Skip to main content

CWE archive

CWE-232 CVEs

Programmatic archive

11 CVEs tagged with CWE-2320 Critical, 5 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2025-20314

Published Sep 24, 2025

A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to an affected d…

CVSS 6.7 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-40775

Published May 21, 2025

When an incoming DNS protocol message includes a Transaction Signature (TSIG), BIND always checks it. If the TSIG contains an invalid value in the algorithm field, BIND immediate…

CVSS 7.5 · High

CVE-2025-20192

Published May 7, 2025

A vulnerability in the Internet Key Exchange version 1 (IKEv1) implementation of Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (…

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2023-39915

Published Sep 13, 2023

NLnet Labs' Routinator up to and including version 0.12.1 may crash when trying to parse certain malformed RPKI objects. This is due to insufficient input checking in the bcder li…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-39914

Published Sep 13, 2023

NLnet Labs' bcder library up to and including version 0.7.2 panics while decoding certain invalid input data rather than rejecting the data with an error. This can affect both the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-36848

Published Jul 14, 2023

An Improper Handling of Undefined Values vulnerability in the periodic packet management daemon (PPMD) of Juniper Networks Junos OS on MX Series(except MPC10, MPC11 and LC9600) al…

CVSS 6.5 · Medium

CVE-2023-2968

Published May 30, 2023

A remote attacker can trigger a denial of service in the socket.remoteAddress variable, by sending a crafted HTTP request. Usage of the undefined variable raises a TypeError excep…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-22213

Published Jul 20, 2022

A vulnerability in Handling of Undefined Values in the routing protocol daemon (RPD) process of Juniper Networks Junos OS and Junos OS Evolved may allow an unauthenticated network…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-34705

Published Sep 23, 2021

A vulnerability in the Voice Telephony Service Provider (VTSP) service of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass co…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-11 of 11 CVEsPage 1 of 1