Vulnerabilities > Use of Incorrectly-Resolved Name or Reference

DATE CVE VULNERABILITY TITLE RISK
2020-04-27 CVE-2020-12279 Use of Incorrectly-Resolved Name or Reference vulnerability in multiple products
An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0.
network
low complexity
libgit2 debian CWE-706
critical
9.8
2020-04-27 CVE-2020-12278 Use of Incorrectly-Resolved Name or Reference vulnerability in multiple products
An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0.
network
low complexity
libgit2 debian CWE-706
critical
9.8
2020-03-14 CVE-2020-10574 Use of Incorrectly-Resolved Name or Reference vulnerability in Meetecho Janus
An issue was discovered in Janus through 0.9.1.
network
low complexity
meetecho CWE-706
critical
9.8
2020-02-12 CVE-2019-19921 Use of Incorrectly-Resolved Name or Reference vulnerability in multiple products
runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go.
7.0
2020-01-24 CVE-2019-1351 Use of Incorrectly-Resolved Name or Reference vulnerability in multiple products
A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, aka 'Git for Visual Studio Tampering Vulnerability'.
network
low complexity
microsoft opensuse CWE-706
7.5
2019-12-02 CVE-2019-19493 Use of Incorrectly-Resolved Name or Reference vulnerability in Kentico
Kentico before 12.0.50 allows file uploads in which the Content-Type header is inconsistent with the file extension, leading to XSS.
network
low complexity
kentico CWE-706
5.4
2019-10-14 CVE-2019-17575 Use of Incorrectly-Resolved Name or Reference vulnerability in Wbce CMS
A file-rename filter bypass exists in admin/media/rename.php in WBCE CMS 1.4.0 and earlier.
network
low complexity
wbce CWE-706
7.2
2019-06-11 CVE-2019-0220 Use of Incorrectly-Resolved Name or Reference vulnerability in multiple products
A vulnerability was found in Apache HTTP Server 2.4.0 to 2.4.38.
5.3
2019-04-25 CVE-2019-9901 Use of Incorrectly-Resolved Name or Reference vulnerability in Envoyproxy Envoy
Envoy 1.9.0 and before does not normalize HTTP URL paths.
network
low complexity
envoyproxy CWE-706
critical
10.0
2019-04-09 CVE-2019-0816 Use of Incorrectly-Resolved Name or Reference vulnerability in Canonical Ubuntu Linux 18.04
A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images that use cloud-init, aka 'Azure SSH Keypairs Security Feature Bypass Vulnerability'.
local
high complexity
canonical CWE-706
5.1