Vulnerabilities > Use of Incorrectly-Resolved Name or Reference

DATE CVE VULNERABILITY TITLE RISK
2024-06-06 CVE-2024-37150 Use of Incorrectly-Resolved Name or Reference vulnerability in Deno 1.44.0
An issue in `.npmrc` support in Deno 1.44.0 was discovered where Deno would send `.npmrc` credentials for the scope to the tarball URL when the registry provided URLs for a tarball on a different domain.
network
low complexity
deno CWE-706
6.5
2023-06-01 CVE-2023-34092 Use of Incorrectly-Resolved Name or Reference vulnerability in Vitejs Vite
Vite provides frontend tooling.
network
low complexity
vitejs CWE-706
7.5
2023-03-30 CVE-2023-28643 Use of Incorrectly-Resolved Name or Reference vulnerability in Nextcloud Server 24.0.0/25.0.0/25.0.2
Nextcloud server is an open source home cloud implementation.
network
low complexity
nextcloud CWE-706
8.8
2023-03-03 CVE-2023-27561 Use of Incorrectly-Resolved Name or Reference vulnerability in multiple products
runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go.
local
high complexity
linuxfoundation redhat debian CWE-706
7.0
2023-02-03 CVE-2021-37315 Use of Incorrectly-Resolved Name or Reference vulnerability in Asus Rt-Ac68U Firmware
Incorrect Access Control issue discoverd in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to write arbitrary files via improper sanitation on the source for COPY and MOVE operations.
network
low complexity
asus CWE-706
critical
9.1
2022-11-21 CVE-2022-30257 Use of Incorrectly-Resolved Name or Reference vulnerability in Technitium DNS Server
An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V1 of unintended domain name resolution.
network
low complexity
technitium CWE-706
critical
9.8
2022-11-21 CVE-2022-30258 Use of Incorrectly-Resolved Name or Reference vulnerability in Technitium DNS Server
An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V2 of unintended domain name resolution.
network
low complexity
technitium CWE-706
critical
9.8
2022-11-10 CVE-2022-41874 Use of Incorrectly-Resolved Name or Reference vulnerability in Tauri
Tauri is a framework for building binaries for all major desktop platforms.
network
low complexity
tauri CWE-706
4.7
2022-07-18 CVE-2022-30621 Use of Incorrectly-Resolved Name or Reference vulnerability in Cellinx NVT - IP PTZ Camera Firmware 3.2.0/3.2.1
Allows a remote user to read files on the camera's OS "GetFileContent.cgi".
network
low complexity
cellinx CWE-706
6.5
2022-06-02 CVE-2022-27778 Use of Incorrectly-Resolved Name or Reference vulnerability in multiple products
A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used together with `--remove-on-error`.
network
low complexity
haxx netapp oracle splunk CWE-706
8.1