Skip to main content

CWE archive

CWE-127 CVEs

Programmatic archive

8 CVEs tagged with CWE-1270 Critical, 4 High, 3 Medium, 1 Low, 0 Unrated.

CVE-2026-45683

Published Jun 2, 2026

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the Java TLS ioctl probe reads user-controlled ioctl…

CVSS 3.8 · Low
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-5928

Published Apr 20, 2026

Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the…

CVSS 7.5 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2025-20359

Published Oct 15, 2025

Multiple Cisco products are affected by a vulnerability in the Snort 3 HTTP Decoder that could allow an unauthenticated, remote attacker to cause the disclosure of possible sensit…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-32050

Published Apr 3, 2025

A flaw was found in libsoup. The libsoup append_param_quoted() function may contain an overflow bug resulting in a buffer under-read.

CVSS 5.9 · Medium

CVE-2024-25629

Published Feb 23, 2024

c-ares is a C library for asynchronous DNS requests. `ares__read_line()` is used to parse local configuration files such as `/etc/resolv.conf`, `/etc/nsswitch.conf`, the `HOSTALIA…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-1918

Published Mar 10, 2021

In-memory file operations (ie: using fopen on a data URI) did not properly restrict negative seeking, allowing for the reading of memory prior to the in-memory buffer. This issue…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1