Vulnerabilities > Externally Controlled Reference to a Resource in Another Sphere

DATE CVE VULNERABILITY TITLE RISK
2022-04-21 CVE-2022-20789 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Cisco Unified Communications Manager 12.5(1)/14.0
A vulnerability in the software upgrade process of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to write arbitrary files on the affected system.
network
low complexity
cisco CWE-610
6.5
2022-04-14 CVE-2022-24854 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Metabase
Metabase is an open source business intelligence and analytics application.
network
low complexity
metabase CWE-610
6.5
2022-03-30 CVE-2021-39765 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Google Android 12.1
In Gallery, there is a possible permission bypass due to a confused deputy.
local
low complexity
google CWE-610
2.1
2022-03-30 CVE-2021-39787 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Google Android 12.0
In SystemUI, there is a possible arbitrary Activity launch due to a confused deputy.
network
google CWE-610
critical
9.3
2022-03-16 CVE-2021-39703 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Google Android 12.0
In updateState of UsbDeviceManager.java, there is a possible unauthorized access of files due to a confused deputy.
local
low complexity
google CWE-610
7.2
2022-03-16 CVE-2021-39707 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Google Android 10.0/11.0/12.0
In onReceive of AppRestrictionsFragment.java, there is a possible way to start a phone call without permissions due to a confused deputy.
local
low complexity
google CWE-610
7.2
2022-02-11 CVE-2021-39663 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Google Android 10.0
In openFileAndEnforcePathPermissionsHelper of MediaProvider.java, there is a possible bypass of a permissions check due to a confused deputy.
local
low complexity
google CWE-610
7.2
2022-02-11 CVE-2021-39668 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Google Android 11.0/12.0
In onActivityViewReady of DetailDialog.kt, there is a possible Intent Redirect due to a confused deputy.
local
low complexity
google CWE-610
7.2
2022-01-14 CVE-2021-1035 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Google Android 10.0/12.0
In setLaunchIntent of BluetoothDevicePickerPreferenceController.java, there is a possible way to invoke an arbitrary broadcast receiver due to a confused deputy.
local
low complexity
google CWE-610
7.2
2022-01-14 CVE-2021-39626 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Google Android
In onAttach of ConnectedDeviceDashboardFragment.java, there is a possible permission bypass due to a confused deputy.
local
low complexity
google CWE-610
7.2