CWE-706

Use of Incorrectly-Resolved Name or Reference

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.

107 vulnerabilities with CWE-706
CVE-2023-27561 HIGH
runc < 1.1.5 - Privilege Escalation via Custom Volume-Mount Configurations
CVSS 7.0
CVE-2022-30258 CRITICAL
Technitium DNS Server <8.0.2 - Info Disclosure
CVSS 9.8
CVE-2022-30257 CRITICAL
Technitium DNS Server <8.0.2 - Info Disclosure
CVSS 9.8
CVE-2022-41874 LOW
Tauri <1.0.7-1.1.2 - Info Disclosure
CVSS 2.6
CVE-2022-30621 HIGH
Cellinx NVT IP PTZ Camera Firmware - Unauthenticated Arbitrary File Read via GetFileContent.cgi
CVSS 7.6
CVE-2022-31089 HIGH
Parse Server <4.10.12, <5.2.3 - DoS
CVSS 7.5
CVE-2022-27778 HIGH
cURL - Use of Incorrectly Resolved Name
CVSS 8.1
CVE-2022-29448 MEDIUM
Herd Effects WordPress Plugin <= 5.2 - Authenticated Local File Inclusion
CVSS 6.8
CVE-2022-29445 MEDIUM
Wow-Company's Popup Box <2.1.2 - LFI
CVSS 6.8
CVE-2022-28198 MEDIUM
NVIDIA Omniverse Nucleus and Cache - Remote Code Execution via OpenSSL Configuration
CVSS 6.6
CVE-2022-0855 MEDIUM
microweber-dev/whmcs_plugin <0.0.4 - Path Traversal
CVSS 6.1
CVE-2021-47276 MEDIUM
Linux Kernel 2.6.28-4.4.273 - Denial of Service via Ftrace IP Address Handling
CVSS 5.5
CVE-2021-47261 HIGH
Linux Kernel 4.17-4.19.195 - Denial of Service via CQ Resize Buffer Initialization
CVSS 7.8
CVE-2021-37315 CRITICAL
ASUS RT-AC68U <3.0.0.4.386.41634 - Info Disclosure
CVSS 9.1
CVE-2021-40856 HIGH
Auerswald COMfortel <2.8G - Auth Bypass
CVSS 7.5
CVE-2021-40539 CRITICAL KEV
ManageEngine ADSelfService Plus CVE-2021-40539
CVSS 9.8
CVE-2021-39156 HIGH
Istio < 1.9.8 - Authorization Bypass via URI Fragment
CVSS 8.1
CVE-2021-37215 MEDIUM
Flygo < 1.91.1 - Authenticated Insecure Direct Object Reference via Employee ID Parameter
CVSS 4.3
CVE-2021-37214 HIGH
Flygo < 1.91.1 - Authenticated Authorization Bypass and Remote Code Execution via Employee ID Parameter
CVSS 8.8
CVE-2021-37213 MEDIUM
Flygo < 1.91.1 - Authenticated Insecure Direct Object Reference via Check-in Record Parameters
CVSS 4.3
CVE-2021-37212 MEDIUM
larvata flygo < 1.91.1 - Authenticated Insecure Direct Object Reference via Bulletin ID Parameter
CVSS 5.4
CVE-2021-22924 LOW
libcurl 7.10.4-7.76.1 - Connection Reuse via Case-Insensitive Path Matching
CVSS 3.7
CVE-2021-37144 CRITICAL
CSZ CMS 1.2.9 - Privilege Escalation
CVSS 9.1
CVE-2021-31920 MEDIUM
Istio < 1.8.6 and 1.9.x < 1.9.5 - Authorization Policy Bypass via Path Manipulation
CVSS 6.5
CVE-2021-32054 MEDIUM
Firely/Incendi Spark <1.5.5-r4 - XSS
CVSS 6.1
Details
Vulnerabilities 107