CWE-610
244 CVEs • Abstraction: Class
Externally Controlled Reference to a Resource in Another Sphere
The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.
CVEs (244)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Manually dragging and dropping an Outlook email message into the browser will trigger a page navigation when the message's mail columns are incorrectly interpreted as a URL. *Note: this issue only affects Windows operati...Show more |
1Safe Eval Project 1Safe Eval Nov 21, 2024 Jun 7, 2018 N/A· v4 10.0 CRITICAL· v3 10.0 HIGH· v2 The safe-eval module describes itself as a safer version of eval. By accessing the object constructors, un-sanitized user input can access the entire standard library and effectively break out of the sandbox. |
The PSFTPd 10.0.4 Build 729 server does not prevent FTP bounce scans by default. These can be performed using "nmap -b" and allow performing scans via the FTP server. |
1Microsoft 5Windows 10 Windows 8.1Windows Rt 8.1+2 moreMay 13, 2026 Apr 12, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An elevation of privilege vulnerability exists in Windows 10, Windows 8.1, Windows RT 8.1, Windows Server 2012, Windows Server 2012 R2, and Windows Server 2016 versions of Microsoft Windows OLE when it fails an integrity...Show more |