Skip to main content

CWE archive

CWE-610 CVEs

Programmatic archive

236 CVEs tagged with CWE-61018 Critical, 93 High, 100 Medium, 25 Low, 0 Unrated.

CVE-2021-32783

Published Jul 23, 2021

Contour is a Kubernetes ingress controller using Envoy proxy. In Contour before version 1.17.1 a specially crafted ExternalName type Service may be used to access Envoy's admin in…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-32773

Published Jul 20, 2021

Racket is a general-purpose programming language and an ecosystem for language-oriented programming. In versions prior to 8.2, code evaluated using the Racket sandbox could cause…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-0599

Published Jul 14, 2021

In scheduleTimeoutLocked of NotificationRecord.java, there is a possible disclosure of a sensitive identifier via broadcasted intent due to a confused deputy. This could lead to l…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-26920

Published Jul 2, 2021

In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from othe…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29965

Published Jun 24, 2021

A malicious website that causes an HTTP Authentication dialog to be spawned could trick the built-in password manager to suggest passwords for the currently active website instead…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-0608

Published Jun 22, 2021

In handleAppLaunch of AppLaunchActivity.java, there is a possible arbitrary activity launch due to a confused deputy. This could lead to local escalation of privilege with no addi…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-0550

Published Jun 22, 2021

In onLoadFailed of AnnotateActivity.java, there is a possible way to gain WRITE_EXTERNAL_STORAGE permissions without user consent due to a confused deputy. This could lead to loca…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-0536

Published Jun 22, 2021

In dropFile of WiFiInstaller, there is a way to delete files accessible to CertInstaller due to a confused deputy. This could lead to local escalation of privilege with no additio…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-27648

Published Apr 28, 2021

Externally controlled reference to a resource in another sphere in quarantine functionality in Synology Antivirus Essential before 1.4.8-2801 allows remote authenticated users to…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-30245

Published Apr 15, 2021

The project received a report that all versions of Apache OpenOffice through 4.1.8 can open non-http(s) hyperlinks. The problem has existed since about 2006 and the issue is also…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-27183

Published Apr 14, 2021

An issue was discovered in MDaemon before 20.0.4. Administrators can use Remote Administration to exploit an Arbitrary File Write vulnerability. An attacker is able to create new…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-25161

Published Feb 23, 2021

The WADashboard component of WebAccess/SCADA Versions 9.0 and prior may allow an attacker to control or influence a path used in an operation on the filesystem and remotely execut…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-26711

Published Feb 5, 2021

A frame-injection issue in the online help in Redwood Report2Web 4.3.4.5 allows remote attackers to render an external resource inside a frame via the help/Online_Help/NetHelp/def…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-6105

Published Oct 15, 2020

An exploitable code execution vulnerability exists in the multiple devices functionality of F2fs-Tools F2fs.Fsck 1.13. A specially crafted f2fs filesystem can cause Information ov…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-0345

Published Sep 17, 2020

In DocumentsUI, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. Us…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-0267

Published Sep 17, 2020

In WindowManager, there is a possible launch of an unexpected app due to a confused deputy. This could lead to local escalation of privilege due to launching a malicious app inste…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-12475

Published Sep 1, 2020

A Externally Controlled Reference to a Resource in Another Sphere vulnerability in obs-service-download_files of openSUSE Open Build Service allows authenticated users to generate…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-8226

Published Aug 17, 2020

A vulnerability exists in phpBB <v3.2.10 and <v3.3.1 which allowed remote image dimensions check to be used to SSRF.

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5412

Published Aug 7, 2020

Spring Cloud Netflix, versions 2.2.x prior to 2.2.4, versions 2.1.x prior to 2.1.6, and older unsupported versions allow applications to use the Hystrix Dashboard proxy.stream end…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-8553

Published Jul 29, 2020

The Kubernetes ingress-nginx component prior to version 0.28.0 allows a user with the ability to create namespaces and to read and create ingress objects to overwrite the password…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-14057

Published Jul 1, 2020

Monsta FTP 2.10.1 or below allows external control of paths used in filesystem operations. This allows attackers to read and write arbitrary local files, allowing an attacker to g…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-0210

Published Jun 11, 2020

In removeSharedAccountAsUser of AccountManager.java, there is a possible permissions bypass to a confused deputy. This could lead to local escalation of privilege with User execut…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-5297

Published Jun 3, 2020

In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an attacker can exploit this vulnerability to upload jpg, jpeg, bmp, png, webp, gif, ico…

CVSS 3.4 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-5296

Published Jun 3, 2020

In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an attacker can exploit this vulnerability to delete arbitrary local files of an October…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort
Showing 176-200 of 236 CVEsPage 8 of 10