Vulnerabilities > Use of Incorrectly-Resolved Name or Reference

DATE CVE VULNERABILITY TITLE RISK
2025-03-10 CVE-2025-24813 Use of Incorrectly-Resolved Name or Reference vulnerability in Apache Tomcat
Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2, from 10.1.0-M1 through 10.1.34, from 9.0.0.M1 through 9.0.98. If all of the following were true, a malicious user was able to view security sensitive files and/or inject content into those files: - writes enabled for the default servlet (disabled by default) - support for partial PUT (enabled by default) - a target URL for security sensitive uploads that was a sub-directory of a target URL for public uploads - attacker knowledge of the names of security sensitive files being uploaded - the security sensitive files also being uploaded via partial PUT If all of the following were true, a malicious user was able to perform remote code execution: - writes enabled for the default servlet (disabled by default) - support for partial PUT (enabled by default) - application was using Tomcat's file based session persistence with the default storage location - application included a library that may be leveraged in a deserialization attack Users are recommended to upgrade to version 11.0.3, 10.1.35 or 9.0.99, which fixes the issue.
network
low complexity
apache CWE-706
critical
9.8
2024-11-30 CVE-2024-53739 Use of Incorrectly-Resolved Name or Reference vulnerability in Coolplugins Cryptocurrency Widgets for Elementor
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Cool Plugins Cryptocurrency Widgets For Elementor allows PHP Local File Inclusion.This issue affects Cryptocurrency Widgets For Elementor: from n/a through 1.6.4.
network
low complexity
coolplugins CWE-706
critical
9.8
2024-06-06 CVE-2024-37150 Use of Incorrectly-Resolved Name or Reference vulnerability in Deno 1.44.0
An issue in `.npmrc` support in Deno 1.44.0 was discovered where Deno would send `.npmrc` credentials for the scope to the tarball URL when the registry provided URLs for a tarball on a different domain.
network
low complexity
deno CWE-706
6.5
2024-03-01 CVE-2024-27295 Use of Incorrectly-Resolved Name or Reference vulnerability in Monospace Directus
Directus is a real-time API and App dashboard for managing SQL database content.
network
low complexity
monospace CWE-706
8.2
2023-06-01 CVE-2023-34092 Use of Incorrectly-Resolved Name or Reference vulnerability in Vitejs Vite
Vite provides frontend tooling.
network
low complexity
vitejs CWE-706
7.5
2023-03-30 CVE-2023-28643 Use of Incorrectly-Resolved Name or Reference vulnerability in Nextcloud Server 24.0.0/25.0.0/25.0.2
Nextcloud server is an open source home cloud implementation.
network
low complexity
nextcloud CWE-706
8.8
2023-03-03 CVE-2023-27561 Use of Incorrectly-Resolved Name or Reference vulnerability in multiple products
runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go.
local
high complexity
linuxfoundation redhat debian CWE-706
7.0
2023-02-03 CVE-2021-37315 Use of Incorrectly-Resolved Name or Reference vulnerability in Asus Rt-Ac68U Firmware
Incorrect Access Control issue discoverd in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to write arbitrary files via improper sanitation on the source for COPY and MOVE operations.
network
low complexity
asus CWE-706
critical
9.1
2022-11-21 CVE-2022-30257 Use of Incorrectly-Resolved Name or Reference vulnerability in Technitium DNS Server
An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V1 of unintended domain name resolution.
network
low complexity
technitium CWE-706
critical
9.8
2022-11-21 CVE-2022-30258 Use of Incorrectly-Resolved Name or Reference vulnerability in Technitium DNS Server
An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V2 of unintended domain name resolution.
network
low complexity
technitium CWE-706
critical
9.8