Skip to main content

CWE archive

CWE-244 CVEs

Programmatic archive

20 CVEs tagged with CWE-2440 Critical, 5 High, 15 Medium, 0 Low, 0 Unrated.

CVE-2026-48025

Published Jul 28, 2026

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.7, internal/pki/resolver.go:36-64 constructs a CAManager with the pl…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2025-70873

Published Mar 12, 2026

An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafte…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-33101

Published Feb 17, 2026

IBM Concert 1.0.0 through 2.1.0 could allow an attacker to obtain sensitive information using man in the middle techniques due to improper clearing of heap memory.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1722

Published Jan 20, 2026

IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-1719

Published Jan 20, 2026

IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-1721

Published Dec 26, 2025

IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-36118

Published Nov 17, 2025

IBM Storage Virtualize 8.4, 8.5, 8.7, and 9.1 IKEv1 implementation allows remote attackers to obtain sensitive information from device memory via a Security Association (SA) negot…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-45663

Published Nov 3, 2025

An issue in NetSurf v3.11 causes the application to read uninitialized heap memory when creating a dom_event structure.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-36083

Published Oct 28, 2025

IBM Concert Software 1.0.0 through 2.0.0 could allow a local user to obtain sensitive information from buffers due to improper clearing of heap memory before release.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1759

Published Aug 18, 2025

IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-5105

Published May 23, 2025

A vulnerability was found in TOZED ZLT W51 up to 1.4.2 and classified as critical. Affected by this issue is some unknown functionality of the component Service Port 7777. The man…

CVSS 6.9 · Medium

CVE-2025-26305

Published Feb 20, 2025

A memory leak has been identified in the parseSWF_SOUNDINFO function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via a crafted SWF file.

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-26304

Published Feb 20, 2025

A memory leak has been identified in the parseSWF_EXPORTASSETS function in util/parser.c of libming v0.4.8.

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-20070

Published Nov 1, 2023

A vulnerability in the TLS 1.3 implementation of the Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 detection e…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-20031

Published Nov 1, 2023

A vulnerability in the SSL/TLS certificate handling of Snort 3 Detection Engine integration with Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remo…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-20177

Published Nov 1, 2023

A vulnerability in the SSL file policy implementation of Cisco Firepower Threat Defense (FTD) Software that occurs when the SSL/TLS connection is configured with a URL Category an…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-20 of 20 CVEsPage 1 of 1