CWE-829

Inclusion of Functionality from Untrusted Control Sphere

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.

257 vulnerabilities with CWE-829
CVE-2013-3321 HIGH
NetApp OnCommand System Manager <2.1 - File Inclusion
CVSS 7.5
CVE-2013-4582 MEDIUM
GitLab <5.4.2, <6.2.4, <6.2.1 - Info Disclosure
CVSS 6.5
CVE-2013-1945 LOW
ruby193 - Inclusion of Functionality from Untrusted Control Sphere via LD_LIBRARY_PATH
CVSS 3.3
CVE-2012-4919 CRITICAL
Gallery Plugin1.4 for WordPress - RCE
CVSS 9.8
CVE-2010-2076 CRITICAL
Apache CXF 2.0.6-2.0.12, 2.1.x < 2.1.10, 2.2.x < 2.2.9 - XML External Entity Injection via SOAP DTD Processing
CVSS 9.8
CVE-2004-0285 CRITICAL
AllMyGuests AllMyLinks AllMyVisitors - Remote File Inclusion via _AMVconfig[cfg_serverpath] Parameter
CVSS 9.8
CVE-2004-0030 CRITICAL
phpgedview 2.61 - Remote File Inclusion via PGV_BASE_DIRECTORY Parameter
CVSS 9.8
Details
Vulnerabilities 257