openshift/ose-rhel-coreos-9

Direct Vulnerabilities

Known vulnerabilities in the openshift/ose-rhel-coreos-9 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
Insufficiently Protected Credentials

*
  • H
OS Command Injection

*
  • M
Improper Certificate Validation

*
  • H
Out-of-bounds Write

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • H
OS Command Injection

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Expired Pointer Dereference

*
  • M
Incorrect Behavior Order: Early Validation

*
  • M
Missing Handler

*
  • L
NULL Pointer Dereference

*
  • M
Improper Resource Locking

*
  • M
Reachable Assertion

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Race Condition

*
  • H
Reliance on Untrusted Inputs in a Security Decision

*
  • H
Expired Pointer Dereference

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
NULL Pointer Dereference

*
  • M
Incorrect Calculation of Buffer Size

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • M
Expired Pointer Dereference

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • L
Time-of-check Time-of-use (TOCTOU)

*
  • M
NULL Pointer Dereference

*
  • L
Information Exposure

*
  • M
Expired Pointer Dereference

*
  • M
Acceptance of Extraneous Untrusted Data With Trusted Data

*
  • M
Missing Lock Check

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Write

*
  • H
Expired Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • M
Access of Uninitialized Pointer

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • M
Improperly Implemented Security Check for Standard

*
  • M
Improper Update of Reference Count

*
  • L
Reachable Assertion

*
  • M
Improper Update of Reference Count

*
  • M
Reachable Assertion

*
  • M
Reachable Assertion

*
  • L
Reachable Assertion

*
  • M
Expired Pointer Dereference

*
  • M
Information Exposure

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • H
Out-of-bounds Read

*
  • L
Incorrect Privilege Assignment

*
  • H
Use After Free

*
  • M
Integer Overflow or Wraparound

*
  • L
Use of Externally-Controlled Format String

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Write

*
  • H
Out-of-bounds Write

*
  • M
Expired Pointer Dereference

*
  • L
NULL Pointer Dereference

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • M
Out-of-bounds Read

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
NULL Pointer Dereference

*
  • L
Reachable Assertion

*
  • H
Incorrect Privilege Assignment

*
  • H
Incorrect Authorization

*
  • M
Improper Handling of Structural Elements

*
  • M
Buffer Overflow

*
  • M
Incorrect Synchronization

*
  • M
Improper Validation of Array Index

*
  • M
Expired Pointer Dereference

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • M
Out-of-bounds Read

*
  • M
Buffer Access with Incorrect Length Value

*
  • M
Out-of-bounds Read

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • H
Out-of-bounds Read

*
  • M
Expired Pointer Dereference

*
  • H
Out-of-bounds Write

*
  • L
Reachable Assertion

*
  • L
Asymmetric Resource Consumption (Amplification)

*
  • M
Out-of-bounds Write

*
  • M
Out-of-bounds Write

*
  • M
Buffer Overflow

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Out-of-bounds Read

*
  • H
Link Following

*
  • M
Race Condition

*
  • M
Out-of-bounds Read

*
  • H
Double Free

*
  • M
Out-of-bounds Read

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Expired Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • M
Expired Pointer Dereference

*
  • M
Missing Synchronization

*
  • M
NULL Pointer Dereference

*
  • M
Buffer Overflow

*
  • M
Reachable Assertion

*
  • H
Integer Overflow or Wraparound

*
  • M
Out-of-bounds Read

*
  • H
Out-of-bounds Write

*
  • M
Reachable Assertion

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • L
Incorrect Permission Assignment for Critical Resource

*
  • H
Improper Handling of Missing Special Element

*
  • H
Out-of-bounds Write

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Expired Pointer Dereference

*
  • M
Out-of-bounds Write

*
  • M
Out-of-bounds Write

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Read

*
  • L
Reachable Assertion

*
  • M
Missing Lock Check

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • M
Missing Synchronization

*
  • M
Reachable Assertion

*
  • M
Expired Pointer Dereference

*
  • H
Expired Pointer Dereference

*
  • M
Deadlock

*
  • H
External Control of File Name or Path

*
  • H
Authentication Bypass

*
  • H
Link Following

*
  • H
Out-of-bounds Write

*
  • H
Link Following

*
  • H
OS Command Injection

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • H
Out-of-bounds Write

*
  • L
Incorrect Synchronization

*
  • L
NULL Pointer Dereference

*
  • H
Not Failing Securely ('Failing Open')

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • M
NULL Pointer Dereference

*
  • M
Incorrect Behavior Order: Early Validation

*
  • H
Link Following

*
  • M
CVE-2026-6368

*
  • M
NULL Pointer Dereference

*
  • M
HTTP Request Smuggling

*
  • M
Out-of-bounds Read

*
  • M
NULL Pointer Dereference

*
  • L
Reachable Assertion

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Insufficient Verification of Data Authenticity

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Read

*
  • M
Buffer Access with Incorrect Length Value

*
  • L
NULL Pointer Dereference

*
  • H
Expired Pointer Dereference

*
  • M
Divide By Zero

*
  • L
Release of Invalid Pointer or Reference

*
  • M
Incorrect Privilege Assignment

*
  • M
Incorrect Synchronization

*
  • M
Buffer Overflow

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • L
NULL Pointer Dereference

*
  • M
NULL Pointer Dereference

*
  • H
Link Following

*
  • H
Time-of-check Time-of-use (TOCTOU)

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • L
Use of Less Trusted Source

*
  • H
Link Following

*
  • L
Off-by-one Error

*
  • L
NULL Pointer Dereference

*
  • H
Arbitrary Code Injection

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • M
Double Free

*
  • M
Out-of-bounds Write

*
  • M
Use After Free

*
  • M
Permissive Regular Expression

*
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • H
Incorrect Privilege Assignment

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Out-of-bounds Write

*
  • M
Use of Out-of-range Pointer Offset

*
  • M
Arbitrary Code Injection

*
  • H
Information Exposure

*
  • M
Use After Free

*
  • M
Use of Insufficiently Random Values

*
  • M
Improper Access Control

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Resource Exhaustion

*
  • H
Arbitrary Code Injection

*
  • M
Buffer Access with Incorrect Length Value

*
  • M
Out-of-bounds Read

*
  • M
Improper Verification of Cryptographic Signature

*
  • M
Improper Verification of Cryptographic Signature

*
  • M
Generation of Weak Initialization Vector (IV)

*
  • H
Integer Overflow or Wraparound

*
  • H
Improper Verification of Cryptographic Signature

*
  • M
Information Exposure

*
  • M
Reliance on Cookies without Validation and Integrity Checking

*
  • H
Improper Update of Reference Count

*
  • M
Integer Overflow or Wraparound

*
  • M
Improper Handling of Case Sensitivity

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • H
Use After Free

*
  • H
Integer Underflow

*
  • L
Incorrect Calculation of Buffer Size

*
  • L
Integer Overflow or Wraparound

*
  • H
Improper Validation of Specified Type of Input

*
  • H
Improperly Implemented Security Check for Standard

*
  • H
Improper Handling of Length Parameter Inconsistency

*
  • M
Directory Traversal

*
  • H
Out-of-bounds Read

*
  • H
Insufficient Verification of Data Authenticity

*
  • H
Integer Underflow

*
  • H
Improper Input Validation

*
  • H
Insufficient Verification of Data Authenticity

*
  • H
Buffer Access with Incorrect Length Value

*
  • H
Expired Pointer Dereference

*
  • M
Use After Free

*
  • H
Authentication Bypass by Primary Weakness

*
  • H
Improper Certificate Validation

*
  • H
OS Command Injection

*
  • M
NULL Pointer Dereference

*
  • H
Access of Uninitialized Pointer

*
  • M
Expired Pointer Dereference

*
  • M
Incorrect Calculation of Buffer Size

*
  • M
Buffer Overflow

*
  • M
Out-of-bounds Read

*
  • M
Integer Overflow or Wraparound

*
  • H
Expired Pointer Dereference

*
  • H
OS Command Injection

*
  • M
Improper Handling of Length Parameter Inconsistency

*
  • H
Improper Handling of Length Parameter Inconsistency

*
  • M
Improper Validation of Specified Type of Input

*
  • H
Arbitrary Argument Injection

*
  • H
OS Command Injection

*
  • M
Reachable Assertion

*
  • M
Expired Pointer Dereference

*
  • H
Off-by-one Error

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • M
Out-of-bounds Write

*
  • M
OS Command Injection

*
  • H
Improper Validation of Integrity Check Value

*
  • H
Excessive Platform Resource Consumption within a Loop

*
  • H
Use of Incorrect Operator

*
  • H
Function Call with Incorrectly Specified Arguments

*
  • M
Insufficient Verification of Data Authenticity

*
  • M
OS Command Injection

*
  • M
Directory Traversal

*
  • M
Buffer Access with Incorrect Length Value

*
  • M
NULL Pointer Dereference

*
  • L
NULL Pointer Dereference

*
  • L
NULL Pointer Dereference

*
  • M
Improper Validation of Specified Type of Input

*
  • H
Reachable Assertion

*
  • H
Resource Exhaustion

*
  • H
Symlink Following

*
  • H
NULL Pointer Dereference

*
  • M
Improper Cross-boundary Removal of Sensitive Data

*
  • M
Improper Certificate Validation

*
  • M
Use of Externally-Controlled Format String

*
  • M
Link Following

*
  • M
Integer Overflow or Wraparound

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Write

*
  • M
Directory Traversal

*
  • M
Buffer Overflow

*
  • M
Out-of-bounds Write

*
  • M
Expired Pointer Dereference

*
  • M
Arbitrary Code Injection

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • H
Arbitrary Code Injection

*
  • M
Integer Overflow or Wraparound

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Write

*
  • M
Out-of-bounds Read

*
  • H
Improper Neutralization

*
  • L
Integer Overflow or Wraparound

*
  • L
Improper Verification of Cryptographic Signature

*
  • M
Improper Restriction of Communication Channel to Intended Endpoints

*
  • L
Improper Privilege Management

*
  • M
Buffer Over-read

*
  • M
Out-of-bounds Read

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • L
Inappropriate Encoding for Output Context

*
  • L
Use After Free

*
  • H
Time-of-check Time-of-use (TOCTOU)

*
  • M
Incorrect Execution-Assigned Permissions

*
  • M
Improper Validation of Specified Type of Input

*
  • M
Off-by-one Error

*
  • M
Comparison Using Wrong Factors

*
  • L
Improper Validation of Integrity Check Value

*
  • M
Improper Validation of Syntactic Correctness of Input

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • L
Improper Certificate Validation

*
  • M
Uncontrolled Recursion

*
  • M
Execution with Unnecessary Privileges

*
  • M
NULL Pointer Dereference

*
  • M
OS Command Injection

*
  • M
XML External Entity (XXE) Injection

*
  • M
Off-by-one Error

*
  • L
Out-of-bounds Read

*
  • L
Directory Traversal

*
  • M
Incorrect Bitwise Shift of Integer

*
  • L
Improper Validation of Integrity Check Value

*
  • M
OS Command Injection

*
  • H
Expired Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • M
Improper Certificate Validation

*
  • M
Buffer Overflow

*
  • M
Out-of-bounds Read

*
  • L
Incorrect Calculation of Multi-Byte String Length

*
  • M
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • M
Out-of-bounds Read

*
  • M
Buffer Underflow

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Improper Restriction of Excessive Authentication Attempts

*
  • H
Insufficient Verification of Data Authenticity

*
  • M
Expired Pointer Dereference

*
  • M
Reachable Assertion

*
  • M
Out-of-bounds Read

*
  • L
Incorrect Behavior Order: Early Validation

*
  • M
Arbitrary Argument Injection

*
  • M
Out-of-bounds Read

*
  • M
NULL Pointer Dereference

*
  • H
Improper Control of Dynamically-Identified Variables

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Improper Handling of Exceptional Conditions

*
  • H
Link Following

*
  • M
OS Command Injection

*
  • M
Buffer Overflow

*
  • M
Improper Handling of Inconsistent Special Elements

*
  • M
Exposure of Data Element to Wrong Session

*
  • M
Buffer Overflow

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • L
Stack-based Buffer Overflow

*
  • M
Integer Overflow or Wraparound

*
  • M
Incorrect Implementation of Authentication Algorithm

*
  • H
OS Command Injection

*
  • M
Out-of-bounds Write

*
  • H
Time-of-check Time-of-use (TOCTOU)

*
  • H
Arbitrary Code Injection

*
  • M
Out-of-bounds Read

*
  • M
Memory Leak

*
  • M
Buffer Overflow

*
  • L
NULL Pointer Dereference

*
  • H
Resource Exhaustion

*
  • M
Reachable Assertion

*
  • L
Access of Uninitialized Pointer

*
  • M
Uncontrolled Recursion

*
  • M
Directory Traversal

*
  • M
Expired Pointer Dereference

*
  • M
Integer Overflow or Wraparound

*
  • M
Improper Validation of Specified Type of Input

*
  • M
Out-of-bounds Write

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • L
Algorithmic Complexity

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • L
Resource Exhaustion

*
  • L
NULL Pointer Dereference

*
  • H
OS Command Injection

*
  • H
Out-of-bounds Write

*
  • M
Acceptance of Extraneous Untrusted Data With Trusted Data

*
  • L
NULL Pointer Dereference

*
  • M
Unrestricted Externally Accessible Lock

*
  • L
Stack-based Buffer Overflow

*
  • M
Heap-based Buffer Overflow

*
  • M
Directory Traversal

*
  • M
Reachable Assertion

*
  • M
NULL Pointer Dereference

*
  • H
Improper Certificate Validation

*
  • M
Directory Traversal

*
  • M
Out-of-bounds Write

*
  • L
Information Exposure

*
  • M
NULL Pointer Dereference

*
  • L
External Control of File Name or Path

*
  • L
Inefficient Regular Expression Complexity

*
  • H
Directory Traversal

*
  • H
Use After Free

*
  • M
Buffer Underflow

*
  • L
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • M
Out-of-Bounds

*
  • L
Improper Validation of Specified Type of Input

*
  • M
Improper Null Termination

*
  • M
Integer Overflow or Wraparound

*
  • M
Improper Restriction of Excessive Authentication Attempts

*
  • M
Out-of-bounds Read

*
  • M
Incorrect Calculation of Buffer Size

*
  • M
Return of Wrong Status Code

*
  • M
Out-of-Bounds

*
  • M
Directory Traversal

*
  • M
Expired Pointer Dereference

*
  • H
Link Following

*
  • M
Out-of-bounds Read

*
  • M
Processor Optimization Removal or Modification of Security-critical Code

*
  • L
Use After Free

*
  • L
Reachable Assertion

*
  • H
Out-of-bounds Write

*
  • L
Out-of-bounds Read

*
  • M
External Control of File Name or Path

*
  • M
Algorithmic Complexity

*
  • M
Reachable Assertion

*
  • M
Improper Check for Unusual or Exceptional Conditions

*
  • H
Use After Free

*
  • L
Out-of-bounds Read

*
  • M
Out-of-bounds Write

*
  • M
Uncontrolled Recursion

*
  • M
Link Following

*
  • L
Improper Null Termination

*
  • M
CVE-2025-61662

*
  • L
Improper Handling of Missing Special Element

*
  • M
Access of Uninitialized Pointer

*
  • H
Out-of-bounds Read

*
  • M
CVE-2026-64535

*
  • M
Incorrect Calculation of Buffer Size

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Arbitrary Code Injection

*
  • L
NULL Pointer Dereference

*
  • L
Integer Overflow or Wraparound

*
  • H
Arbitrary Code Injection

*
  • M
Comparison Using Wrong Factors

*
  • M
Resource Exhaustion

*
  • L
Improper Cross-boundary Removal of Sensitive Data

*
  • M
Missing Initialization of Resource

*
  • M
Double Free

*
  • L
Out-of-bounds Read

*
  • M
Information Exposure

*
  • M
OS Command Injection

*
  • L
Authentication Bypass

*
  • M
Buffer Access with Incorrect Length Value

*
  • M
Uncontrolled Recursion

*
  • L
Improperly Implemented Security Check for Standard

*
  • M
Incorrect Execution-Assigned Permissions

*
  • M
Invokable Control Element in Multi-Thread Context with non-Final Static Storable or Member Element

*
  • M
Memory Leak

*
  • L
Out-of-Bounds

*
  • M
Out-of-bounds Read

*
  • M
Information Exposure

*
  • M
Arbitrary Argument Injection

*
  • M
Improper Neutralization of Null Byte or NUL Character

*
  • M
Stack-based Buffer Overflow

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Out-of-bounds Read

*
  • M
Improper Input Validation

*
  • M
Directory Traversal

*
  • M
Incorrect Calculation

*
  • L
Buffer Access with Incorrect Length Value

*
  • H
Arbitrary Argument Injection

*
  • H
Link Following

*
  • M
Insufficient Control of Network Message Volume (Network Amplification)

*
  • M
Cleartext Transmission of Sensitive Information

*
  • L
Improper Validation of Specified Quantity in Input

*
  • M
Reversible One-Way Hash

*
  • M
Missing Authentication for Critical Function

*
  • M
Buffer Overflow

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Improper Privilege Management

*
  • H
Out-of-bounds Read

*
  • M
Race Condition

*
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • H
Use After Free

*
  • H
Improper Input Validation

*
  • H
Expired Pointer Dereference

*
  • L
Buffer Overflow

*
  • M
Incorrect Privilege Assignment

*
  • M
Off-by-one Error

*
  • L
Expired Pointer Dereference

*
  • H
Execution with Unnecessary Privileges

*
  • M
Double Free

*
  • L
Buffer Access with Incorrect Length Value

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Out-of-bounds Write

*
  • L
NULL Pointer Dereference

*
  • M
Integer Overflow or Wraparound

*
  • H
Out-of-bounds Read

*
  • C
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • M
HTTP Request Smuggling

*
  • L
Information Exposure

*
  • L
Integer Overflow or Wraparound

*
  • M
Integer Overflow or Wraparound

*
  • M
Out-of-bounds Read

*
  • L
NULL Pointer Dereference

*
  • M
Improper Preservation of Permissions

*
  • H
Undefined Behavior for Input to API

*
  • M
Improper Finite State Machines (FSMs) in Hardware Logic

*
  • L
Use of Uninitialized Resource

*
  • M
Use of Uninitialized Resource

*
  • H
Resource Exhaustion

*
  • H
Directory Traversal

*
  • M
Integer Underflow

*
  • H
Buffer Access with Incorrect Length Value

*
  • M
Integer Overflow or Wraparound

*
  • L
Improper Update of Reference Count

*
  • L
Out-of-bounds Write

*
  • M
Link Following

*
  • L
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • M
Improper Neutralization of Null Byte or NUL Character

*
  • M
Link Following

*
  • M
Use After Free

*
  • M
Improper Access Control

*
  • M
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • L
Authentication Bypass by Primary Weakness

*
  • L
Unchecked Return Value

*
  • M
Improper Certificate Validation

*
  • M
Expired Pointer Dereference

*
  • M
Improper Input Validation

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Authentication Bypass by Primary Weakness

*
  • L
Out-of-bounds Read

*
  • M
Integer Overflow or Wraparound

*
  • M
Expected Behavior Violation

*
  • M
NULL Pointer Dereference

*
  • H
Write-what-where Condition

*
  • M
Improper Update of Reference Count

*
  • L
Out-of-bounds Write

*
  • M
Creation of Temporary File With Insecure Permissions

*
  • M
Integer Overflow or Wraparound

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • L
Out-of-bounds Write

*
  • M
Integer Underflow

*
  • H
Resource Exhaustion

*
  • M
Expired Pointer Dereference

*
  • H
Stack-based Buffer Overflow

*
  • H
Insufficient Granularity of Access Control

*
  • M
Information Exposure

*
  • M
Arbitrary Argument Injection

*
  • H
Expired Pointer Dereference

*
  • M
Uncontrolled Recursion

*
  • M
Authentication Bypass

*
  • L
Buffer Access with Incorrect Length Value

*
  • H
Out-of-bounds Read

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • M
CVE-2026-23865

*
  • M
Directory Traversal

*
  • M
Use of Uninitialized Resource

*
  • M
Misinterpretation of Input

*
  • M
Resource Exhaustion

*
  • H
Use After Free

*
  • H
Access of Uninitialized Pointer

*
  • M
Improper Validation of Integrity Check Value

*
  • M
Integer Overflow or Wraparound

*
  • M
Information Exposure

*
  • M
Double Free

*
  • H
Insufficient Granularity of Access Control

*
  • M
Improper Handling of Parameters

*
  • L
NULL Pointer Dereference

*
  • H
Resource Exhaustion

*
  • M
Integer Overflow or Wraparound

*
  • H
Improper Null Termination

*
  • L
CVE-2026-28387

*
  • M
Information Exposure

*
  • M
Integer Underflow

*
  • M
Use After Free

*
  • L
Out-of-bounds Read

*
  • H
Symlink Following

*
  • H
Predictable from Observable State

*
  • M
Buffer Overflow

*
  • M
Use After Free

*
  • M
Information Exposure

*
  • M
Improper Authorization

*
  • H
Use of Uninitialized Resource

*
  • M
Improper Input Validation

*
  • L
Missing Authentication for Critical Function

*
  • M
Information Exposure

*
  • L
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • M
Out-of-bounds Write

*
  • H
Improper Access Control

*
  • L
Misinterpretation of Input

*
  • M
Buffer Overflow

*
  • M
Improper Validation of Consistency within Input

*
  • M
Incorrect Calculation of Buffer Size

*
  • M
Improper Certificate Validation

*
  • L
Improper Verification of Cryptographic Signature

*
  • L
Incorrect Calculation of Buffer Size

*
  • M
Integer Underflow

*
  • M
Buffer Overflow

*
  • L
External Control of System or Configuration Setting

*
  • M
Integer Overflow or Wraparound

*
  • M
Information Exposure

*
  • L
Integer Underflow

*
  • M
Misinterpretation of Input

*
  • M
Out-of-bounds Read

*
  • H
Out-of-bounds Read

*
  • M
Release of Invalid Pointer or Reference

*
  • M
Failure to Sanitize Special Element

*
  • M
Detection of Error Condition Without Action

*
  • L
Integer Overflow or Wraparound

*
  • H
Use After Free

*
  • H
Improper Validation of Consistency within Input

*
  • M
Buffer Overflow

*
  • L
Memory Leak

*
  • L
Origin Validation Error

*
  • H
Link Following

*
  • L
Use of Uninitialized Resource

*
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • L
Unchecked Input for Loop Condition

*
  • M
Out-of-bounds Read

*
  • H
Resource Exhaustion

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • L
Out-of-bounds Write

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Write

*
  • H
Premature Release of Resource During Expected Lifetime

*
  • L
Out-of-bounds Write

*
  • L
Integer Overflow or Wraparound

*
  • L
Incorrect Implementation of Authentication Algorithm

*
  • M
Link Following

*
  • M
Unchecked Input for Loop Condition

*
  • M
Incorrect Calculation of Buffer Size

*
  • H
CRLF Injection

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
NULL Pointer Dereference

*
  • H
Excessive Platform Resource Consumption within a Loop

*
  • M
Use After Free

*
  • L
Heap-based Buffer Overflow

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • H
Improper Authentication

*
  • H
Integer Overflow or Wraparound

*
  • H
Expired Pointer Dereference

*
  • M
Acceptance of Extraneous Untrusted Data With Trusted Data

*
  • L
Integer Overflow or Wraparound

*
  • M
Stack-based Buffer Overflow

*
  • L
Stack-based Buffer Overflow

*
  • H
Heap-based Buffer Overflow

*
  • L
Buffer Overflow

*
  • H
Improper Privilege Management

*
  • M
Incorrect Calculation of Buffer Size

*
  • H
Improper Handling of Highly Compressed Data (Data Amplification)

*
  • H
Insecure Default Initialization of Resource

*
  • L
Uncontrolled Recursion

*
  • M
Integer Overflow or Wraparound

*
  • H
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

*
  • L
NULL Pointer Dereference

*
  • L
Expired Pointer Dereference

*
  • M
Heap-based Buffer Overflow

*
  • L
Improperly Implemented Security Check for Standard

*
  • H
Improper Update of Reference Count

*
  • M
Improper Certificate Validation

*
  • M
Out-of-bounds Write

*
  • M
Out-of-bounds Read

*
  • L
Unchecked Input for Loop Condition

*
  • H
Write-what-where Condition

*
  • L
Use of Uninitialized Resource

*
  • M
Out-of-bounds Write

*
  • H
Link Following

*
  • M
Unchecked Return Value

*
  • H
Write-what-where Condition

*
  • M
Insufficient Granularity of Access Control

*
  • M
Out-of-bounds Read

*
  • M
Directory Traversal

*
  • M
Uncontrolled Search Path Element

*
  • L
Improper Validation of Specified Index, Position, or Offset in Input

*
  • M
OS Command Injection

*
  • M
Buffer Over-read

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • L
Out-of-bounds Read

*
  • M
Directory Traversal

*
  • M
Out-of-bounds Read

*
  • M
OS Command Injection

*
  • H
Acceptance of Extraneous Untrusted Data With Trusted Data

*
  • M
Out-of-bounds Read

*
  • H
Buffer Overflow

*
  • M
Integer Overflow or Wraparound

*
  • M
Improper Validation of Specified Quantity in Input

*
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • H
Reachable Assertion

*
  • L
Out-of-bounds Read

*
  • M
Improper Validation of Integrity Check Value

*
  • M
Improper Certificate Validation

*
  • M
Integer Overflow or Wraparound

*
  • H
Improper Preservation of Permissions

*
  • H
Excessive Platform Resource Consumption within a Loop

*
  • M
Uncontrolled Recursion

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • H
Least Privilege Violation

*
  • M
Symlink Following

*
  • H
CRLF Injection

*
  • M
Double Free

*
  • H
Improper Handling of Highly Compressed Data (Data Amplification)

*
  • H
Improper Verification of Cryptographic Signature

*
  • M
Improper Check for Unusual or Exceptional Conditions

*
  • M
Uncontrolled Recursion

*
  • L
Use After Free

*
  • M
Expired Pointer Dereference

*
  • M
Integer Overflow or Wraparound

*
  • L
NULL Pointer Dereference

*
  • M
Improper Handling of Insufficient Permissions or Privileges

*
  • H
Resource Exhaustion

*
  • L
OS Command Injection

*
  • M
Out-of-bounds Read

*
  • M
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • M
Reachable Assertion

*
  • H
Memory Leak

*
  • H
Improper Authentication

*
  • M
Improper Handling of Case Sensitivity

*
  • M
Incorrect Privilege Assignment

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Incorrect Calculation of Buffer Size

*
  • L
Out-of-bounds Read

*
  • H
Reachable Assertion

*
  • M
Directory Traversal

*
  • L
NULL Pointer Dereference

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • L
Out-of-bounds Read

*
  • L
Out-of-bounds Read

*
  • M
Expired Pointer Dereference

*
  • H
Arbitrary Code Injection

*
  • M
Link Following

*
  • L
Out-of-bounds Write

*
  • H
Incorrect Privilege Assignment

*
  • M
Out-of-bounds Read

*
  • M
Unchecked Input for Loop Condition

*
  • L
Out-of-bounds Write

*
  • L
Out-of-bounds Read

*
  • H
Out-of-bounds Write

*
  • M
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • L
Stack-based Buffer Overflow

*
  • H
Numeric Truncation Error

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Reachable Assertion

*
  • M
NULL Pointer Dereference

*
  • L
Missing Required Cryptographic Step

*
  • H
Buffer Overflow

*
  • M
Double Free

*
  • H
Out-of-Bounds

*
  • H
Out-of-bounds Write

*
  • M
Resource Exhaustion

*
  • L
Arbitrary Argument Injection

*
  • M
Improper Use of Validation Framework

*
  • M
Directory Traversal

*
  • M
Out-of-bounds Write

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Return of Wrong Status Code

*
  • M
Out-of-bounds Read

*
  • M
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

*
  • L
Improper Certificate Validation

*
  • M
Untrusted Search Path

*
  • M
Heap-based Buffer Overflow

*
  • H
Out-of-bounds Read

*
  • M
Improper Certificate Validation

*
  • H
Incorrect Authorization

*
  • L
Buffer Access with Incorrect Length Value

*
  • L
Information Exposure

*
  • L
Out-of-bounds Read

*
  • M
Improper Synchronization

*
  • M
Race Condition

*
  • H
Out-of-bounds Write

*
  • L
Improper Check for Unusual or Exceptional Conditions

*
  • M
Out-of-bounds Read

*
  • M
Buffer Overflow

*
  • H
Improper Privilege Management

*
  • H
Race Condition

*
  • H
Directory Traversal

*
  • L
Out-of-bounds Read

*
  • M
CVE-2024-26602

*
  • M
Use After Free

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*