CWE-706

Use of Incorrectly-Resolved Name or Reference

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.

116 vulnerabilities with CWE-706
CVE-2019-12837 MEDIUM
accesuniversitat.gencat.cat 1.7.5 - Unauthenticated Personal Information Exposure via Java API
CVSS 4.3
CVE-2019-19493 MEDIUM
Kentico Xperience 9.0-12.0.49 - Cross-Site Scripting via Inconsistent Content-Type Header
CVSS 5.4
CVE-2019-17575 HIGH
WBCE CMS <1.4.0 - Command Injection
CVSS 7.2
CVE-2019-0220 MEDIUM
Apache HTTP Server <2.4.39 - Path Traversal
CVSS 5.3
CVE-2019-9901 MEDIUM
Envoy < 1.9.0 - Path Normalization Bypass via Relative Path Traversal
CVSS 6.5
CVE-2019-0816 MEDIUM
Ubuntu Linux - Security Feature Bypass via Azure SSH Keypairs Provisioning Logic
CVSS 5.1
CVE-2019-9616 HIGH
ofcms < 1.1.3 - Remote Code Execution via Alternate Data Stream Bypass
CVSS 7.2
CVE-2019-8908 CRITICAL
WTCMS 1.0 - Remote Code Execution via Mailbox Configuration Image Upload
CVSS 9.8
CVE-2019-8395 CRITICAL
Zoho ManageEngine ServiceDesk Plus < 10.0 - Insecure Direct Object Reference via Request Attachment
CVSS 9.8
CVE-2019-7731 CRITICAL
MyWebSQL 3.7 - Remote Code Execution via Backup Database Function
CVSS 9.8
CVE-2019-6289 HIGH
DedeCMS V57_UTF8_SP2 - Remote Code Execution via Mixed-Case PHP Extension Bypass
CVSS 8.8
CVE-2019-0571 HIGH
Windows Data Sharing Service - Privilege Escalation
CVSS 7.8
CVE-2018-6112 MEDIUM
Google Chrome <66.0.3359.117 - Open Redirect
CVSS 4.3
CVE-2018-12020 HIGH
GnuPG <2.2.8 - Info Disclosure
CVSS 7.5
CVE-2018-0237 MEDIUM
Cisco Advanced Malware Protection for Endpoints - Malware Detection Bypass via DMG File Extension Spoofing
CVSS 5.8
CVE-2014-125125 HIGH
A10 Networks AX Loadbalancer <2.7.0 - Path Traversal
Details
Vulnerabilities 116