Vulnerabilities > Externally Controlled Reference to a Resource in Another Sphere

DATE CVE VULNERABILITY TITLE RISK
2023-05-10 CVE-2023-32076 Externally Controlled Reference to a Resource in Another Sphere vulnerability in In-Toto Project In-Toto
in-toto is a framework to protect supply chain integrity.
local
low complexity
in-toto-project CWE-610
5.5
2023-05-10 CVE-2023-0008 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Paloaltonetworks Pan-Os
A file disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write administrator with access to the web interface to export local files from the firewall through a race condition.
network
high complexity
paloaltonetworks CWE-610
4.4
2023-05-02 CVE-2023-30943 Externally Controlled Reference to a Resource in Another Sphere vulnerability in multiple products
The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders.
network
low complexity
moodle fedoraproject CWE-610
5.3
2023-04-25 CVE-2023-0045 Externally Controlled Reference to a Resource in Another Sphere vulnerability in multiple products
The current implementation of the prctl syscall does not issue an IBPB immediately during the syscall.
network
low complexity
linux debian netapp CWE-610
7.5
2023-04-19 CVE-2023-21097 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Google Android
In toUriInner of Intent.java, there is a possible way to launch an arbitrary activity due to a confused deputy.
local
low complexity
google CWE-610
7.8
2023-04-18 CVE-2023-2152 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Oretnom23 Student Study Center Desk Management System 1.0
A vulnerability has been found in SourceCodester Student Study Center Desk Management System 1.0 and classified as critical.
network
low complexity
oretnom23 CWE-610
critical
9.8
2023-04-12 CVE-2023-22616 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Insyde Insydeh2O
An issue was discovered in Insyde InsydeH2O with kernel 5.2 through 5.5.
local
low complexity
insyde CWE-610
7.8
2023-02-08 CVE-2023-0003 Externally Controlled Reference to a Resource in Another Sphere vulnerability in multiple products
A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user with access to the web interface to read local files from the server.
network
low complexity
paloaltonetworks fedoraproject CWE-610
6.5
2023-01-10 CVE-2022-43513 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Siemens Automation License Manager
A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6 (All versions < V6.0 SP9 Upd4), TeleControl Server Basic V3 (All versions < V3.1.2).
network
low complexity
siemens CWE-610
7.5
2023-01-05 CVE-2014-125044 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Wing-Tight Project Wing-Tight
A vulnerability, which was classified as critical, was found in soshtolsus wing-tight.
network
low complexity
wing-tight-project CWE-610
critical
9.8