CWE-641
Improper Restriction of Names for Files and Other Resources
Description
The product constructs the name of a file or other resource using input from an upstream component, but it does not restrict or incorrectly restricts the resulting name.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (18)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-25177 | Hig | 0.57 | 8.8 | 0.01 | Mar 10, 2026 | Improper restriction of names for files and other resources in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2022-36302 | Hig | 0.57 | 8.8 | 0.01 | Aug 1, 2022 | File path manipulation vulnerability in BF-OS version 3.00 up to and including 3.83 allows an attacker to modify the file path to access different resources, which may contain sensitive information. | ||
| CVE-2020-36326 | Cri | 0.57 | 9.8 | 0.03 | Apr 28, 2021 | PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE-2018-19296, but arose because 6.1.8 fixed a functionality problem in which UNC pathnames were always considered unreadable by… | ||
| CVE-2025-47953 | Hig | 0.55 | 8.4 | 0.01 | Jun 10, 2025 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-47173 | Hig | 0.51 | 7.8 | 0.01 | Jun 10, 2025 | Improper input validation in Microsoft Office allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-21402 | Hig | 0.51 | 7.8 | 0.01 | Jan 14, 2025 | Microsoft Office OneNote Remote Code Execution Vulnerability | ||
| CVE-2025-21361 | Hig | 0.51 | 7.8 | 0.01 | Jan 14, 2025 | Microsoft Outlook Remote Code Execution Vulnerability | ||
| CVE-2026-27140 | Hig | 0.50 | 8.8 | 0.01 | Apr 8, 2026 | SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass. | ||
| CVE-2021-41146 | Hig | 0.50 | 8.8 | 0.01 | Oct 21, 2021 | qutebrowser is an open source keyboard-focused browser with a minimal GUI. Starting with qutebrowser v1.7.0, the Windows installer for qutebrowser registers a `qutebrowserurl:` URL handler. With certain applications, opening a specially crafted `qutebrowserurl:...` URL can lead… | ||
| CVE-2026-46581 | Hig | 0.49 | 7.5 | 0.00 | Aug 5, 2026 | In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or block remote URLs, allowing an attacker to specify a URL to a remote Facelet which will be included and processed as part of the normal request, with the… | ||
| CVE-2026-50023 | Hig | 0.47 | 8.3 | 0.01 | Jun 23, 2026 | yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, a vulnerability exists in yt-dlp that allows a remote attacker to write arbitrary OS-shortcut files (such as .desktop, .url, .webloc) to the user's filesystem, bypassing the remediation for CVE-2024-38519. The… | ||
| CVE-2024-30063 | Med | 0.44 | 6.7 | 0.01 | Jun 11, 2024 | Windows Distributed File System (DFS) Remote Code Execution Vulnerability | ||
| CVE-2024-47260 | Med | 0.42 | 6.5 | 0.00 | Mar 4, 2025 | 51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API mediaclip.cgi did not have a sufficient input validation allowing for uploading more audio clips then designed resulting in the Axis device running out of memory. Axis has released patched AXIS OS… | ||
| CVE-2019-25623 | Med | 0.40 | 6.2 | 0.00 | Mar 23, 2026 | Luminance Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the keyboard interface. Attackers can create a text file with arbitrary character sequences and trigger the application to… | ||
| CVE-2022-23536 | Med | 0.35 | 6.5 | 0.01 | Dec 19, 2022 | Cortex provides multi-tenant, long term storage for Prometheus. A local file inclusion vulnerability exists in Cortex versions 1.13.0, 1.13.1 and 1.14.0, where a malicious actor could remotely read local files as a result of parsing maliciously crafted Alertmanager… | ||
| CVE-2026-50510 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally. | ||
| CVE-2024-45312 | Med | 0.00 | 5.3 | 0.00 | Sep 2, 2024 | Overleaf is a web-based collaborative LaTeX editor. Overleaf Community Edition and Server Pro prior to version 5.0.7 (or 4.2.7 for the 4.x series) contain a vulnerability that allows an arbitrary language parameter in client spelling requests to be passed to the `aspell`… | ||
| CVE-2023-0046 | Hig | 0.00 | 7.2 | 0.01 | Jan 4, 2023 | Improper Restriction of Names for Files and Other Resources in GitHub repository lirantal/daloradius prior to master-branch. |
- risk 0.57cvss 8.8epss 0.01
Improper restriction of names for files and other resources in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.01
File path manipulation vulnerability in BF-OS version 3.00 up to and including 3.83 allows an attacker to modify the file path to access different resources, which may contain sensitive information.
- risk 0.57cvss 9.8epss 0.03
PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE-2018-19296, but arose because 6.1.8 fixed a functionality problem in which UNC pathnames were always considered unreadable by…
- risk 0.55cvss 8.4epss 0.01
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.01
Improper input validation in Microsoft Office allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.01
Microsoft Office OneNote Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Outlook Remote Code Execution Vulnerability
- risk 0.50cvss 8.8epss 0.01
SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.
- risk 0.50cvss 8.8epss 0.01
qutebrowser is an open source keyboard-focused browser with a minimal GUI. Starting with qutebrowser v1.7.0, the Windows installer for qutebrowser registers a `qutebrowserurl:` URL handler. With certain applications, opening a specially crafted `qutebrowserurl:...` URL can lead…
- risk 0.49cvss 7.5epss 0.00
In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or block remote URLs, allowing an attacker to specify a URL to a remote Facelet which will be included and processed as part of the normal request, with the…
- risk 0.47cvss 8.3epss 0.01
yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, a vulnerability exists in yt-dlp that allows a remote attacker to write arbitrary OS-shortcut files (such as .desktop, .url, .webloc) to the user's filesystem, bypassing the remediation for CVE-2024-38519. The…
- risk 0.44cvss 6.7epss 0.01
Windows Distributed File System (DFS) Remote Code Execution Vulnerability
- risk 0.42cvss 6.5epss 0.00
51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API mediaclip.cgi did not have a sufficient input validation allowing for uploading more audio clips then designed resulting in the Axis device running out of memory. Axis has released patched AXIS OS…
- risk 0.40cvss 6.2epss 0.00
Luminance Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the keyboard interface. Attackers can create a text file with arbitrary character sequences and trigger the application to…
- risk 0.35cvss 6.5epss 0.01
Cortex provides multi-tenant, long term storage for Prometheus. A local file inclusion vulnerability exists in Cortex versions 1.13.0, 1.13.1 and 1.14.0, where a malicious actor could remotely read local files as a result of parsing maliciously crafted Alertmanager…
- risk 0.00cvss 7.8epss 0.00
Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 5.3epss 0.00
Overleaf is a web-based collaborative LaTeX editor. Overleaf Community Edition and Server Pro prior to version 5.0.7 (or 4.2.7 for the 4.x series) contain a vulnerability that allows an arbitrary language parameter in client spelling requests to be passed to the `aspell`…
- risk 0.00cvss 7.2epss 0.01
Improper Restriction of Names for Files and Other Resources in GitHub repository lirantal/daloradius prior to master-branch.