openshift/ose-rhel-coreos-8

Direct Vulnerabilities

Known vulnerabilities in the openshift/ose-rhel-coreos-8 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Use After Free

*
  • H
Out-of-bounds Read

*
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • M
Integer Overflow or Wraparound

*
  • M
Out-of-bounds Write

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • L
Improper Update of Reference Count

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • L
Trust Boundary Violation

*
  • H
Resource Exhaustion

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Out-of-bounds Read

*
  • H
Out-of-bounds Read

*
  • H
Out-of-bounds Write

*
  • H
Out-of-bounds Write

*
  • H
Heap-based Buffer Overflow

*
  • L
Buffer Access with Incorrect Length Value

*
  • M
NULL Pointer Dereference

*
  • M
NULL Pointer Dereference

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Out-of-bounds Write

*
  • L
Incorrect Implementation of Authentication Algorithm

*
  • M
Excessive Platform Resource Consumption within a Loop

*
  • H
Improper Validation of Specified Quantity in Input

*
  • M
Buffer Overflow

*
  • H
Improper Handling of Unicode Encoding

*
  • M
Improper Handling of Insufficient Permissions or Privileges

*
  • L
Improper Update of Reference Count

*
  • M
Authentication Bypass

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • H
Use After Free

*
  • M
Comparison Using Wrong Factors

*
  • L
Out-of-bounds Write

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • H
Missing Release of Resource after Effective Lifetime

*
  • M
Expired Pointer Dereference

*
  • M
Improper Handling of Inconsistent Special Elements

*
  • H
Reachable Assertion

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • L
Expired Pointer Dereference

*
  • M
Origin Validation Error

*
  • H
Integer Overflow or Wraparound

*
  • H
Reachable Assertion

*
  • M
Improper Verification of Cryptographic Signature

*
  • L
Use After Free

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Out-of-bounds Write

*
  • M
NULL Pointer Dereference

*
  • M
Buffer Access with Incorrect Length Value

*
  • M
Incorrect Synchronization

*
  • M
Path Equivalence

*
  • M
Buffer Access with Incorrect Length Value

*
  • M
Out-of-bounds Read

*
  • M
Buffer Access with Incorrect Length Value

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • M
Out-of-bounds Read

*
  • M
Improper Validation of Specified Quantity in Input

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • L
NULL Pointer Dereference

*
  • L
Release of Invalid Pointer or Reference

*
  • M
Expired Pointer Dereference

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Out-of-bounds Read

*
  • M
NULL Pointer Dereference

*
  • M
NULL Pointer Dereference

*
  • M
NULL Pointer Dereference

*
  • M
NULL Pointer Dereference

*
  • L
NULL Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • M
Information Exposure

*
  • M
Race Condition

*
  • H
Algorithmic Complexity

*
  • L
Excessive Platform Resource Consumption within a Loop

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • M
Missing Lock Check

*
  • M
Improper Update of Reference Count

*
  • M
Reachable Assertion

*
  • L
NULL Pointer Dereference

*
  • M
NULL Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • M
NULL Pointer Dereference

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • L
Access of Uninitialized Pointer

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • M
NULL Pointer Dereference

*
  • M
Race Condition

*
  • M
Expired Pointer Dereference

*
  • M
Integer Overflow or Wraparound

*
  • L
Improper Update of Reference Count

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • L
Information Exposure

*
  • L
Out-of-bounds Read

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Deadlock

*
  • M
Buffer Access with Incorrect Length Value

*
  • M
Incorrect Calculation of Buffer Size

*
  • M
Authorization Bypass Through User-Controlled Key

*
  • M
Improper Update of Reference Count

*
  • M
Integer Overflow or Wraparound

*
  • M
Out-of-bounds Read

*
  • L
Improper Update of Reference Count

*
  • M
NULL Pointer Dereference

*
  • M
NULL Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • M
Improper Resource Locking

*
  • L
Time-of-check Time-of-use (TOCTOU)

*
  • M
Off-by-one Error

*
  • M
Expired Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • M
Incorrect Synchronization

*
  • L
NULL Pointer Dereference

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Integer Underflow

*
  • L
Incorrect Synchronization

*
  • M
Out-of-bounds Read

*
  • M
NULL Pointer Dereference

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • L
NULL Pointer Dereference

*
  • M
Deadlock

*
  • L
NULL Pointer Dereference

*
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Expired Pointer Dereference

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
NULL Pointer Dereference

*
  • M
Buffer Access with Incorrect Length Value

*
  • M
Access of Uninitialized Pointer

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Expired Pointer Dereference

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Out-of-bounds Read

*
  • M
Release of Invalid Pointer or Reference

*
  • M
Improper Validation of Specified Index, Position, or Offset in Input

*
  • M
Race Condition

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Link Following

*
  • M
Expired Pointer Dereference

*
  • M
Plaintext Storage of a Password

*
  • M
Link Following

*
  • L
Improper Update of Reference Count

*
  • M
Incorrect Bitwise Shift of Integer

*
  • M
Improper Null Termination

*
  • M
CVE-2026-89582

*
  • L
Improper Update of Reference Count

*
  • M
NULL Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • L
Improper Validation of Integrity Check Value

*
  • M
Expired Pointer Dereference

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Out-of-bounds Read

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Directory Traversal

*
  • H
Integer Overflow or Wraparound

*
  • M
Buffer Overflow

*
  • M
Buffer Overflow

*
  • H
Incomplete Cleanup

*
  • M
Improper Update of Reference Count

*
  • M
Comparison Using Wrong Factors

*
  • M
Access of Uninitialized Pointer

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • M
Information Exposure Through Caching

*
  • M
Misinterpretation of Input

*
  • H
Improper Preservation of Permissions

*
  • M
Expired Pointer Dereference

*
  • M
Integer Underflow

*
  • M
Expired Pointer Dereference

*
  • M
Improper Validation of Consistency within Input

*
  • M
Use of Uninitialized Resource

*
  • M
Expired Pointer Dereference

*
  • M
Access of Uninitialized Pointer

*
  • M
Out-of-bounds Read

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • H
Information Exposure

*
  • M
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • M
Race Condition

*
  • M
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • M
Use of Out-of-range Pointer Offset

*
  • M
Expired Pointer Dereference

*
  • M
NULL Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • M
Out-of-bounds Write

*
  • M
Out-of-bounds Read

*
  • M
NULL Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Read

*
  • M
Expired Pointer Dereference

*
  • M
Missing Synchronization

*
  • M
Out-of-bounds Write

*
  • M
Incorrect Calculation of Buffer Size

*
  • M
Expired Pointer Dereference

*
  • M
NULL Pointer Dereference

*
  • L
Incorrect Synchronization

*
  • M
Out-of-bounds Write

*
  • M
Out-of-bounds Write

*
  • M
NULL Pointer Dereference

*
  • H
Expired Pointer Dereference

*
  • M
Unchecked Input for Loop Condition

*
  • M
Integer Overflow or Wraparound

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Read

*
  • H
Out-of-bounds Write

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Write

*
  • H
Expired Pointer Dereference

*
  • M
Out-of-bounds Write

*
  • M
Expired Pointer Dereference

*
  • M
NULL Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Read

*
  • H
Out-of-bounds Write

*
  • H
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • H
Expired Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • M
Use of Incorrect Operator

*
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Expired Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • H
CVE-2026-89563

*
  • M
Out-of-bounds Write

*
  • M
Out-of-bounds Write

*
  • M
Expired Pointer Dereference

*
  • H
Race Condition

*
  • M
Improper Resource Locking

*
  • M
Race Condition

*
  • M
Improper Update of Reference Count

*
  • H
Time-of-check Time-of-use (TOCTOU)

*
  • L
Missing Initialization of Resource

*
  • M
Use of Uninitialized Resource

*
  • M
Improperly Implemented Security Check for Standard

*
  • H
Expired Pointer Dereference

*
  • M
Race Condition

*
  • L
Out-of-bounds Write

*
  • M
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • M
Out-of-bounds Write

*
  • M
Buffer Access with Incorrect Length Value

*
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • H
Time-of-check Time-of-use (TOCTOU)

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Improper Update of Reference Count

*
  • M
Incorrect Privilege Assignment

*
  • M
Out-of-bounds Read

*
  • M
Integer Overflow or Wraparound

*
  • H
Out-of-bounds Write

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Out-of-bounds Read

*
  • H
Improper Update of Reference Count

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Expired Pointer Dereference

*
  • M
Race Condition

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Out-of-bounds Read

*
  • H
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • M
Incorrect Synchronization

*
  • M
Integer Overflow or Wraparound

*
  • M
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • M
Out-of-bounds Write

*
  • M
Out-of-bounds Write

*
  • H
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • L
Out-of-bounds Write

*
  • M
Divide By Zero

*
  • M
Buffer Overflow

*
  • M
Out-of-bounds Write

*
  • M
Buffer Overflow

*
  • H
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • M
Incorrect Synchronization

*
  • M
NULL Pointer Dereference

*
  • M
Out-of-bounds Write

*
  • M
Expired Pointer Dereference

*
  • M
Out-of-bounds Write

*
  • M
NULL Pointer Dereference

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Improper Update of Reference Count

*
  • M
CVE-2026-89741

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Out-of-bounds Write

*
  • M
Expired Pointer Dereference

*
  • M
Race Condition

*
  • H
Out-of-bounds Read

*
  • H
Expired Pointer Dereference

*
  • M
Out-of-bounds Write

*
  • M
Out-of-bounds Read

*
  • M
Use of Uninitialized Resource

*
  • L
Improper Handling of Length Parameter Inconsistency

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • M
Incorrect Calculation of Buffer Size

*
  • M
Out-of-bounds Write

*
  • M
Expired Pointer Dereference

*
  • H
Out-of-bounds Read

*
  • M
Missing Initialization of Resource

*
  • M
Integer Underflow

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Read

*
  • M
Access of Uninitialized Pointer

*
  • M
Out-of-bounds Write

*
  • M
CVE-2026-80989

*
  • M
Out-of-bounds Write

*
  • M
Buffer Overflow

*
  • M
NULL Pointer Dereference

*
  • M
NULL Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • M
Integer Underflow

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • H
Expired Pointer Dereference

*
  • M
Improper Validation of Specified Index, Position, or Offset in Input

*
  • M
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • M
Race Condition

*
  • M
Untrusted Pointer Dereference

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • H
Buffer Overflow

*
  • M
Unchecked Input for Loop Condition

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Insufficient Granularity of Access Control

*
  • M
Expired Pointer Dereference

*
  • L
Incorrect Synchronization

*
  • H
Expired Pointer Dereference

*
  • M
Access of Uninitialized Pointer

*
  • M
Use of Uninitialized Resource

*
  • M
NULL Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • M
Access of Uninitialized Pointer

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • H
Improper Handling of Length Parameter Inconsistency

*
  • H
Out-of-bounds Read

*
  • M
Integer Underflow

*
  • M
Expired Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • M
Expired Pointer Dereference

*
  • M
Improper Cross-boundary Removal of Sensitive Data

*
  • M
Integer Overflow or Wraparound

*
  • H
Buffer Overflow

*
  • H
Information Exposure

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Comparison Using Wrong Factors

*
  • M
Resource Exhaustion

*
  • M
Out-of-bounds Write

*
  • H
OS Command Injection

*
  • L
Out-of-bounds Read

*
  • H
Out-of-bounds Write

*
  • M
Improper Certificate Validation

*
  • L
Incorrect Calculation of Buffer Size

*
  • M
Out-of-bounds Write

*
  • L
Reachable Assertion

*
  • M
Buffer Overflow

*
  • M
Information Exposure

*
  • L
Integer Overflow or Wraparound

*
  • M
Expired Pointer Dereference

*
  • M
Use of Insufficiently Random Values

*
  • M
Authentication Bypass

*
  • L
Out-of-bounds Read

*
  • H
Out-of-bounds Write

*
  • M
Incorrect Resource Transfer Between Spheres

*
  • M
Reliance on Cookies without Validation and Integrity Checking

*
  • M
Link Following

*
  • H
OS Command Injection

*
  • H
Not Failing Securely ('Failing Open')

*
  • M
Reachable Assertion

*
  • M
Out-of-bounds Write

*
  • H
Out-of-bounds Write

*
  • M
NULL Pointer Dereference

*
  • M
Integer Overflow or Wraparound

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • M
Expired Pointer Dereference

*
  • M
Integer Coercion Error

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Buffer Overflow

*
  • M
Missing Initialization of Resource

*
  • M
NULL Pointer Dereference

*
  • H
Link Following

*
  • H
Incorrect Authorization

*
  • M
Use of Blocking Code in Single-threaded, Non-blocking Context

*
  • M
Information Exposure

*
  • M
Divide By Zero

*
  • M
Use of Externally-Controlled Format String

*
  • M
Arbitrary Argument Injection

*
  • H
Directory Traversal

*
  • H
CVE-2026-89161

*
  • M
Expired Pointer Dereference

*
  • L
Incorrect Conversion between Numeric Types

*
  • M
Improper Access Control

*
  • L
Incorrect Permission Assignment for Critical Resource

*
  • L
Incorrect Calculation of Buffer Size

*
  • M
Stack-based Buffer Overflow

*
  • L
Use of Uninitialized Resource

*
  • M
Out-of-bounds Read

*
  • L
Out-of-bounds Read

*
  • H
Improper Certificate Validation

*
  • H
HTTP Request Smuggling

*
  • M
Use After Free

*
  • M
Out-of-bounds Read

*
  • L
Out-of-bounds Read

*
  • M
Integer Overflow or Wraparound

*
  • M
Heap-based Buffer Overflow

*
  • H
HTTP Request Smuggling

*
  • M
Link Following

*
  • M
Out-of-bounds Read

*
  • M
HTTP Request Smuggling

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • H
Authentication Bypass by Primary Weakness

*
  • M
Out-of-bounds Read

*
  • M
Improper Null Termination

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Buffer Overflow

*
  • H
External Control of File Name or Path

*
  • M
Directory Traversal

*
  • M
Information Exposure

*
  • L
Incorrect Implementation of Authentication Algorithm

*
  • M
Use After Free

*
  • M
Integer Overflow or Wraparound

*
  • M
Reachable Assertion

*
  • H
Out-of-bounds Write

*
  • M
Out-of-bounds Write

*
  • H
Improper Handling of Length Parameter Inconsistency

*
  • M
Use After Free

*
  • M
Directory Traversal

*
  • M
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • L
Integer Overflow or Wraparound

*
  • H
Expired Pointer Dereference

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
NULL Pointer Dereference

*
  • M
Improper Restriction of Excessive Authentication Attempts

*
  • M
Information Exposure

*
  • M
Uncontrolled Recursion

*
  • M
Improper Validation of Array Index

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

*
  • M
Improper Preservation of Permissions

*
  • M
Incorrect Privilege Assignment

*
  • M
Insufficient Verification of Data Authenticity

*
  • M
Out-of-bounds Write

*
  • L
Use of Less Trusted Source

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
CVE-2026-6368

*
  • L
Improperly Implemented Security Check for Standard

*
  • M
Integer Overflow or Wraparound

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Improper Restriction of Communication Channel to Intended Endpoints

*
  • M
CVE-2026-64535

*
  • M
Out-of-bounds Read

*
  • M
Information Exposure

*
  • M
Improper Update of Reference Count

*
  • H
Time-of-check Time-of-use (TOCTOU)

*
  • H
Link Following

*
  • M
Out-of-bounds Read

*
  • L
Information Exposure

*
  • M
Misinterpretation of Input

*
  • M
Out-of-bounds Write

*
  • M
Incorrect Calculation of Buffer Size

*
  • M
Use of Externally-Controlled Format String

*
  • L
Expired Pointer Dereference

*
  • H
Improper Control of Dynamically-Identified Variables

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Improper Validation of Specified Type of Input

*
  • M
Out-of-bounds Read

*
  • M
Buffer Overflow

*
  • M
Improper Restriction of Excessive Authentication Attempts

*
  • M
Buffer Access with Incorrect Length Value

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
OS Command Injection

*
  • H
Link Following

*
  • H
OS Command Injection

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Integer Overflow or Wraparound

*
  • M
Double Free

*
  • L
NULL Pointer Dereference

*
  • M
Directory Traversal

*
  • M
Generation of Weak Initialization Vector (IV)

*
  • M
Off-by-one Error

*
  • M
Uncontrolled Recursion

*
  • M
Out-of-bounds Write

*
  • H
Improperly Implemented Security Check for Standard

*
  • H
Time-of-check Time-of-use (TOCTOU)

*
  • L
Inappropriate Encoding for Output Context

*
  • H
Link Following

*
  • M
OS Command Injection

*
  • M
Buffer Over-read

*
  • H
Expired Pointer Dereference

*
  • L
Use After Free

*
  • M
Integer Overflow or Wraparound

*
  • L
Asymmetric Resource Consumption (Amplification)

*
  • H
Link Following

*
  • M
Link Following

*
  • H
Link Following

*
  • M
Authentication Bypass

*
  • M
Incomplete Filtering of Special Elements

*
  • M
NULL Pointer Dereference

*
  • M
Directory Traversal

*
  • L
Origin Validation Error

*
  • M
NULL Pointer Dereference

*
  • H
Out-of-bounds Read

*
  • H
Link Following

*
  • L
NULL Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • H
Expired Pointer Dereference

*
  • M
Improper Input Validation

*
  • M
Comparison Using Wrong Factors

*
  • H
OS Command Injection

*
  • M
Incorrect Bitwise Shift of Integer

*
  • H
Write-what-where Condition

*
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • H
Excessive Platform Resource Consumption within a Loop

*
  • M
Out-of-bounds Read

*
  • H
Heap-based Buffer Overflow

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Improper Certificate Validation

*
  • L
Information Exposure

*
  • H
Improper Validation of Specified Type of Input

*
  • L
Directory Traversal

*
  • M
Out-of-bounds Read

*
  • M
Expired Pointer Dereference

*
  • M
Out-of-bounds Write

*
  • H
Write-what-where Condition

*
  • L
Out-of-bounds Write

*
  • M
Out-of-bounds Write

*
  • M
Acceptance of Extraneous Untrusted Data With Trusted Data

*
  • M
Cleartext Transmission of Sensitive Information

*
  • H
Integer Overflow or Wraparound

*
  • H
Out-of-bounds Read

*
  • M
Exposure of Data Element to Wrong Session

*
  • L
Improper Privilege Management

*
  • H
Buffer Access with Incorrect Length Value

*
  • M
Expired Pointer Dereference

*
  • M
Incorrect Calculation of Buffer Size

*
  • M
Uncontrolled Recursion

*
  • M
Heap-based Buffer Overflow

*
  • L
Out-of-bounds Write

*
  • L
NULL Pointer Dereference

*
  • L
Improper Certificate Validation

*
  • M
Incorrect Calculation of Buffer Size

*
  • M
Improper Input Validation

*
  • L
Improper Validation of Integrity Check Value

*
  • L
Improper Update of Reference Count

*
  • M
Resource Exhaustion

*
  • M
Integer Overflow or Wraparound

*
  • M
NULL Pointer Dereference

*
  • M
Improper Neutralization of Null Byte or NUL Character

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • H
Link Following

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • L
Buffer Access with Incorrect Length Value

*
  • H
Write-what-where Condition

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • M
Improper Handling of Length Parameter Inconsistency

*
  • M
Incorrect Execution-Assigned Permissions

*
  • L
NULL Pointer Dereference

*
  • M
Improper Handling of Inconsistent Special Elements

*
  • M
Integer Overflow or Wraparound

*
  • L
Missing Authentication for Critical Function

*
  • M
Incorrect Calculation of Buffer Size

*
  • H
Out-of-bounds Read

*
  • M
Integer Overflow or Wraparound

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Expired Pointer Dereference

*
  • M
Improper Certificate Validation

*
  • M
Directory Traversal

*
  • H
Predictable from Observable State

*
  • H
Out-of-bounds Read

*
  • M
Buffer Overflow

*
  • L
Improper Verification of Cryptographic Signature

*
  • L
Information Exposure

*
  • L
Improper Validation of Specified Type of Input

*
  • M
Improper Validation of Consistency within Input

*
  • H
Access of Uninitialized Pointer

*
  • H
Improper Update of Reference Count

*
  • H
Access of Uninitialized Pointer

*
  • M
Out-of-bounds Read

*
  • M
Improper Validation of Integrity Check Value

*
  • M
Improper Validation of Consistency within Input

*
  • M
Expired Pointer Dereference

*
  • M
Out-of-bounds Write

*
  • L
Improper Handling of Missing Special Element

*
  • L
NULL Pointer Dereference

*
  • M
Buffer Underflow

*
  • H
Expired Pointer Dereference

*
  • M
Authentication Bypass by Primary Weakness

*
  • M
OS Command Injection

*
  • H
Insufficient Verification of Data Authenticity

*
  • L
Improper Validation of Integrity Check Value

*
  • M
Off-by-one Error

*
  • M
Acceptance of Extraneous Untrusted Data With Trusted Data

*
  • M
Reachable Assertion

*
  • M
OS Command Injection

*
  • H
Arbitrary Code Injection

*
  • M
Link Following

*
  • M
Out-of-bounds Read

*
  • L
NULL Pointer Dereference

*
  • M
Use After Free

*
  • L
Integer Overflow or Wraparound

*
  • M
NULL Pointer Dereference

*
  • M
Improper Validation of Syntactic Correctness of Input

*
  • M
Out-of-bounds Read

*
  • H
Excessive Platform Resource Consumption within a Loop

*
  • L
Integer Overflow or Wraparound

*
  • M
Out-of-bounds Read

*
  • H
Improper Validation of Integrity Check Value

*
  • L
Out-of-bounds Read

*
  • H
OS Command Injection

*
  • C
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • M
Information Exposure

*
  • M
Improper Certificate Validation

*
  • M
Out-of-bounds Read

*
  • M
Uncontrolled Recursion

*
  • L
Out-of-bounds Read

*
  • M
External Control of File Name or Path

*
  • L
Out-of-bounds Read

*
  • H
Out-of-bounds Read

*
  • L
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • M
Improper Handling of Insufficient Permissions or Privileges

*
  • M
Integer Underflow

*
  • M
Link Following

*
  • M
Out-of-bounds Read

*
  • L
Unchecked Input for Loop Condition

*
  • H
Improper Handling of Length Parameter Inconsistency

*
  • M
Out-of-bounds Read

*
  • M
Uncontrolled Recursion

*
  • L
Improper Verification of Cryptographic Signature

*
  • M
Integer Underflow

*
  • M
Execution with Unnecessary Privileges

*
  • M
Expired Pointer Dereference

*
  • H
Integer Underflow

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • M
Stack-based Buffer Overflow

*
  • L
Uncontrolled Recursion

*
  • H
Improper Preservation of Permissions

*
  • L
Improper Null Termination

*
  • M
Incorrect Calculation of Buffer Size

*
  • M
Off-by-one Error

*
  • M
Improper Access Control

*
  • H
Undefined Behavior for Input to API

*
  • M
Out-of-bounds Read

*
  • M
Integer Overflow or Wraparound

*
  • H
Time-of-check Time-of-use (TOCTOU)

*
  • H
Symlink Following

*
  • H
Least Privilege Violation

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • M
Improper Handling of Case Sensitivity

*
  • M
Reachable Assertion

*
  • M
Directory Traversal

*
  • L
Stack-based Buffer Overflow

*
  • M
Insufficient Verification of Data Authenticity

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • L
External Control of System or Configuration Setting

*
  • M
Integer Underflow

*
  • L
Use of Uninitialized Resource

*
  • M
Reachable Assertion

*
  • M
Link Following

*
  • H
OS Command Injection

*
  • H
Reachable Assertion

*
  • H
Improper Access Control

*
  • H
Reachable Assertion

*
  • L
Memory Leak

*
  • M
Directory Traversal

*
  • M
Uncontrolled Recursion

*
  • M
OS Command Injection

*
  • L
Incorrect Behavior Order: Early Validation

*
  • L
CVE-2026-28387

*
  • M
Buffer Overflow

*
  • M
Out-of-bounds Write

*
  • M
Expired Pointer Dereference

*
  • M
Buffer Overflow

*
  • M
Buffer Access with Incorrect Length Value

*
  • H
Numeric Truncation Error

*
  • M
Improper Handling of Case Sensitivity

*
  • M
Permissive Regular Expression

*
  • L
Out-of-bounds Read

*
  • L
Integer Overflow or Wraparound

*
  • L
OS Command Injection

*
  • H
Out-of-bounds Write

*
  • H
Improper Null Termination

*
  • L
Integer Underflow

*
  • H
Insecure Default Initialization of Resource

*
  • H
Out-of-bounds Read

*
  • M
Integer Underflow

*
  • H
Insufficient Verification of Data Authenticity

*
  • M
Memory Leak

*
  • L
Buffer Access with Incorrect Length Value

*
  • M
Incorrect Implementation of Authentication Algorithm

*
  • H
Execution with Unnecessary Privileges

*
  • L
Reachable Assertion

*
  • H
Link Following

*
  • M
Uncontrolled Recursion

*
  • M
Reachable Assertion

*
  • M
Link Following

*
  • L
Out-of-bounds Read

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Write

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • L
Out-of-bounds Read

*
  • M
Improper Validation of Specified Type of Input

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • H
Improper Validation of Consistency within Input

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • L
Out-of-bounds Write

*
  • M
NULL Pointer Dereference

*
  • M
Memory Leak

*
  • M
Buffer Overflow

*
  • H
Insufficient Verification of Data Authenticity

*
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Directory Traversal

*
  • L
Algorithmic Complexity

*
  • M
Resource Exhaustion

*
  • M
Stack-based Buffer Overflow

*
  • L
Misinterpretation of Input

*
  • M
Buffer Underflow

*
  • L
External Control of File Name or Path

*
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Directory Traversal

*
  • H
Resource Exhaustion

*
  • L
Out-of-bounds Read

*
  • M
Improper Certificate Validation

*
  • M
Out-of-bounds Write

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Read

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • L
Missing Required Cryptographic Step

*
  • M
Uncontrolled Search Path Element

*
  • H
OS Command Injection

*
  • M
Integer Overflow or Wraparound

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • L
Incorrect Calculation of Multi-Byte String Length

*
  • M
Buffer Over-read

*
  • H
Use After Free

*
  • M
Out-of-bounds Read

*
  • M
Expired Pointer Dereference

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • H
CRLF Injection

*
  • M
Out-of-bounds Read

*
  • L
Stack-based Buffer Overflow

*
  • M
Incorrect Calculation of Buffer Size

*
  • L
Expired Pointer Dereference

*
  • M
Out-of-bounds Write

*
  • L
Unchecked Input for Loop Condition

*
  • L
Incorrect Calculation of Buffer Size

*
  • M
Out-of-bounds Read

*
  • H
CRLF Injection

*
  • M
Unchecked Input for Loop Condition

*
  • M
Directory Traversal

*
  • M
NULL Pointer Dereference

*
  • M
Improper Validation of Specified Type of Input

*
  • M
Double Free

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • L
NULL Pointer Dereference

*
  • M
Incorrect Calculation

*
  • M
Information Exposure

*
  • M
Information Exposure

*
  • M
Double Free

*
  • M
NULL Pointer Dereference

*
  • H
Out-of-bounds Read

*
  • M
Directory Traversal

*
  • H
Incorrect Authorization

*
  • L
Improper Validation of Specified Index, Position, or Offset in Input

*
  • H
Link Following

*
  • M
Improper Privilege Management

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Heap-based Buffer Overflow

*
  • M
Release of Invalid Pointer or Reference

*
  • M
Out-of-bounds Read

*
  • L
Resource Exhaustion

*
  • L
Out-of-bounds Read

*
  • L
Out-of-bounds Write

*
  • M
Out-of-bounds Read

*
  • L
Use After Free

*
  • M
Missing Authentication for Critical Function

*
  • M
Link Following

*
  • M
Use After Free

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • M
Incorrect Calculation of Buffer Size

*
  • H
OS Command Injection

*
  • M
Use After Free

*
  • M
Reachable Assertion

*
  • M
Expected Behavior Violation

*
  • M
CVE-2025-61662

*
  • L
Improper Validation of Specified Quantity in Input

*
  • M
Reachable Assertion

*
  • M
Invokable Control Element in Multi-Thread Context with non-Final Static Storable or Member Element

*
  • M
Insufficient Granularity of Access Control

*
  • L
Stack-based Buffer Overflow

*
  • H
Out-of-bounds Read

*
  • M
Improper Use of Validation Framework

*
  • H
Buffer Overflow

*
  • L
Improper Certificate Validation

*
  • H
Integer Underflow

*
  • M
Improper Certificate Validation

*
  • M
Improper Check for Unusual or Exceptional Conditions

*
  • M
Heap-based Buffer Overflow

*
  • L
NULL Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • M
Unrestricted Externally Accessible Lock

*
  • H
Resource Exhaustion

*
  • H
Directory Traversal

*
  • L
NULL Pointer Dereference

*
  • M
Buffer Overflow

*
  • L
Buffer Overflow

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • L
Out-of-bounds Write

*
  • M
Return of Wrong Status Code

*
  • L
Out-of-bounds Read

*
  • L
Out-of-bounds Read

*
  • L
NULL Pointer Dereference

*
  • M
Directory Traversal

*
  • H
Out-of-bounds Read

*
  • M
Out-of-bounds Write

*
  • M
Out-of-bounds Write

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Out-of-bounds Read

*
  • H
Improper Certificate Validation

*
  • L
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • L
NULL Pointer Dereference

*
  • M
Out-of-Bounds

*
  • M
Out-of-bounds Write

*
  • L
Integer Overflow or Wraparound

*
  • L
Access of Uninitialized Pointer

*
  • H
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

*
  • L
NULL Pointer Dereference

*
  • M
Heap-based Buffer Overflow

*
  • M
Improper Certificate Validation

*
  • M
Untrusted Search Path

*
  • H
Out-of-bounds Read

*
  • M
Reversible One-Way Hash

*
  • M
OS Command Injection

*
  • H
Directory Traversal

*
  • M
Arbitrary Argument Injection

*
  • L
Arbitrary Argument Injection

*
  • L
Information Exposure

*
  • L
Improper Check for Unusual or Exceptional Conditions

*
  • M
Out-of-bounds Read

*
  • M
Directory Traversal

*
  • M
Incorrect Privilege Assignment

*
  • H
Improper Verification of Cryptographic Signature

*
  • M
Buffer Overflow

*
  • L
Heap-based Buffer Overflow

*
  • L
NULL Pointer Dereference

*
  • H
Improper Authentication

*
  • M
Creation of Temporary File With Insecure Permissions

*
  • H
Link Following

*
  • M
Integer Overflow or Wraparound

*
  • H
Stack-based Buffer Overflow

*
  • M
Out-of-bounds Write

*
  • M
Return of Wrong Status Code

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • L
Use of Uninitialized Resource

*
  • M
Improper Neutralization of Null Byte or NUL Character

*
  • L
Improperly Implemented Security Check for Standard

*
  • H
Improper Validation of Syntactic Correctness of Input

*
  • H
Resource Exhaustion

*
  • M
Integer Overflow or Wraparound

*
  • M
Expired Pointer Dereference

*
  • M
NULL Pointer Dereference

*
  • M
Use After Free

*
  • M
Acceptance of Extraneous Untrusted Data With Trusted Data

*
  • M
Expired Pointer Dereference

*
  • H
Resource Exhaustion

*
  • H
Use After Free

*
  • H
Out-of-bounds Write

*
  • M
Stack-based Buffer Overflow

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Use of Uninitialized Resource

*
  • H
Use After Free

*
  • M
Expired Pointer Dereference

*
  • H
Improper Privilege Management

*
  • H
Resource Exhaustion

*
  • H
Use of Uninitialized Resource

*
  • M
Buffer Overflow

*
  • L
Inefficient Regular Expression Complexity

*
  • M
Reachable Assertion

*
  • H
Improper Input Validation

*
  • L
Stack-based Buffer Overflow

*
  • M
Improper Validation of Integrity Check Value

*
  • H
Out-of-bounds Write

*
  • M
Information Exposure

*
  • M
NULL Pointer Dereference

*
  • H
Resource Exhaustion

*
  • M
Buffer Overflow

*
  • H
Expired Pointer Dereference

*
  • M
Algorithmic Complexity

*
  • L
Out-of-bounds Read

*
  • M
Use of Uninitialized Resource

*
  • M
Out-of-Bounds

*
  • L
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • M
Improper Validation of Specified Quantity in Input

*
  • M
Incorrect Execution-Assigned Permissions

*
  • M
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • M
Integer Overflow or Wraparound

*
  • H
Acceptance of Extraneous Untrusted Data With Trusted Data

*
  • M
Processor Optimization Removal or Modification of Security-critical Code

*
  • L
Out-of-bounds Read

*
  • L
Out-of-bounds Read

*
  • M
Improper Check for Unusual or Exceptional Conditions

*
  • L
Unchecked Return Value

*
  • H
Out-of-bounds Write

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Expired Pointer Dereference

*
  • L
Out-of-bounds Write

*
  • H
Race Condition

*
  • M
Double Free

*
  • M
Failure to Sanitize Special Element

*
  • H
Link Following

*
  • M
Directory Traversal

*
  • H
Buffer Overflow

*
  • L
Buffer Access with Incorrect Length Value

*
  • M
Out-of-bounds Read

*
  • L
NULL Pointer Dereference

*
  • L
Out-of-bounds Write

*
  • M
Integer Overflow or Wraparound

*
  • L
Use of Uninitialized Resource

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • H
Incorrect Privilege Assignment

*
  • L
Authentication Bypass by Primary Weakness

*
  • H
Incorrect Privilege Assignment

*
  • H
Reachable Assertion

*
  • H
Improper Privilege Management

*
  • H
Improper Authentication

*
  • M
Improper Handling of Parameters

*
  • H
Symlink Following

*
  • M
Use of Out-of-range Pointer Offset

*
  • M
Out-of-bounds Read

*
  • L
Out-of-Bounds

*
  • M
Improper Synchronization

*
  • M
Insufficiently Protected Credentials

*
  • M
CVE-2024-26602

*
  • H
NULL Pointer Dereference

*
  • M
Use After Free

*
  • M
Buffer Overflow

*
  • M
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • H
Out-of-bounds Read

*
  • M
Expired Pointer Dereference

*
  • H
Integer Overflow or Wraparound

*
  • H
Out-of-bounds Write

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • H
Out-of-bounds Write

*
  • M
NULL Pointer Dereference

*
  • M
HTTP Request Smuggling

*
  • M
NULL Pointer Dereference

*
  • M
Improper Validation of Specified Type of Input

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*