CWE-641
16 CVEs • Abstraction: Base • Likelihood of Exploit: Low
Improper Restriction of Names for Files and Other Resources
The product constructs the name of a file or other resource using input from an upstream component, but it does not restrict or incorrectly restricts the resulting name.
CVEs (16)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally. |
yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, a vulnerability exists in yt-dlp that allows a remote attacker to write arbitrary OS-shortcut files (such as .desktop, .url, .webloc) to the user's fi...Show more |
SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass. |
Luminance Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the keyboard interface. Attackers can create a text file with arb...Show more |
1Microsoft 14Windows 10 1607 Windows 10 1809Windows 10 21h2+11 moreJun 17, 2026 Mar 10, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 Improper restriction of names for files and other resources in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network. |
1Microsoft 4365 Apps 365 CopilotOffice+1 moreJun 17, 2026 Jun 10, 2025 N/A· v4 8.4 HIGH· v3 N/A· v2 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
1Microsoft 3365 Apps OfficeOffice Long Term Servicing ChannelJun 17, 2026 Jun 10, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper input validation in Microsoft Office allows an unauthorized attacker to execute code locally. |
51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API mediaclip.cgi did not have a sufficient input validation allowing for uploading more audio clips then designed resulting in the Axis device...Show more |
1Microsoft 3Office Office Long Term Servicing ChannelOnenoteJun 17, 2026 Jan 14, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Microsoft Office OneNote Remote Code Execution Vulnerability |
1Microsoft 3Office Office Long Term Servicing ChannelOutlookJun 17, 2026 Jan 14, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Microsoft Outlook Remote Code Execution Vulnerability |
Overleaf is a web-based collaborative LaTeX editor. Overleaf Community Edition and Server Pro prior to version 5.0.7 (or 4.2.7 for the 4.x series) contain a vulnerability that allows an arbitrary language parameter in cl...Show more |
1Microsoft 14Windows 10 1507 Windows 10 1607Windows 10 1809+11 moreJul 20, 2026 Jun 11, 2024 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Windows Distributed File System (DFS) Remote Code Execution Vulnerability |
Improper Restriction of Names for Files and Other Resources in GitHub repository lirantal/daloradius prior to master-branch. |
Cortex provides multi-tenant, long term storage for Prometheus. A local file inclusion vulnerability exists in Cortex versions 1.13.0, 1.13.1 and 1.14.0, where a malicious actor could remotely read local files as a resul...Show more |
File path manipulation vulnerability in BF-OS version 3.00 up to and including 3.83 allows an attacker to modify the file path to access different resources, which may contain sensitive information. |
qutebrowser is an open source keyboard-focused browser with a minimal GUI. Starting with qutebrowser v1.7.0, the Windows installer for qutebrowser registers a `qutebrowserurl:` URL handler. With certain applications, ope...Show more |