openshift/ose-rhel-coreos-9

Direct Vulnerabilities

Known vulnerabilities in the openshift/ose-rhel-coreos-9 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
Insufficiently Protected Credentials

*
  • H
External Control of File Name or Path

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Buffer Overflow

*
  • H
Out-of-bounds Write

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • M
Reachable Assertion

*
  • M
Reachable Assertion

*
  • M
Out-of-bounds Write

*
  • M
Out-of-bounds Read

*
  • L
Time-of-check Time-of-use (TOCTOU)

*
  • L
Incorrect Permission Assignment for Critical Resource

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • L
Reachable Assertion

*
  • M
Deadlock

*
  • H
Incorrect Privilege Assignment

*
  • M
Out-of-bounds Write

*
  • H
Out-of-bounds Write

*
  • L
NULL Pointer Dereference

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • M
Incorrect Calculation of Buffer Size

*
  • M
Improper Update of Reference Count

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • L
Reachable Assertion

*
  • L
NULL Pointer Dereference

*
  • H
Double Free

*
  • L
Release of Invalid Pointer or Reference

*
  • M
Out-of-bounds Read

*
  • M
Race Condition

*
  • M
Out-of-bounds Read

*
  • M
Missing Synchronization

*
  • H
Out-of-bounds Read

*
  • H
Out-of-bounds Write

*
  • M
Incorrect Synchronization

*
  • M
Reachable Assertion

*
  • M
Out-of-bounds Read

*
  • M
Buffer Overflow

*
  • H
Link Following

*
  • M
Reachable Assertion

*
  • M
Out-of-bounds Read

*
  • M
NULL Pointer Dereference

*
  • M
Out-of-bounds Write

*
  • M
Expired Pointer Dereference

*
  • M
Reachable Assertion

*
  • M
HTTP Request Smuggling

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • H
Out-of-bounds Write

*
  • M
Out-of-bounds Read

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • M
Expired Pointer Dereference

*
  • M
Buffer Access with Incorrect Length Value

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Access of Uninitialized Pointer

*
  • M
Buffer Overflow

*
  • L
NULL Pointer Dereference

*
  • L
Incorrect Synchronization

*
  • M
Out-of-bounds Read

*
  • M
Incorrect Privilege Assignment

*
  • H
Expired Pointer Dereference

*
  • H
Out-of-bounds Read

*
  • M
Expired Pointer Dereference

*
  • M
NULL Pointer Dereference

*
  • H
Authentication Bypass

*
  • M
Expired Pointer Dereference

*
  • M
Improper Validation of Array Index

*
  • H
OS Command Injection

*
  • M
Improper Update of Reference Count

*
  • H
OS Command Injection

*
  • H
Use After Free

*
  • L
Incorrect Privilege Assignment

*
  • H
Out-of-bounds Write

*
  • M
Integer Overflow or Wraparound

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Improper Resource Locking

*
  • M
Expired Pointer Dereference

*
  • M
Missing Handler

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Out-of-bounds Read

*
  • M
NULL Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • M
Incorrect Synchronization

*
  • L
Reachable Assertion

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • H
Expired Pointer Dereference

*
  • H
Reliance on Untrusted Inputs in a Security Decision

*
  • M
Expired Pointer Dereference

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • M
NULL Pointer Dereference

*
  • H
Time-of-check Time-of-use (TOCTOU)

*
  • M
NULL Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • L
Information Exposure

*
  • M
Divide By Zero

*
  • M
Insufficient Verification of Data Authenticity

*
  • H
Link Following

*
  • M
Out-of-bounds Read

*
  • M
Information Exposure

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • L
Use of Less Trusted Source

*
  • M
CVE-2026-6368

*
  • H
OS Command Injection

*
  • M
Expired Pointer Dereference

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Incorrect Behavior Order: Early Validation

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
NULL Pointer Dereference

*
  • H
Not Failing Securely ('Failing Open')

*
  • M
Incorrect Behavior Order: Early Validation

*
  • M
NULL Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • M
Improper Handling of Structural Elements

*
  • M
Out-of-bounds Write

*
  • M
Expired Pointer Dereference

*
  • L
Reachable Assertion

*
  • H
Expired Pointer Dereference

*
  • M
Reachable Assertion

*
  • M
Missing Synchronization

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Missing Lock Check

*
  • L
NULL Pointer Dereference

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • M
Out-of-bounds Write

*
  • M
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • L
Asymmetric Resource Consumption (Amplification)

*
  • L
Reachable Assertion

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • H
Out-of-bounds Write

*
  • L
NULL Pointer Dereference

*
  • M
Improper Certificate Validation

*
  • M
Out-of-bounds Read

*
  • M
NULL Pointer Dereference

*
  • H
Incorrect Authorization

*
  • M
Out-of-bounds Read

*
  • M
Buffer Access with Incorrect Length Value

*
  • M
Double Free

*
  • M
Buffer Overflow

*
  • M
Race Condition

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Read

*
  • M
Missing Lock Check

*
  • H
Expired Pointer Dereference

*
  • H
Link Following

*
  • M
Out-of-bounds Read

*
  • L
Reachable Assertion

*
  • H
Arbitrary Code Injection

*
  • M
Improperly Implemented Security Check for Standard

*
  • H
Link Following

*
  • M
Out-of-bounds Write

*
  • L
Use of Externally-Controlled Format String

*
  • M
Acceptance of Extraneous Untrusted Data With Trusted Data

*
  • H
Out-of-bounds Write

*
  • H
Integer Overflow or Wraparound

*
  • H
Link Following

*
  • H
Improper Handling of Missing Special Element

*
  • H
Incorrect Privilege Assignment

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • H
Link Following

*
  • M
Out-of-bounds Write

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • L
Off-by-one Error

*
  • L
NULL Pointer Dereference

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • M
Use After Free

*
  • M
Out-of-bounds Write

*
  • M
Permissive Regular Expression

*
  • M
Use of Out-of-range Pointer Offset

*
  • M
Expired Pointer Dereference

*
  • M
Arbitrary Code Injection

*
  • M
Improper Access Control

*
  • M
Use After Free

*
  • H
OS Command Injection

*
  • H
Arbitrary Code Injection

*
  • M
Out-of-bounds Read

*
  • M
Buffer Access with Incorrect Length Value

*
  • M
Out-of-bounds Write

*
  • H
Improperly Implemented Security Check for Standard

*
  • H
Improper Verification of Cryptographic Signature

*
  • H
Integer Overflow or Wraparound

*
  • H
Improper Validation of Specified Type of Input

*
  • H
Access of Uninitialized Pointer

*
  • M
Use of Insufficiently Random Values

*
  • L
Integer Overflow or Wraparound

*
  • M
OS Command Injection

*
  • M
Information Exposure

*
  • M
Improper Verification of Cryptographic Signature

*
  • M
NULL Pointer Dereference

*
  • M
Integer Overflow or Wraparound

*
  • M
OS Command Injection

*
  • M
Out-of-bounds Read

*
  • H
Use After Free

*
  • M
Buffer Access with Incorrect Length Value

*
  • M
Integer Overflow or Wraparound

*
  • M
Expired Pointer Dereference

*
  • H
Expired Pointer Dereference

*
  • M
Improper Handling of Case Sensitivity

*
  • H
Information Exposure

*
  • H
Improper Certificate Validation

*
  • H
Authentication Bypass by Primary Weakness

*
  • M
NULL Pointer Dereference

*
  • M
Generation of Weak Initialization Vector (IV)

*
  • L
NULL Pointer Dereference

*
  • H
Reachable Assertion

*
  • H
OS Command Injection

*
  • H
Symlink Following

*
  • M
Insufficient Verification of Data Authenticity

*
  • H
Buffer Access with Incorrect Length Value

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • M
Reliance on Cookies without Validation and Integrity Checking

*
  • M
Resource Exhaustion

*
  • M
Improper Verification of Cryptographic Signature

*
  • M
Improper Validation of Specified Type of Input

*
  • L
NULL Pointer Dereference

*
  • H
Arbitrary Argument Injection

*
  • H
Use of Incorrect Operator

*
  • H
Improper Input Validation

*
  • M
Improper Handling of Length Parameter Inconsistency

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • H
Expired Pointer Dereference

*
  • M
Reachable Assertion

*
  • H
Excessive Platform Resource Consumption within a Loop

*
  • H
Resource Exhaustion

*
  • H
Insufficient Verification of Data Authenticity

*
  • H
Improper Update of Reference Count

*
  • L
Incorrect Calculation of Buffer Size

*
  • H
Improper Handling of Length Parameter Inconsistency

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Use After Free

*
  • H
Integer Underflow

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • M
Improper Validation of Specified Type of Input

*
  • H
Improper Handling of Length Parameter Inconsistency

*
  • M
Directory Traversal

*
  • H
OS Command Injection

*
  • H
Insufficient Verification of Data Authenticity

*
  • H
Off-by-one Error

*
  • H
Improper Validation of Integrity Check Value

*
  • H
Function Call with Incorrectly Specified Arguments

*
  • M
Incorrect Calculation of Buffer Size

*
  • M
Directory Traversal

*
  • H
NULL Pointer Dereference

*
  • H
Integer Underflow

*
  • H
Out-of-bounds Read

*
  • M
Buffer Overflow

*
  • M
Improper Certificate Validation

*
  • M
Information Exposure

*
  • M
Improper Preservation of Permissions

*
  • H
Insufficient Granularity of Access Control

*
  • M
Expired Pointer Dereference

*
  • M
Out-of-bounds Write

*
  • H
Expired Pointer Dereference

*
  • M
Arbitrary Code Injection

*
  • M
Integer Overflow or Wraparound

*
  • M
Misinterpretation of Input

*
  • M
HTTP Request Smuggling

*
  • M
Integer Overflow or Wraparound

*
  • M
Out-of-bounds Write

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Improper Input Validation

*
  • M
Out-of-bounds Read

*
  • M
Insufficient Control of Network Message Volume (Network Amplification)

*
  • H
Time-of-check Time-of-use (TOCTOU)

*
  • L
Improperly Implemented Security Check for Standard

*
  • M
Arbitrary Code Injection

*
  • M
Buffer Overflow

*
  • H
Expired Pointer Dereference

*
  • M
Out-of-bounds Write

*
  • M
Authentication Bypass

*
  • M
Out-of-bounds Read

*
  • M
Uncontrolled Recursion

*
  • H
Improper Null Termination

*
  • H
Undefined Behavior for Input to API

*
  • H
Premature Release of Resource During Expected Lifetime

*
  • M
Comparison Using Wrong Factors

*
  • H
Arbitrary Code Injection

*
  • M
Arbitrary Argument Injection

*
  • M
NULL Pointer Dereference

*
  • M
OS Command Injection

*
  • M
Integer Underflow

*
  • M
Execution with Unnecessary Privileges

*
  • M
Improper Access Control

*
  • M
OS Command Injection

*
  • M
Directory Traversal

*
  • H
Buffer Access with Incorrect Length Value

*
  • H
Least Privilege Violation

*
  • H
Out-of-bounds Read

*
  • M
Buffer Underflow

*
  • M
Improper Neutralization of Null Byte or NUL Character

*
  • H
Improper Handling of Highly Compressed Data (Data Amplification)

*
  • H
Expired Pointer Dereference

*
  • M
Buffer Overflow

*
  • H
Link Following

*
  • M
Out-of-bounds Read

*
  • M
Access of Uninitialized Pointer

*
  • H
Heap-based Buffer Overflow

*
  • L
NULL Pointer Dereference

*
  • M
Heap-based Buffer Overflow

*
  • H
Reachable Assertion

*
  • M
Integer Overflow or Wraparound

*
  • M
Link Following

*
  • M
OS Command Injection

*
  • H
Out-of-bounds Read

*
  • L
Use After Free

*
  • M
Link Following

*
  • L
CVE-2026-28387

*
  • M
Out-of-bounds Read

*
  • L
Buffer Access with Incorrect Length Value

*
  • L
Inappropriate Encoding for Output Context

*
  • C
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • M
Incorrect Calculation of Buffer Size

*
  • L
Out-of-bounds Write

*
  • M
Out-of-bounds Read

*
  • M
Uncontrolled Recursion

*
  • L
Improper Validation of Integrity Check Value

*
  • L
Out-of-bounds Read

*
  • M
XML External Entity (XXE) Injection

*
  • H
Improper Preservation of Permissions

*
  • M
Integer Underflow

*
  • M
Improper Handling of Inconsistent Special Elements

*
  • L
Missing Authentication for Critical Function

*
  • H
Execution with Unnecessary Privileges

*
  • H
Access of Uninitialized Pointer

*
  • L
Improper Cross-boundary Removal of Sensitive Data

*
  • M
Buffer Overflow

*
  • L
External Control of System or Configuration Setting

*
  • M
Heap-based Buffer Overflow

*
  • M
Improper Validation of Consistency within Input

*
  • M
Directory Traversal

*
  • L
Unchecked Input for Loop Condition

*
  • M
Resource Exhaustion

*
  • M
Improper Neutralization of Null Byte or NUL Character

*
  • L
Out-of-bounds Read

*
  • M
Buffer Overflow

*
  • M
Reachable Assertion

*
  • M
Improper Certificate Validation

*
  • L
External Control of File Name or Path

*
  • L
Incorrect Calculation of Multi-Byte String Length

*
  • M
Unrestricted Externally Accessible Lock

*
  • M
Failure to Sanitize Special Element

*
  • L
Out-of-bounds Write

*
  • M
Stack-based Buffer Overflow

*
  • L
Use After Free

*
  • M
Out-of-Bounds

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Directory Traversal

*
  • M
CVE-2026-64535

*
  • L
NULL Pointer Dereference

*
  • M
Acceptance of Extraneous Untrusted Data With Trusted Data

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Arbitrary Argument Injection

*
  • M
Integer Overflow or Wraparound

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Out-of-bounds Write

*
  • H
Use After Free

*
  • H
Out-of-bounds Write

*
  • L
Improper Validation of Specified Type of Input

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • L
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • M
NULL Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • H
Buffer Overflow

*
  • M
Out-of-bounds Read

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Read

*
  • L
Out-of-bounds Read

*
  • M
Out-of-bounds Write

*
  • M
Race Condition

*
  • L
Authentication Bypass

*
  • M
Out-of-bounds Write

*
  • L
Integer Overflow or Wraparound

*
  • M
Integer Overflow or Wraparound

*
  • M
Improper Use of Validation Framework

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Integer Overflow or Wraparound

*
  • M
Integer Overflow or Wraparound

*
  • L
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • H
Buffer Overflow

*
  • H
Use After Free

*
  • H
Improper Update of Reference Count

*
  • L
Out-of-bounds Read

*
  • M
Integer Overflow or Wraparound

*
  • M
Improper Handling of Parameters

*
  • H
Resource Exhaustion

*
  • L
Expired Pointer Dereference

*
  • L
Use After Free

*
  • L
Stack-based Buffer Overflow

*
  • M
Link Following

*
  • M
Unchecked Input for Loop Condition

*
  • M
Out-of-bounds Write

*
  • M
Out-of-bounds Write

*
  • M
Information Exposure

*
  • L
NULL Pointer Dereference

*
  • L
Out-of-bounds Read

*
  • L
Use of Uninitialized Resource

*
  • L
Improper Certificate Validation

*
  • M
Reachable Assertion

*
  • M
Insufficient Granularity of Access Control

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Improper Update of Reference Count

*
  • H
Resource Exhaustion

*
  • M
Resource Exhaustion

*
  • H
Acceptance of Extraneous Untrusted Data With Trusted Data

*
  • H
Improper Authentication

*
  • M
OS Command Injection

*
  • L
Out-of-Bounds

*
  • L
Expired Pointer Dereference

*
  • H
Arbitrary Code Injection

*
  • H
Insufficient Granularity of Access Control

*
  • H
Out-of-bounds Write

*
  • M
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

*
  • M
Improper Validation of Specified Type of Input

*
  • M
Expired Pointer Dereference

*
  • H
Improper Authentication

*
  • M
Return of Wrong Status Code

*
  • L
Misinterpretation of Input

*
  • M
Reversible One-Way Hash

*
  • M
Missing Authentication for Critical Function

*
  • H
Out-of-bounds Read

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Resource Exhaustion

*
  • M
Improper Cross-boundary Removal of Sensitive Data

*
  • L
Information Exposure

*
  • H
Improper Input Validation

*
  • L
Directory Traversal

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Improper Certificate Validation

*
  • H
Resource Exhaustion

*
  • M
Unchecked Input for Loop Condition

*
  • L
OS Command Injection

*
  • M
CVE-2024-26602

*
  • L
Origin Validation Error

*
  • H
Resource Exhaustion

*
  • M
Buffer Access with Incorrect Length Value

*
  • M
Missing Initialization of Resource

*
  • M
Buffer Overflow

*
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • H
Time-of-check Time-of-use (TOCTOU)

*
  • M
Out-of-bounds Read

*
  • M
Information Exposure

*
  • M
Integer Overflow or Wraparound

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • M
Incorrect Privilege Assignment

*
  • L
Out-of-bounds Write

*
  • M
Link Following

*
  • M
Improper Restriction of Communication Channel to Intended Endpoints

*
  • L
Integer Overflow or Wraparound

*
  • M
Incorrect Execution-Assigned Permissions

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Read

*
  • H
Insecure Default Initialization of Resource

*
  • M
Directory Traversal

*
  • L
Out-of-bounds Read

*
  • M
Out-of-bounds Read

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Information Exposure

*
  • M
Expired Pointer Dereference

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Cleartext Transmission of Sensitive Information

*
  • M
Incorrect Calculation of Buffer Size

*
  • H
Arbitrary Code Injection

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Write

*
  • M
Use After Free

*
  • L
Integer Overflow or Wraparound

*
  • M
Exposure of Data Element to Wrong Session

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • H
Improper Control of Dynamically-Identified Variables

*
  • L
Memory Leak

*
  • L
Out-of-bounds Write

*
  • M
Heap-based Buffer Overflow

*
  • L
NULL Pointer Dereference

*
  • L
Information Exposure

*
  • M
Buffer Overflow

*
  • M
Expired Pointer Dereference

*
  • M
Uncontrolled Recursion

*
  • M
Improper Validation of Syntactic Correctness of Input

*
  • L
Out-of-bounds Read

*
  • M
Double Free

*
  • L
Reachable Assertion

*
  • M
Double Free

*
  • L
Buffer Access with Incorrect Length Value

*
  • M
Use of Uninitialized Resource

*
  • H
Out-of-bounds Write

*
  • M
Off-by-one Error

*
  • L
Stack-based Buffer Overflow

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Incorrect Bitwise Shift of Integer

*
  • M
NULL Pointer Dereference

*
  • L
Out-of-bounds Write

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Uncontrolled Recursion

*
  • M
Expired Pointer Dereference

*
  • H
Out-of-bounds Read

*
  • M
Out-of-bounds Read

*
  • M
Use After Free

*
  • H
OS Command Injection

*
  • M
Unchecked Return Value

*
  • H
Improper Neutralization

*
  • L
NULL Pointer Dereference

*
  • M
Buffer Over-read

*
  • M
Out-of-bounds Write

*
  • H
CRLF Injection

*
  • M
Out-of-bounds Read

*
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Improper Input Validation

*
  • M
Expected Behavior Violation

*
  • M
Improper Certificate Validation

*
  • M
Authentication Bypass by Primary Weakness

*
  • L
Improper Validation of Integrity Check Value

*
  • L
Integer Overflow or Wraparound

*
  • L
Integer Overflow or Wraparound

*
  • L
Improper Verification of Cryptographic Signature

*
  • M
Uncontrolled Recursion

*
  • H
Incorrect Privilege Assignment

*
  • M
Information Exposure

*
  • H
Directory Traversal

*
  • M
Integer Overflow or Wraparound

*
  • H
Stack-based Buffer Overflow

*
  • M
Information Exposure

*
  • M
Integer Overflow or Wraparound

*
  • M
Out-of-bounds Read

*
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Expired Pointer Dereference

*
  • L
Improper Update of Reference Count

*
  • M
NULL Pointer Dereference

*
  • H
Excessive Platform Resource Consumption within a Loop

*
  • L
Out-of-bounds Read

*
  • M
Expired Pointer Dereference

*
  • M
Integer Overflow or Wraparound

*
  • L
NULL Pointer Dereference

*
  • L
NULL Pointer Dereference

*
  • M
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • M
Improper Validation of Integrity Check Value

*
  • M
Symlink Following

*
  • H
Link Following

*
  • M
Out-of-bounds Read

*
  • M
Buffer Overflow

*
  • M
Directory Traversal

*
  • H
Reachable Assertion

*
  • M
Improper Handling of Case Sensitivity

*
  • H
Insufficient Verification of Data Authenticity

*
  • M
Comparison Using Wrong Factors

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Misinterpretation of Input

*
  • M
Uncontrolled Recursion

*
  • M
Integer Underflow

*
  • M
Incorrect Calculation of Buffer Size

*
  • L
Stack-based Buffer Overflow

*
  • M
Double Free

*
  • M
Memory Leak

*
  • L
Incorrect Calculation of Buffer Size

*
  • M
Memory Leak

*
  • M
Integer Underflow

*
  • M
Improper Restriction of Excessive Authentication Attempts

*
  • M
Reachable Assertion

*
  • M
Integer Overflow or Wraparound

*
  • M
NULL Pointer Dereference

*
  • L
Integer Underflow

*
  • L
Improper Handling of Missing Special Element

*
  • M
Buffer Underflow

*
  • L
Out-of-bounds Read

*
  • M
Buffer Overflow

*
  • H
Out-of-bounds Read

*
  • M
Use of Externally-Controlled Format String

*
  • L
Buffer Overflow

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • M
Improper Restriction of Excessive Authentication Attempts

*
  • M
Improper Null Termination

*
  • L
Inefficient Regular Expression Complexity

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Improper Privilege Management

*
  • M
Improper Handling of Insufficient Permissions or Privileges

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Reachable Assertion

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Use After Free

*
  • L
Buffer Access with Incorrect Length Value

*
  • L
Improper Validation of Specified Index, Position, or Offset in Input

*
  • H
CRLF Injection

*
  • M
Incorrect Calculation of Buffer Size

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • M
Directory Traversal

*
  • H
Numeric Truncation Error

*
  • L
Out-of-bounds Read

*
  • L
Use of Uninitialized Resource

*
  • M
Information Exposure

*
  • M
Out-of-bounds Read

*
  • L
Unchecked Input for Loop Condition

*
  • H
Use After Free

*
  • M
Out-of-bounds Read

*
  • H
Out-of-Bounds

*
  • M
Buffer Over-read

*
  • L
Missing Required Cryptographic Step

*
  • M
Double Free

*
  • M
Out-of-bounds Write

*
  • M
Integer Overflow or Wraparound

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • M
Double Free

*
  • L
Out-of-bounds Read

*
  • M
Out-of-bounds Read

*
  • L
Stack-based Buffer Overflow

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • L
Incorrect Implementation of Authentication Algorithm

*
  • M
Incorrect Calculation of Buffer Size

*
  • M
Use of Uninitialized Resource

*
  • M
Incorrect Calculation

*
  • M
Out-of-Bounds

*
  • M
Arbitrary Argument Injection

*
  • M
NULL Pointer Dereference

*
  • M
Out-of-bounds Write

*
  • H
Out-of-bounds Read

*
  • M
Uncontrolled Search Path Element

*
  • L
Heap-based Buffer Overflow

*
  • M
Expired Pointer Dereference

*
  • H
Integer Overflow or Wraparound

*
  • M
Buffer Overflow

*
  • H
Expired Pointer Dereference

*
  • M
Race Condition

*
  • L
Improper Verification of Cryptographic Signature

*
  • L
Out-of-bounds Write

*
  • M
Out-of-bounds Read

*
  • L
Authentication Bypass by Primary Weakness

*
  • M
OS Command Injection

*
  • M
Buffer Overflow

*
  • L
Algorithmic Complexity

*
  • M
Integer Overflow or Wraparound

*
  • M
Processor Optimization Removal or Modification of Security-critical Code

*
  • M
Integer Overflow or Wraparound

*
  • L
Buffer Overflow

*
  • H
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

*
  • M
Incorrect Privilege Assignment

*
  • H
Write-what-where Condition

*
  • H
Arbitrary Argument Injection

*
  • H
Race Condition

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • L
Improper Certificate Validation

*
  • M
Incorrect Execution-Assigned Permissions

*
  • M
Directory Traversal

*
  • M
Reachable Assertion

*
  • M
Return of Wrong Status Code

*
  • L
Information Exposure

*
  • M
Acceptance of Extraneous Untrusted Data With Trusted Data

*
  • H
Resource Exhaustion

*
  • L
NULL Pointer Dereference

*
  • M
Stack-based Buffer Overflow

*
  • L
Buffer Access with Incorrect Length Value

*
  • L
Improper Validation of Specified Quantity in Input

*
  • M
Off-by-one Error

*
  • H
Use After Free

*
  • L
Unchecked Return Value

*
  • M
Use After Free

*
  • L
Integer Overflow or Wraparound

*
  • M
Off-by-one Error

*
  • L
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • H
Symlink Following

*
  • L
Use of Uninitialized Resource

*
  • M
Improper Input Validation

*
  • H
Out-of-bounds Write

*
  • M
Improper Certificate Validation

*
  • M
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

*
  • H
Arbitrary Code Injection

*
  • M
Use After Free

*
  • H
OS Command Injection

*
  • M
Improper Certificate Validation

*
  • M
CVE-2026-23865

*
  • H
Out-of-bounds Write

*
  • H
Predictable from Observable State

*
  • M
Expired Pointer Dereference

*
  • L
Out-of-bounds Read

*
  • L
Incorrect Behavior Order: Early Validation

*
  • M
External Control of File Name or Path

*
  • H
Write-what-where Condition

*
  • M
Out-of-bounds Read

*
  • M
Expired Pointer Dereference

*
  • M
Link Following

*
  • M
Out-of-bounds Read

*
  • M
Buffer Overflow

*
  • M
Incorrect Implementation of Authentication Algorithm

*
  • L
Improper Null Termination

*
  • H
Improper Validation of Consistency within Input

*
  • M
OS Command Injection

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Improper Validation of Specified Type of Input

*
  • H
Improper Access Control

*
  • M
Improper Handling of Exceptional Conditions

*
  • M
Improper Validation of Specified Quantity in Input

*
  • M
Release of Invalid Pointer or Reference

*
  • M
Directory Traversal

*
  • H
Resource Exhaustion

*
  • M
Improper Certificate Validation

*
  • L
Access of Uninitialized Pointer

*
  • L
Resource Exhaustion

*
  • M
CVE-2025-61662

*
  • H
Improper Verification of Cryptographic Signature

*
  • M
NULL Pointer Dereference

*
  • L
Out-of-bounds Read

*
  • L
NULL Pointer Dereference

*
  • M
Reachable Assertion

*
  • L
Arbitrary Argument Injection

*
  • M
Uncontrolled Recursion

*
  • L
Uncontrolled Recursion

*
  • M
Out-of-bounds Write

*
  • M
Out-of-bounds Read

*
  • M
Improper Check for Unusual or Exceptional Conditions

*
  • H
Improper Handling of Highly Compressed Data (Data Amplification)

*
  • L
NULL Pointer Dereference

*
  • M
Directory Traversal

*
  • M
Improper Synchronization

*
  • M
Invokable Control Element in Multi-Thread Context with non-Final Static Storable or Member Element

*
  • H
Use of Uninitialized Resource

*
  • L
Out-of-bounds Read

*
  • M
Untrusted Search Path

*
  • H
Incorrect Authorization

*
  • M
Directory Traversal

*
  • L
Improperly Implemented Security Check for Standard

*
  • M
Incorrect Calculation of Buffer Size

*
  • M
Directory Traversal

*
  • L
Improper Check for Unusual or Exceptional Conditions

*
  • M
Algorithmic Complexity

*
  • M
Improper Check for Unusual or Exceptional Conditions

*
  • H
Use After Free

*
  • M
Out-of-bounds Read

*
  • L
Out-of-bounds Write

*
  • H
Improper Privilege Management

*
  • M
Improper Finite State Machines (FSMs) in Hardware Logic

*
  • M
Integer Overflow or Wraparound

*
  • M
Information Exposure

*
  • M
Detection of Error Condition Without Action

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*