CWE-684
Incorrect Provision of Specified Functionality
The code does not function according to its published specifications, potentially leading to incorrect usage.
27 vulnerabilities with CWE-684
CVE-2026-44597
LOW
Tor < 0.4.9.7 - Out-of-Bounds Read via Malformed END/TRUNCATE/TRUNCATED Cell
CVSS 3.7
CVE-2026-40685
MEDIUM
Exim < 4.99.2 - Heap-Based Buffer Overflow via Malformed JSON Header Processing
CVSS 6.5
CVE-2026-40684
MEDIUM
Exim < 4.99.2 - Denial of Service via Malformed DNS PTR Record
CVSS 5.9
CVE-2026-42255
HIGH
Technitium DnsServer < 15.0.0 - DNS Traffic Amplification via Cyclic Name Server Delegation
CVSS 7.2
CVE-2026-35381
LOW
uutils coreutils cut Local Logic Error and Data Integrity Issue in Output Filtering
CVSS 3.3
CVE-2026-35379
LOW
uutils coreutils tr Local Logic Error and Data Integrity Issue in Character Class Handling
CVSS 3.3
CVE-2026-34478
HIGH
Apache Log4j Core: Log injection in Rfc5424Layout due to silent configuration incompatibility
CVSS 7.5
CVE-2026-3598
HIGH
RustDesk Server Pro <=1.7.5 - Info Disclosure
CVSS 7.5
CVE-2026-30791
HIGH
RustDesk Client <1.4.5 - Info Disclosure
CVSS 7.5
CVE-2025-66384
HIGH
MISP < 2.5.24 - Invalid File Upload Validation in EventsController
CVSS 8.2
CVE-2025-55174
LOW
KDE Skanpage <25.08.0 - Info Disclosure
CVSS 3.2
CVE-2025-58325
HIGH
FortiOS <7.6.0 - Privilege Escalation
CVSS 8.2
CVE-2025-54568
LOW
Akamai Rate Control alpha-2025 - Incorrect Rate Limiting via Per-Node Accounting
CVSS 3.7
CVE-2025-54567
MEDIUM
QEMU < 10.0.3 - Incorrect VF Enable Bit Write Mask Handling
CVSS 4.2
CVE-2025-47227
HIGH
Netmake ScriptCase <9.12.006 - Auth Bypass
CVSS 7.5
CVE-2024-50357
CRITICAL
FutureNet NXR-G110 21.15.7-21.15.9 & NXR-G050 21.12.5-21.12.11 - Unauthenticated REST-API Access via Default Credentials
CVSS 9.8
CVE-2024-5005
MEDIUM
GitLab EE/CE <17.2.9-17.4.2 - Info Disclosure
CVSS 4.3
CVE-2024-8974
LOW
GitLab 15.6-17.2.7, 17.3-17.3.3, 17.4-17.4.0 - Unauthenticated Private Project Path Disclosure
CVSS 2.6
CVE-2024-20317
HIGH
Cisco IOS XR - Unauthenticated Denial of Service via Ethernet Frame Classification
CVSS 7.4
CVE-2024-6502
MEDIUM
GitLab CE/EE <17.1.6-17.2.4-17.3.1 - Info Disclosure
CVSS 5.7
CVE-2024-6425
CRITICAL
MESbook 20221021.03 - Info Disclosure
CVSS 9.1
CVE-2023-5363
HIGH
OpenSSL 3.0.0-3.0.11 and 3.1.0-3.1.3 - Loss of Confidentiality via IV Truncation in Symmetric Cipher Initialization
CVSS 7.5
CVE-2023-4258
HIGH
Zephyr < 3.4.0 - Bluetooth Mesh Provisioning Authentication Bypass via Public Key Reuse
CVSS 8.6
CVE-2023-5158
MEDIUM
Linux Kernel < 5.12.19 - Denial of Service via Zero Length Descriptor in vringh_kiov_advance
CVSS 6.5
CVE-2023-24845
CRITICAL
Siemens RUGGEDCOM ROS < 4.3.8 - Unauthenticated Network Traffic Injection via Mirror Port
CVSS 9.1
Details
Vulnerabilities
27