Vulnerabilities > Externally Controlled Reference to a Resource in Another Sphere

DATE CVE VULNERABILITY TITLE RISK
2023-04-25 CVE-2023-0045 Externally Controlled Reference to a Resource in Another Sphere vulnerability in multiple products
The current implementation of the prctl syscall does not issue an IBPB immediately during the syscall.
network
low complexity
linux debian netapp CWE-610
7.5
2023-04-18 CVE-2023-2152 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Student Study Center Desk Management System Project Student Study Center Desk Management System 1.0
A vulnerability has been found in SourceCodester Student Study Center Desk Management System 1.0 and classified as critical.
9.8
2023-04-12 CVE-2023-22616 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Insyde Insydeh2O
An issue was discovered in Insyde InsydeH2O with kernel 5.2 through 5.5.
local
low complexity
insyde CWE-610
7.8
2023-02-08 CVE-2023-0003 Externally Controlled Reference to a Resource in Another Sphere vulnerability in multiple products
A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user with access to the web interface to read local files from the server.
network
low complexity
paloaltonetworks fedoraproject CWE-610
6.5
2023-01-10 CVE-2022-43513 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Siemens Automation License Manager
A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6 (All versions < V6.0 SP9 Upd4), TeleControl Server Basic V3 (All versions < V3.1.2).
network
low complexity
siemens CWE-610
7.5
2023-01-05 CVE-2014-125044 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Wing-Tight Project Wing-Tight
A vulnerability, which was classified as critical, was found in soshtolsus wing-tight.
network
low complexity
wing-tight-project CWE-610
critical
9.8
2022-12-30 CVE-2022-34669 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Nvidia Cloud Gaming and Virtual GPU
NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can access or modify system files or other files that are critical to the application, which may lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.
local
low complexity
nvidia CWE-610
7.8
2022-12-22 CVE-2022-3032 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Mozilla Thunderbird
When receiving an HTML email that contained an <code>iframe</code> element, which used a <code>srcdoc</code> attribute to define the inner HTML document, remote objects specified in the nested document, for example images or videos, were not blocked.
network
low complexity
mozilla CWE-610
6.5
2022-12-16 CVE-2022-20199 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Google Android 13.0
In multiple locations of NfcService.java, there is a possible disclosure of NFC tags due to a confused deputy.
local
low complexity
google CWE-610
5.5
2022-12-07 CVE-2022-45918 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Ilias
ILIAS before 7.16 allows External Control of File Name or Path.
network
low complexity
ilias CWE-610
6.5