Skip to main content

CWE archive

CWE-391 CVEs

Programmatic archive

24 CVEs tagged with CWE-39114 Critical, 3 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2025-71325

Published Jun 17, 2026

picklescan before 0.0.27 contains a parsing logic error in the _list_globals function when handling STACK_GLOBAL opcodes, failing to track arguments in the correct range and allow…

CVSS 9.3 · Critical

CVE-2024-52316

Published Nov 18, 2024

Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may th…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
24.1
Vendor/product tagsBeta · best-effort

CVE-2024-23326

Published Jun 4, 2024

Envoy is a cloud-native, open source edge and service proxy. A theoretical request smuggling vulnerability exists through Envoy if a server can be tricked into adding an upgrade h…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-22160

Published Jan 19, 2022

An Unchecked Error Condition vulnerability in the subscriber management daemon (smgd) of Juniper Networks Junos OS allows an unauthenticated adjacent attacker to cause a crash of…

CVSS 6.5 · Medium

CVE-2020-14383

Published Dec 2, 2020

A flaw was found in samba's DNS server. An authenticated user could use this flaw to the RPC server to crash. This RPC server, which also serves protocols other than dnsserver, wi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14853

Published Nov 26, 2019

An error-handling flaw was found in python-ecdsa before version 0.13.3. During signature decoding, malformed DER signatures could raise unexpected exceptions (or no exceptions at…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1091

Published Mar 27, 2018

In the flush_tmregs_to_thread function in arch/powerpc/kernel/ptrace.c in the Linux kernel before 4.13.5, a guest kernel crash can be triggered from unprivileged userspace during…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-12185

Published Jan 24, 2018

xorg-x11-server before 1.19.5 was missing length validation in MIT-SCREEN-SAVER extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-12180

Published Jan 24, 2018

xorg-x11-server before 1.19.5 was missing length validation in XFree86 VidModeExtension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-12179

Published Jan 24, 2018

xorg-x11-server before 1.19.5 was vulnerable to integer overflow in (S)ProcXIBarrierReleasePointer functions allowing malicious X client to cause X server to crash or possibly exe…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-12178

Published Jan 24, 2018

xorg-x11-server before 1.19.5 had wrong extra length check in ProcXIChangeHierarchy function allowing malicious X client to cause X server to crash or possibly execute arbitrary c…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-12177

Published Jan 24, 2018

xorg-x11-server before 1.19.5 was vulnerable to integer overflow in ProcDbeGetVisualInfo function allowing malicious X client to cause X server to crash or possibly execute arbitr…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-12176

Published Jan 24, 2018

xorg-x11-server before 1.19.5 was missing extra length validation in ProcEstablishConnection function allowing malicious X client to cause X server to crash or possibly execute ar…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-7496

Published Jun 26, 2017

fedora-arm-installer up to and including 1.99.16 is vulnerable to local privilege escalation due to lack of checking the error condition of mount operation failure on unsafely cre…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort
Showing 1-24 of 24 CVEsPage 1 of 1