Skip to main content

CWE archive

CWE-388 CVEs

Programmatic archive

42 CVEs tagged with CWE-38812 Critical, 17 High, 13 Medium, 0 Low, 0 Unrated.

CVE-2026-20168

Published May 6, 2026

A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to retrieve files that…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-20006

Published Mar 4, 2026

A vulnerability in the TLS cryptography functionality of the Snort 3 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote…

CVSS 5.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2020-3509

Published Sep 24, 2020

A vulnerability in the DHCP message handler of Cisco IOS XE Software for Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, remote attacker to cause the super…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2019-12380

Published May 28, 2019

**DISPUTED** An issue was discovered in the efi subsystem in the Linux kernel through 5.1.5. phys_efi_set_virtual_address_map in arch/x86/platform/efi/efi.c and efi_call_phys_prol…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-1750

Published Mar 28, 2019

A vulnerability in the Easy Virtual Switching System (VSS) of Cisco IOS XE Software on Catalyst 4500 Series Switches could allow an unauthenticated, adjacent attacker to cause the…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6346

Published Dec 31, 2018

A potential denial-of-service issue in the Proxygen handling of invalid HTTP2 priority settings (specifically a circular dependency). This affects Proxygen prior to v2018.12.31.00.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0415

Published Aug 15, 2018

A vulnerability in the implementation of Extensible Authentication Protocol over LAN (EAPOL) functionality in Cisco Small Business 100 Series Wireless Access Points and Cisco Smal…

CVSS 6.8 · Medium

CVE-2017-5401

Published Jun 11, 2018

A crash triggerable by web content in which an "ErrorResult" references unassigned memory due to a logic error. The resulting crash may be exploitable. This vulnerability affects…

CVSS 9.8 · Critical

CVE-2017-16014

Published Jun 4, 2018

Http-proxy is a proxying library. Because of the way errors are handled in versions before 0.7.0, an attacker that forces an error can crash the server, causing a denial of servic…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-17564

Published Dec 12, 2017

An issue was discovered in Xen through 4.9.x allowing guest OS users to cause a denial of service (host OS crash) or gain host OS privileges by leveraging incorrect error handling…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-16644

Published Nov 7, 2017

The hdpvr_probe function in drivers/media/usb/hdpvr/hdpvr-core.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (improper error handling and s…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 42 CVEsPage 1 of 2