Skip to main content

CWE archive

CWE-404 CVEs

Programmatic archive

747 CVEs tagged with CWE-4042 Critical, 181 High, 333 Medium, 231 Low, 0 Unrated.

CVE-2024-39721

Published Oct 31, 2024

An issue was discovered in Ollama before 0.1.34. The CreateModelHandler function uses os.Open to read a file until completion. The req.Path parameter is user-controlled and can be…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-21253

Published Oct 15, 2024

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.22. Easily exploitable vulnera…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-47972

Published Oct 7, 2024

Improper resource management in firmware of some Solidigm DC Products may allow an attacker to potentially control the performance of the resource.

CVSS 4.0 · Medium

CVE-2024-9399

Published Oct 1, 2024

A website configured to initiate a specially crafted WebTransport session could crash the Firefox process leading to a denial of service condition. This vulnerability affects Fire…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-46752

Published Sep 18, 2024

In the Linux kernel, the following vulnerability has been resolved: btrfs: replace BUG_ON() with error handling at update_ref_for_cow() Instead of a BUG_ON() just return an erro…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45182

Published Sep 12, 2024

An issue was discovered in WibuKey64.sys in WIBU-SYSTEMS WibuKey before v6.70 and fixed in v.6.70 An improper bounds check allows specially crafted packets to cause an arbitrary a…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7887

Published Aug 17, 2024

A vulnerability was found in LimeSurvey 6.3.0-231016 and classified as problematic. Affected by this issue is some unknown functionality of the file /index.php of the component Fi…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-38271

Published Jun 26, 2024

There exists a vulnerability in Quick Share/Nearby, where an attacker can force a victim to stay connected to a temporary hotspot created for the sharing. As part of the sequence…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2024-36856

Published Jun 12, 2024

RMQTT Broker 0.4.0 is vulnerable to Denial of Service (DoS) due to improper session resource management. An attacker can exhaust system memory and crash the daemon by establishing…

CVSS 7.5 · High

CVE-2024-31611

Published Jun 10, 2024

SeaCMS 12.9 has a file deletion vulnerability via admin_template.php.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-4013

Published Jun 6, 2024

A bug exists in the API, mesh_node_power_off(), which fails to copy the contents of the Replay Protection List (RPL) from RAM to NVM before powering down, resulting in the abilit…

CVSS 5.6 · Medium

CVE-2024-5095

Published May 19, 2024

A vulnerability classified as problematic has been found in Victor Zsviot Camera 8.26.31. This affects an unknown part of the component MQTT Packet Handler. The manipulation leads…

CVSS 7.1 · High

CVE-2024-4791

Published May 14, 2024

A vulnerability classified as critical was found in Contemporary Control System BASrouter BACnet BASRT-B 2.7.2. This vulnerability affects unknown code of the component Applicatio…

CVSS 8.7 · High

CVE-2024-33844

Published May 3, 2024

The 'control' in Parrot ANAFI USA firmware 1.10.4 does not check the MAV_MISSION_TYPE(0, 1, 2, 255), which allows attacker to cut off the connection between a controller and the d…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-48661

Published Apr 28, 2024

In the Linux kernel, the following vulnerability has been resolved: gpio: mockup: Fix potential resource leakage when register a chip If creation of software node fails, the loc…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-4292

Published Apr 27, 2024

A vulnerability classified as critical has been found in Contemporary Controls BASrouter BACnet BASRT-B 2.7.2. Affected is an unknown function of the component Device-Communicatio…

CVSS 6.5 · Medium

CVE-2024-2760

Published Apr 23, 2024

Bkav Home v7816, build 2403161130 is vulnerable to a Memory Information Leak vulnerability by triggering the 0x222240 IOCTL code of the BkavSDFlt.sys driver.

CVSS 5.5 · Medium

CVE-2024-20995

Published Apr 16, 2024

Vulnerability in the Oracle Database Sharding component of Oracle Database Server. Supported versions that are affected are 19.3-19.22 and 21.3-21.13. Easily exploitable vulnera…

CVSS 2.4 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-3764

Published Apr 14, 2024

** DISPUTED ** A vulnerability classified as problematic has been found in Tuya SDK up to 5.0.x. Affected is an unknown function of the component MQTT Packet Handler. The manipula…

CVSS 2.7 · Low

CVE-2024-3652

Published Apr 11, 2024

The Libreswan Project was notified of an issue causing libreswan to restart when using IKEv1 without specifying an esp= line. When the peer requests AES-GMAC, libreswan's default…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-26757

Published Apr 3, 2024

In the Linux kernel, the following vulnerability has been resolved: md: Don't ignore read-only array in md_check_recovery() Usually if the array is not read-write, md_check_reco…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 376-400 of 747 CVEsPage 16 of 30