Vulnerabilities > Use of Incorrectly-Resolved Name or Reference

DATE CVE VULNERABILITY TITLE RISK
2020-01-24 CVE-2019-1351 Use of Incorrectly-Resolved Name or Reference vulnerability in multiple products
A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, aka 'Git for Visual Studio Tampering Vulnerability'.
network
low complexity
microsoft opensuse CWE-706
7.5
2019-12-02 CVE-2019-19493 Use of Incorrectly-Resolved Name or Reference vulnerability in Kentico
Kentico before 12.0.50 allows file uploads in which the Content-Type header is inconsistent with the file extension, leading to XSS.
network
kentico CWE-706
3.5
2019-06-11 CVE-2019-0220 Use of Incorrectly-Resolved Name or Reference vulnerability in multiple products
A vulnerability was found in Apache HTTP Server 2.4.0 to 2.4.38.
5.3
2019-04-25 CVE-2019-9901 Use of Incorrectly-Resolved Name or Reference vulnerability in Envoyproxy Envoy
Envoy 1.9.0 and before does not normalize HTTP URL paths.
network
low complexity
envoyproxy CWE-706
critical
10.0
2019-04-09 CVE-2019-0816 Use of Incorrectly-Resolved Name or Reference vulnerability in Canonical Ubuntu Linux 18.04
A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images that use cloud-init, aka 'Azure SSH Keypairs Security Feature Bypass Vulnerability'.
1.9
2019-03-06 CVE-2019-9616 Use of Incorrectly-Resolved Name or Reference vulnerability in Ofcms Project Ofcms
An issue was discovered in OFCMS before 1.1.3.
network
low complexity
ofcms-project CWE-706
6.5
2019-01-09 CVE-2018-6112 Use of Incorrectly-Resolved Name or Reference vulnerability in multiple products
Making URLs clickable and allowing them to be styled in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
network
low complexity
google debian redhat CWE-706
4.3
2019-01-08 CVE-2019-0571 Use of Incorrectly-Resolved Name or Reference vulnerability in Microsoft products
An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data Sharing Service Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows Server 2019, Windows 10 Servers.
network
microsoft CWE-706
6.8
2018-06-08 CVE-2018-12020 Use of Incorrectly-Resolved Name or Reference vulnerability in multiple products
mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof the output that GnuPG sends on file descriptor 2 to other programs that use the "--status-fd 2" option.
network
low complexity
redhat canonical debian gnupg CWE-706
5.0
2018-04-19 CVE-2018-0237 Use of Incorrectly-Resolved Name or Reference vulnerability in Cisco Advanced Malware Protection FOR Endpoints 1.4(5)
A vulnerability in the file type detection mechanism of the Cisco Advanced Malware Protection (AMP) for Endpoints macOS Connector could allow an unauthenticated, remote attacker to bypass malware detection.
network
low complexity
cisco CWE-706
5.0