← Back
CWE-610

244 CVEs • Abstraction: Class

Externally Controlled Reference to a Resource in Another Sphere

The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.

JSON object

Loading...

CVEs (244)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mozilla
1Firefox
Nov 25, 2025
Oct 18, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Manually dragging and dropping an Outlook email message into the browser will trigger a page navigation when the message's mail columns are incorrectly interpreted as a URL. *Note: this issue only affects Windows operati...Show more
Manually dragging and dropping an Outlook email message into the browser will trigger a page navigation when the message's mail columns are incorrectly interpreted as a URL. *Note: this issue only affects Windows operating systems with Outlook installed. Other operating systems are not affected.*. This vulnerability affects Firefox ESR < 60.2 and Firefox < 62.Show less
1Safe Eval Project
1Safe Eval
Nov 21, 2024
Jun 7, 2018
N/A· v4
10.0 CRITICAL· v3
10.0 HIGH· v2
The safe-eval module describes itself as a safer version of eval. By accessing the object constructors, un-sanitized user input can access the entire standard library and effectively break out of the sandbox.
1Psftp
1Psftpd
May 13, 2026
Nov 15, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The PSFTPd 10.0.4 Build 729 server does not prevent FTP bounce scans by default. These can be performed using "nmap -b" and allow performing scans via the FTP server.
1Microsoft
5Windows 10
Windows 8.1Windows Rt 8.1+2 more
May 13, 2026
Apr 12, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An elevation of privilege vulnerability exists in Windows 10, Windows 8.1, Windows RT 8.1, Windows Server 2012, Windows Server 2012 R2, and Windows Server 2016 versions of Microsoft Windows OLE when it fails an integrity...Show more
An elevation of privilege vulnerability exists in Windows 10, Windows 8.1, Windows RT 8.1, Windows Server 2012, Windows Server 2012 R2, and Windows Server 2016 versions of Microsoft Windows OLE when it fails an integrity-level check, aka "Windows OLE Elevation of Privilege Vulnerability."Show less