CWE-610
244 CVEs • Abstraction: Class
Externally Controlled Reference to a Resource in Another Sphere
The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.
CVEs (244)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In toUriInner of Intent.java, there is a possible way to launch an arbitrary activity due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User intera...Show more |
1Oretnom23 1Student Study Center Desk Management System Jun 17, 2026 Apr 18, 2023 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A vulnerability has been found in SourceCodester Student Study Center Desk Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file index.php. The manipulat...Show more |
An issue was discovered in Insyde InsydeH2O with kernel 5.2 through 5.5. The Save State register is not checked before use. The IhisiSmm driver does not check the value of a save state register before use. Due to insuffi...Show more |
In multiple functions of MediaSessionRecord.java, there is a possible Intent rebroadcast due to a confused deputy. This could lead to local denial of service or escalation of privilege with no additional execution privil...Show more |
2Fedoraproject Paloaltonetworks2Cortex Xsoar FedoraJun 17, 2026 Feb 8, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user with access to the web interface to read local files from the server. |
A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6 (All versions < V6.0 SP9 Upd4), TeleControl Server Basic V3 (All versions < V3.1.2). The affected compone...Show more |
1Wing Tight Project 1Wing Tight Nov 21, 2024 Jan 5, 2023 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability, which was classified as critical, was found in soshtolsus wing-tight. This affects an unknown part of the file index.php. The manipulation of the argument p leads to file inclusion. It is possible to ini...Show more |
NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can access or modify system files or other files that are critical to the application, which may l...Show more |
When receiving an HTML email that contained an <code>iframe</code> element, which used a <code>srcdoc</code> attribute to define the inner HTML document, remote objects specified in the nested document, for example image...Show more |
In Multiple Locations, there is a possibility to launch arbitrary protected activities due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is...Show more |
In onPreferenceClick of AccountTypePreferenceLoader.java, there is a possible way to retrieve protected files from the Settings app due to a confused deputy. This could lead to local information disclosure with no additi...Show more |
In multiple locations of NfcService.java, there is a possible disclosure of NFC tags due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interact...Show more |
ILIAS before 7.16 allows External Control of File Name or Path. |
1Siemens 1Syngo Dynamics Cardiovascular Imaging And Information System Jun 17, 2026 Nov 17, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper write access control that could allow to write dat...Show more |
1Siemens 1Syngo Dynamics Cardiovascular Imaging And Information System Jun 17, 2026 Nov 17, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper write access control that could allow to write dat...Show more |
1Siemens 1Syngo Dynamics Cardiovascular Imaging And Information System Jun 17, 2026 Nov 17, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper write access control that could allow to write dat...Show more |
1Siemens 1Syngo Dynamics Cardiovascular Imaging And Information System Jun 17, 2026 Nov 17, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper read access control that could allow files to be r...Show more |
1Siemens 1Syngo Dynamics Cardiovascular Imaging And Information System Jun 17, 2026 Nov 17, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper read access control that could allow files to be r...Show more |
Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40107. |
1Jenkins 1Compuware Topaz For Total Test Jun 17, 2026 Oct 19, 2022 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to obtain the values...Show more |