Vulnerabilities > Use of Incorrectly-Resolved Name or Reference

DATE CVE VULNERABILITY TITLE RISK
2023-09-19 CVE-2023-42451 Use of Incorrectly-Resolved Name or Reference vulnerability in Joinmastodon Mastodon
Mastodon is a free, open-source social network server based on ActivityPub.
network
low complexity
joinmastodon CWE-706
7.5
2023-06-01 CVE-2023-34092 Use of Incorrectly-Resolved Name or Reference vulnerability in Vitejs Vite
Vite provides frontend tooling.
network
low complexity
vitejs CWE-706
7.5
2023-03-03 CVE-2023-27561 Use of Incorrectly-Resolved Name or Reference vulnerability in multiple products
runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go.
local
high complexity
linuxfoundation redhat debian CWE-706
7.0
2023-02-03 CVE-2021-37315 Use of Incorrectly-Resolved Name or Reference vulnerability in Asus Rt-Ac68U Firmware
Incorrect Access Control issue discoverd in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to write arbitrary files via improper sanitation on the source for COPY and MOVE operations.
network
low complexity
asus CWE-706
critical
9.1
2022-11-21 CVE-2022-30257 Use of Incorrectly-Resolved Name or Reference vulnerability in Technitium DNS Server
An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V1 of unintended domain name resolution.
network
low complexity
technitium CWE-706
critical
9.8
2022-11-21 CVE-2022-30258 Use of Incorrectly-Resolved Name or Reference vulnerability in Technitium DNS Server
An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V2 of unintended domain name resolution.
network
low complexity
technitium CWE-706
critical
9.8
2022-11-10 CVE-2022-41874 Use of Incorrectly-Resolved Name or Reference vulnerability in Tauri
Tauri is a framework for building binaries for all major desktop platforms.
network
low complexity
tauri CWE-706
4.7
2022-06-27 CVE-2022-31089 Use of Incorrectly-Resolved Name or Reference vulnerability in Parseplatform Parse-Server
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js.
network
low complexity
parseplatform CWE-706
5.0
2022-06-02 CVE-2022-27778 Use of Incorrectly-Resolved Name or Reference vulnerability in multiple products
A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used together with `--remove-on-error`.
network
low complexity
haxx netapp oracle splunk CWE-706
8.1
2022-05-20 CVE-2022-29448 Use of Incorrectly-Resolved Name or Reference vulnerability in Wow-Estore Herd Effects
Authenticated (admin or higher user role) Local File Inclusion (LFI) vulnerability in Wow-Company's Herd Effects plugin <= 5.2 at WordPress.
network
low complexity
wow-estore CWE-706
4.0