUM
Istio <1.8.6, 1.9.x <1.9.5 - SSRF
CVSS 6.5
CVE-2021-32054 MEDIUM
Firely/Incendi Spark <1.5.5-r4 - XSS
CVSS 6.1
CVE-2021-31933 HIGH
Chamilo < 1.11.14 - Remote Code Execution
CVSS 7.2
CVE-2021-27306 HIGH
Kong Gateway <2.3.2.0 - Info Disclosure
CVSS 7.5
Details
Vulnerabilities 105