openshift/ose-rhel-coreos-9

Direct Vulnerabilities

Known vulnerabilities in the openshift/ose-rhel-coreos-9 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Use After Free

*
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • H
Out-of-bounds Read

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • L
Improper Update of Reference Count

*
  • L
Improper Update of Reference Count

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Out-of-bounds Read

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • H
Use After Free

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • H
Improper Handling of Unicode Encoding

*
  • M
Buffer Overflow

*
  • M
Integer Overflow or Wraparound

*
  • H
Resource Exhaustion

*
  • H
Out-of-bounds Read

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Improper Handling of Insufficient Permissions or Privileges

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • H
Improper Validation of Specified Quantity in Input

*
  • H
Improper Control of Dynamically-Identified Variables

*
  • H
Arbitrary Argument Injection

*
  • H
Improper Handling of Highly Compressed Data (Data Amplification)

*
  • M
Out-of-bounds Write

*
  • M
Expired Pointer Dereference

*
  • M
NULL Pointer Dereference

*
  • L
Trust Boundary Violation

*
  • M
Use After Free

*
  • H
Out-of-bounds Write

*
  • H
Heap-based Buffer Overflow

*
  • M
Out-of-bounds Write

*
  • L
Duplicate Operations on Resource

*
  • L
Buffer Access with Incorrect Length Value

*
  • M
NULL Pointer Dereference

*
  • L
Out-of-bounds Write

*
  • M
Insufficient Verification of Data Authenticity

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • H
Out-of-bounds Write

*
  • M
Comparison Using Wrong Factors

*
  • H
Reachable Assertion

*
  • M
Authentication Bypass

*
  • M
Excessive Platform Resource Consumption within a Loop

*
  • L
Incorrect Implementation of Authentication Algorithm

*
  • M
Improper Handling of Inconsistent Special Elements

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • L
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Origin Validation Error

*
  • M
Exposure of Data Element to Wrong Session

*
  • H
Reachable Assertion

*
  • L
Use After Free

*
  • M
Improper Verification of Cryptographic Signature

*
  • H
Integer Overflow or Wraparound

*
  • M
NULL Pointer Dereference

*
  • M
NULL Pointer Dereference

*
  • M
Improper Resource Locking

*
  • L
NULL Pointer Dereference

*
  • L
Excessive Platform Resource Consumption within a Loop

*
  • M
Incorrect Calculation of Buffer Size

*
  • M
Out-of-bounds Read

*
  • M
Improper Validation of Specified Quantity in Input

*
  • L
NULL Pointer Dereference

*
  • M
Improper Update of Reference Count

*
  • M
Improper Null Termination

*
  • L
Access of Uninitialized Pointer

*
  • L
Improper Update of Reference Count

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • M
Out-of-bounds Read

*
  • L
NULL Pointer Dereference

*
  • M
NULL Pointer Dereference

*
  • M
Improperly Controlled Modification of Dynamically-Determined Object Attributes

*
  • M
Information Exposure Through Caching

*
  • L
Information Exposure

*
  • M
Buffer Access with Incorrect Length Value

*
  • M
Buffer Access with Incorrect Length Value

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Out-of-bounds Write

*
  • L
Incorrect Synchronization

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Buffer Access with Incorrect Length Value

*
  • M
NULL Pointer Dereference

*
  • M
NULL Pointer Dereference

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Expired Pointer Dereference

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Read

*
  • M
Integer Underflow

*
  • M
Incorrect Synchronization

*
  • M
Deadlock

*
  • L
Out-of-bounds Read

*
  • M
Out-of-bounds Read

*
  • M
Incorrect Bitwise Shift of Integer

*
  • M
Reachable Assertion

*
  • M
Plaintext Storage of a Password

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • M
Buffer Access with Incorrect Length Value

*
  • M
Integer Overflow or Wraparound

*
  • M
Access of Uninitialized Pointer

*
  • M
Improper Validation of Specified Index, Position, or Offset in Input

*
  • M
CVE-2026-89582

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Expired Pointer Dereference

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Link Following

*
  • M
Link Following

*
  • M
NULL Pointer Dereference

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • L
Improper Update of Reference Count

*
  • M
Use of a Non-reentrant Function in a Concurrent Context

*
  • M
Integer Overflow or Wraparound

*
  • L
Improper Update of Reference Count

*
  • L
NULL Pointer Dereference

*
  • M
Out-of-bounds Write

*
  • M
NULL Pointer Dereference

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • L
NULL Pointer Dereference

*
  • M
NULL Pointer Dereference

*
  • M
Incorrect Synchronization

*
  • L
NULL Pointer Dereference

*
  • L
NULL Pointer Dereference

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • L
Time-of-check Time-of-use (TOCTOU)

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • M
Expired Pointer Dereference

*
  • M
Off-by-one Error

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Expired Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • M
Path Equivalence

*
  • H
Algorithmic Complexity

*
  • M
Out-of-bounds Read

*
  • M
Expired Pointer Dereference

*
  • M
NULL Pointer Dereference

*
  • M
NULL Pointer Dereference

*
  • L
Improper Update of Reference Count

*
  • M
NULL Pointer Dereference

*
  • M
Buffer Access with Incorrect Length Value

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Out-of-bounds Read

*
  • M
Expired Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • M
Improper Update of Reference Count

*
  • M
Deadlock

*
  • M
Improper Update of Reference Count

*
  • M
Race Condition

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • M
Authorization Bypass Through User-Controlled Key

*
  • M
Missing Lock Check

*
  • M
Information Exposure

*
  • M
NULL Pointer Dereference

*
  • M
NULL Pointer Dereference

*
  • M
Release of Invalid Pointer or Reference

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Out-of-bounds Read

*
  • L
Release of Invalid Pointer or Reference

*
  • H
Integer Overflow or Wraparound

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Expired Pointer Dereference

*
  • M
Race Condition

*
  • M
Buffer Overflow

*
  • M
Race Condition

*
  • L
Improper Update of Reference Count

*
  • M
NULL Pointer Dereference

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Use of Uninitialized Resource

*
  • M
Out-of-bounds Read

*
  • M
Expired Pointer Dereference

*
  • L
NULL Pointer Dereference

*
  • H
Out-of-bounds Write

*
  • M
Directory Traversal

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Out-of-bounds Read

*
  • M
Buffer Overflow

*
  • M
CRLF Injection

*
  • H
Incomplete Cleanup

*
  • M
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Expired Pointer Dereference

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • M
Buffer Access with Incorrect Length Value

*
  • M
Out-of-bounds Read

*
  • M
Expired Pointer Dereference

*
  • H
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • H
Out-of-bounds Read

*
  • L
Out-of-bounds Write

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Incorrect Privilege Assignment

*
  • M
Out-of-bounds Read

*
  • M
NULL Pointer Dereference

*
  • M
NULL Pointer Dereference

*
  • H
Expired Pointer Dereference

*
  • M
Out-of-bounds Write

*
  • M
Misinterpretation of Input

*
  • H
Expired Pointer Dereference

*
  • H
Time-of-check Time-of-use (TOCTOU)

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • M
Race Condition

*
  • M
Out-of-bounds Read

*
  • M
Improper Update of Reference Count

*
  • M
CVE-2026-89741

*
  • M
NULL Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • H
Expired Pointer Dereference

*
  • M
Integer Underflow

*
  • M
Out-of-bounds Write

*
  • M
Out-of-bounds Write

*
  • M
Out-of-bounds Write

*
  • M
Out-of-bounds Read

*
  • M
Expired Pointer Dereference

*
  • M
Race Condition

*
  • M
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Access of Uninitialized Pointer

*
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • M
Out-of-bounds Write

*
  • M
Unchecked Input for Loop Condition

*
  • H
Expired Pointer Dereference

*
  • M
NULL Pointer Dereference

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • H
Race Condition

*
  • M
Improper Update of Reference Count

*
  • M
Comparison Using Wrong Factors

*
  • M
NULL Pointer Dereference

*
  • L
Improper Handling of Length Parameter Inconsistency

*
  • M
Improper Update of Reference Count

*
  • M
Out-of-bounds Write

*
  • M
Out-of-bounds Write

*
  • H
Expired Pointer Dereference

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Write

*
  • M
Expired Pointer Dereference

*
  • M
Buffer Overflow

*
  • M
Out-of-bounds Write

*
  • H
Out-of-bounds Write

*
  • M
Race Condition

*
  • M
Expired Pointer Dereference

*
  • M
Integer Underflow

*
  • H
CVE-2026-89563

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Read

*
  • M
Buffer Overflow

*
  • M
Divide By Zero

*
  • H
Expired Pointer Dereference

*
  • M
Incorrect Calculation of Buffer Size

*
  • M
Information Exposure Through Caching

*
  • M
Improper Validation of Consistency within Input

*
  • M
Expired Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Write

*
  • M
Expired Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Write

*
  • M
Out-of-bounds Read

*
  • M
Expired Pointer Dereference

*
  • L
Incorrect Synchronization

*
  • H
Time-of-check Time-of-use (TOCTOU)

*
  • M
Expired Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • H
Out-of-bounds Write

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • M
Incorrect Synchronization

*
  • M
Expired Pointer Dereference

*
  • M
NULL Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
NULL Pointer Dereference

*
  • H
Expired Pointer Dereference

*
  • M
NULL Pointer Dereference

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Out-of-bounds Write

*
  • H
Out-of-bounds Write

*
  • M
Access of Uninitialized Pointer

*
  • H
Improper Update of Reference Count

*
  • M
Use of Uninitialized Resource

*
  • M
Out-of-bounds Read

*
  • M
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • M
Improper Update of Reference Count

*
  • M
Out-of-bounds Write

*
  • H
Improper Preservation of Permissions

*
  • M
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • M
Access of Uninitialized Pointer

*
  • M
Out-of-bounds Read

*
  • M
Missing Initialization of Resource

*
  • M
Expired Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • M
Use of Out-of-range Pointer Offset

*
  • H
Out-of-bounds Write

*
  • M
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • M
Use of Uninitialized Resource

*
  • M
Missing Synchronization

*
  • H
Expired Pointer Dereference

*
  • M
Out-of-bounds Write

*
  • M
Use of Uninitialized Resource

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Write

*
  • M
Incorrect Calculation of Buffer Size

*
  • L
Out-of-bounds Write

*
  • M
Improper Resource Locking

*
  • M
Expired Pointer Dereference

*
  • M
NULL Pointer Dereference

*
  • H
Time-of-check Time-of-use (TOCTOU)

*
  • M
Out-of-bounds Write

*
  • H
Out-of-bounds Read

*
  • M
Out-of-bounds Write

*
  • M
Expired Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • M
Expired Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • M
Improperly Implemented Security Check for Standard

*
  • M
Expired Pointer Dereference

*
  • H
Out-of-bounds Read

*
  • M
Expired Pointer Dereference

*
  • M
Integer Overflow or Wraparound

*
  • M
Race Condition

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Write

*
  • M
Use of Incorrect Operator

*
  • M
Expired Pointer Dereference

*
  • H
Information Exposure

*
  • M
Incomplete Cleanup

*
  • M
Race Condition

*
  • M
Expired Pointer Dereference

*
  • M
Out-of-bounds Write

*
  • M
Incorrect Synchronization

*
  • M
Out-of-bounds Write

*
  • M
CVE-2026-80989

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Expired Pointer Dereference

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Race Condition

*
  • M
Integer Overflow or Wraparound

*
  • M
Out-of-bounds Write

*
  • L
Missing Initialization of Resource

*
  • M
Expired Pointer Dereference

*
  • M
NULL Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • M
NULL Pointer Dereference

*
  • M
Race Condition

*
  • M
Out-of-bounds Read

*
  • L
Incorrect Synchronization

*
  • M
Use of Uninitialized Resource

*
  • M
NULL Pointer Dereference

*
  • M
Unchecked Input for Loop Condition

*
  • M
Expired Pointer Dereference

*
  • L
Integer Underflow

*
  • L
Unchecked Input for Loop Condition

*
  • M
Unchecked Return Value

*
  • M
Expired Pointer Dereference

*
  • M
Integer Underflow

*
  • M
Expired Pointer Dereference

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
NULL Pointer Dereference

*
  • M
Access of Uninitialized Pointer

*
  • M
Integer Underflow

*
  • M
Expired Pointer Dereference

*
  • M
Buffer Overflow

*
  • M
Out-of-bounds Read

*
  • H
Buffer Overflow

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • H
Expired Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • M
Access of Uninitialized Pointer

*
  • M
Access of Uninitialized Pointer

*
  • M
Expired Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • M
Expired Pointer Dereference

*
  • H
Improper Handling of Length Parameter Inconsistency

*
  • M
Expired Pointer Dereference

*
  • M
Use of Blocking Code in Single-threaded, Non-blocking Context

*
  • M
Expired Pointer Dereference

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Expired Pointer Dereference

*
  • M
Insufficient Granularity of Access Control

*
  • H
Buffer Overflow

*
  • H
Out-of-bounds Read

*
  • M
Out-of-bounds Write

*
  • M
NULL Pointer Dereference

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • H
Out-of-bounds Write

*
  • L
Out-of-bounds Read

*
  • H
Incorrect Conversion between Numeric Types

*
  • M
Use of a Non-reentrant Function in a Concurrent Context

*
  • M
Access of Uninitialized Pointer

*
  • M
Out-of-bounds Write

*
  • L
Release of Invalid Pointer or Reference

*
  • M
Improper Validation of Specified Index, Position, or Offset in Input

*
  • H
CVE-2026-89161

*
  • M
Out-of-bounds Read

*
  • L
Out-of-bounds Read

*
  • M
Untrusted Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • M
Use of Uninitialized Resource

*
  • H
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • M
Buffer Overflow

*
  • M
NULL Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • M
Authentication Bypass

*
  • H
Heap-based Buffer Overflow

*
  • M
Integer Overflow or Wraparound

*
  • M
Stack-based Buffer Overflow

*
  • L
Out-of-bounds Read

*
  • M
Heap-based Buffer Overflow

*
  • M
Link Following

*
  • H
Buffer Overflow

*
  • M
Buffer Access with Incorrect Length Value

*
  • M
Integer Coercion Error

*
  • M
NULL Pointer Dereference

*
  • M
Incorrect Permission Assignment for Critical Resource

*
  • M
Out-of-bounds Write

*
  • M
Incorrect Resource Transfer Between Spheres

*
  • M
Out-of-bounds Read

*
  • M
Uncontrolled Recursion

*
  • M
Use of Externally-Controlled Format String

*
  • H
OS Command Injection

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Write

*
  • L
Use of Uninitialized Resource

*
  • H
Out-of-bounds Write

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

*
  • H
HTTP Request Smuggling

*
  • M
Out-of-bounds Read

*
  • L
NULL Pointer Dereference

*
  • M
NULL Pointer Dereference

*
  • H
HTTP Request Smuggling

*
  • M
Directory Traversal

*
  • M
Divide By Zero

*
  • L
Incorrect Conversion between Numeric Types

*
  • L
NULL Pointer Dereference

*
  • M
Reachable Assertion

*
  • M
Off-by-one Error

*
  • M
Incomplete Filtering of Special Elements

*
  • H
Link Following

*
  • M
Incorrect Privilege Assignment

*
  • M
Directory Traversal

*
  • M
Directory Traversal

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Link Following

*
  • M
CRLF Injection

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Link Following

*
  • L
Out-of-bounds Read

*
  • M
Improper Validation of Consistency within Input

*
  • M
Out-of-bounds Read

*
  • M
Reachable Assertion

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • M
Expired Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • L
Incorrect Calculation of Buffer Size

*
  • H
Out-of-bounds Read

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • M
Insufficiently Protected Credentials

*
  • M
Expired Pointer Dereference

*
  • H
Out-of-bounds Write

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • L
Incorrect Permission Assignment for Critical Resource

*
  • H
Out-of-bounds Write

*
  • M
Out-of-bounds Read

*
  • M
Buffer Overflow

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Read

*
  • L
Incorrect Synchronization

*
  • M
Out-of-bounds Read

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Out-of-bounds Read

*
  • M
Missing Lock Check

*
  • L
Reachable Assertion

*
  • M
Incorrect Behavior Order: Early Validation

*
  • M
Reachable Assertion

*
  • L
Reachable Assertion

*
  • M
Buffer Overflow

*
  • H
Expired Pointer Dereference

*
  • M
Buffer Access with Incorrect Length Value

*
  • H
Reliance on Untrusted Inputs in a Security Decision

*
  • M
Buffer Access with Incorrect Length Value

*
  • M
Incorrect Behavior Order: Early Validation

*
  • M
Reachable Assertion

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • M
Incorrect Privilege Assignment

*
  • M
CVE-2026-6368

*
  • M
Out-of-bounds Read

*
  • M
Improperly Implemented Security Check for Standard

*
  • H
Expired Pointer Dereference

*
  • L
Release of Invalid Pointer or Reference

*
  • L
Reachable Assertion

*
  • M
NULL Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • H
Out-of-bounds Read

*
  • H
Expired Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • H
Out-of-bounds Write

*
  • H
Double Free

*
  • M
Out-of-bounds Read

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • L
Asymmetric Resource Consumption (Amplification)

*
  • L
NULL Pointer Dereference

*
  • M
Race Condition

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Write

*
  • M
NULL Pointer Dereference

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • H
Out-of-bounds Write

*
  • M
NULL Pointer Dereference

*
  • L
NULL Pointer Dereference

*
  • M
Insufficient Verification of Data Authenticity

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • M
Improper Update of Reference Count

*
  • H
Link Following

*
  • L
Reachable Assertion

*
  • H
Expired Pointer Dereference

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • H
Integer Overflow or Wraparound

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • M
Out-of-bounds Write

*
  • M
Reachable Assertion

*
  • M
Expired Pointer Dereference

*
  • M
Reachable Assertion

*
  • L
NULL Pointer Dereference

*
  • M
Improper Update of Reference Count

*
  • M
Improper Resource Locking

*
  • H
Not Failing Securely ('Failing Open')

*
  • L
Reachable Assertion

*
  • L
NULL Pointer Dereference

*
  • H
Link Following

*
  • H
Out-of-bounds Write

*
  • M
Out-of-bounds Write

*
  • M
NULL Pointer Dereference

*
  • M
Missing Lock Check

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Out-of-bounds Read

*
  • H
Improper Handling of Missing Special Element

*
  • M
Access of Uninitialized Pointer

*
  • H
Out-of-bounds Write

*
  • M
Integer Overflow or Wraparound

*
  • L
Use of Less Trusted Source

*
  • H
Incorrect Authorization

*
  • M
Divide By Zero

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
NULL Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • M
Missing Synchronization

*
  • M
Expired Pointer Dereference

*
  • L
Incorrect Privilege Assignment

*
  • M
Incorrect Calculation of Buffer Size

*
  • H
Out-of-bounds Write

*
  • M
Information Exposure

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
NULL Pointer Dereference

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • L
Time-of-check Time-of-use (TOCTOU)

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • M
Out-of-bounds Write

*
  • M
Expired Pointer Dereference

*
  • L
NULL Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • M
Expired Pointer Dereference

*
  • M
Incorrect Synchronization

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • M
Out-of-bounds Read

*
  • H
Link Following

*
  • M
Improper Handling of Structural Elements

*
  • M
Out-of-bounds Read

*
  • M
Incorrect Synchronization

*
  • M
Expired Pointer Dereference

*
  • M
NULL Pointer Dereference

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • M
Out-of-bounds Read

*
  • H
Link Following

*
  • H
Out-of-bounds Read

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • L
Use of Externally-Controlled Format String

*
  • H
OS Command Injection

*
  • H
Link Following

*
  • H
Use After Free

*
  • M
Out-of-bounds Read

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Improper Certificate Validation

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • H
Link Following

*
  • M
Deadlock

*
  • M
Out-of-bounds Write

*
  • M
NULL Pointer Dereference

*
  • M
Missing Handler

*
  • M
Expired Pointer Dereference

*
  • M
Race Condition

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • M
Out-of-bounds Write

*
  • M
Expired Pointer Dereference

*
  • M
Improper Validation of Array Index

*
  • H
Expired Pointer Dereference

*
  • M
Missing Synchronization

*
  • M
Reachable Assertion

*
  • H
Arbitrary Code Injection

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • H
Authentication Bypass

*
  • M
Buffer Overflow

*
  • H
Incorrect Privilege Assignment

*
  • L
Off-by-one Error

*
  • M
Reachable Assertion

*
  • M
Permissive Regular Expression

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Buffer Overflow

*
  • L
Reachable Assertion

*
  • M
HTTP Request Smuggling

*
  • M
Acceptance of Extraneous Untrusted Data With Trusted Data

*
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • L
Information Exposure

*
  • H
Time-of-check Time-of-use (TOCTOU)

*
  • M
Use After Free

*
  • L
NULL Pointer Dereference

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Out-of-bounds Write

*
  • M
Double Free

*
  • M
Out-of-bounds Write

*
  • M
Use of Out-of-range Pointer Offset

*
  • H
Improperly Implemented Security Check for Standard

*
  • M
Expired Pointer Dereference

*
  • H
Authentication Bypass by Primary Weakness

*
  • H
Information Exposure

*
  • M
Information Exposure

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Resource Exhaustion

*
  • M
Improper Verification of Cryptographic Signature

*
  • H
Improper Validation of Specified Type of Input

*
  • M
OS Command Injection

*
  • H
Improper Verification of Cryptographic Signature

*
  • H
Improper Certificate Validation

*
  • L
Incorrect Calculation of Buffer Size

*
  • H
Access of Uninitialized Pointer

*
  • M
Improper Verification of Cryptographic Signature

*
  • H
Improper Update of Reference Count

*
  • M
NULL Pointer Dereference

*
  • M
Integer Overflow or Wraparound

*
  • M
Use After Free

*
  • M
Use of Insufficiently Random Values

*
  • M
Improper Access Control

*
  • H
Expired Pointer Dereference

*
  • M
Improper Handling of Case Sensitivity

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • H
Buffer Access with Incorrect Length Value

*
  • H
Out-of-bounds Read

*
  • M
Expired Pointer Dereference

*
  • M
Reliance on Cookies without Validation and Integrity Checking

*
  • H
Integer Underflow

*
  • H
Improper Input Validation

*
  • M
Out-of-bounds Write

*
  • L
Integer Overflow or Wraparound

*
  • M
Buffer Access with Incorrect Length Value

*
  • M
Directory Traversal

*
  • H
Reachable Assertion

*
  • M
Out-of-bounds Read

*
  • H
Excessive Platform Resource Consumption within a Loop

*
  • H
Improper Validation of Integrity Check Value

*
  • H
OS Command Injection

*
  • M
Incorrect Calculation of Buffer Size

*
  • H
Resource Exhaustion

*
  • H
Use of Incorrect Operator

*
  • M
Improper Handling of Length Parameter Inconsistency

*
  • M
Generation of Weak Initialization Vector (IV)

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • H
NULL Pointer Dereference

*
  • H
OS Command Injection

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • H
Function Call with Incorrectly Specified Arguments

*
  • M
Insufficient Verification of Data Authenticity

*
  • H
OS Command Injection

*
  • M
Use After Free

*
  • H
Improper Handling of Length Parameter Inconsistency

*
  • H
Improper Handling of Length Parameter Inconsistency

*
  • M
Buffer Access with Incorrect Length Value

*
  • H
Integer Underflow

*
  • M
Out-of-bounds Read

*
  • M
Improper Validation of Specified Type of Input

*
  • L
NULL Pointer Dereference

*
  • L
NULL Pointer Dereference

*
  • H
Integer Overflow or Wraparound

*
  • M
Integer Overflow or Wraparound

*
  • H
Off-by-one Error

*
  • H
Insufficient Verification of Data Authenticity

*
  • H
Symlink Following

*
  • M
OS Command Injection

*
  • H
Use After Free

*
  • M
Directory Traversal

*
  • H
Insufficient Verification of Data Authenticity

*
  • M
Reachable Assertion

*
  • M
Buffer Overflow

*
  • M
Improper Certificate Validation

*
  • M
Expired Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • L
Information Exposure

*
  • M
Buffer Access with Incorrect Length Value

*
  • M
Out-of-bounds Write

*
  • M
Integer Overflow or Wraparound

*
  • M
Integer Overflow or Wraparound

*
  • M
Improper Input Validation

*
  • M
Arbitrary Code Injection

*
  • M
Out-of-bounds Read

*
  • M
Directory Traversal

*
  • M
Cleartext Transmission of Sensitive Information

*
  • L
Use After Free

*
  • M
Improper Preservation of Permissions

*
  • L
Improperly Implemented Security Check for Standard

*
  • M
Improper Restriction of Excessive Authentication Attempts

*
  • M
Integer Overflow or Wraparound

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Out-of-bounds Write

*
  • M
Out-of-bounds Write

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Out-of-bounds Read

*
  • M
Improper Cross-boundary Removal of Sensitive Data

*
  • M
Reachable Assertion

*
  • L
Out-of-bounds Read

*
  • M
Comparison Using Wrong Factors

*
  • M
Double Free

*
  • M
Authentication Bypass

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Incorrect Execution-Assigned Permissions

*
  • H
Link Following

*
  • M
Buffer Overflow

*
  • M
Insufficient Control of Network Message Volume (Network Amplification)

*
  • M
Improper Neutralization of Null Byte or NUL Character

*
  • H
Improper Neutralization

*
  • M
Incorrect Privilege Assignment

*
  • H
Improper Preservation of Permissions

*
  • L
Improper Verification of Cryptographic Signature

*
  • H
Improper Handling of Highly Compressed Data (Data Amplification)

*
  • L
Expired Pointer Dereference

*
  • L
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • H
Improper Update of Reference Count

*
  • L
OS Command Injection

*
  • L
Incorrect Implementation of Authentication Algorithm

*
  • M
Information Exposure

*
  • L
Integer Overflow or Wraparound

*
  • M
Arbitrary Argument Injection

*
  • M
Buffer Overflow

*
  • H
Expired Pointer Dereference

*
  • H
OS Command Injection

*
  • M
Integer Overflow or Wraparound

*
  • H
Expired Pointer Dereference

*
  • L
Incorrect Calculation of Multi-Byte String Length

*
  • M
Use of Externally-Controlled Format String

*
  • M
Improper Handling of Insufficient Permissions or Privileges

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Out-of-bounds Read

*
  • L
Stack-based Buffer Overflow

*
  • L
Buffer Access with Incorrect Length Value

*
  • L
Improper Validation of Integrity Check Value

*
  • M
Out-of-bounds Read

*
  • M
HTTP Request Smuggling

*
  • M
Heap-based Buffer Overflow

*
  • M
Improper Certificate Validation

*
  • M
Improper Null Termination

*
  • M
Missing Initialization of Resource

*
  • L
Improper Validation of Specified Type of Input

*
  • M
Improper Privilege Management

*
  • M
Use of Uninitialized Resource

*
  • M
Out-of-bounds Write

*
  • M
Incorrect Bitwise Shift of Integer

*
  • M
Directory Traversal

*
  • M
Buffer Overflow

*
  • L
Stack-based Buffer Overflow

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • L
Unchecked Input for Loop Condition

*
  • M
Release of Invalid Pointer or Reference

*
  • M
CVE-2026-64535

*
  • L
Incorrect Calculation of Buffer Size

*
  • M
Arbitrary Code Injection

*
  • L
Use of Uninitialized Resource

*
  • M
Use After Free

*
  • M
Incorrect Calculation of Buffer Size

*
  • H
Excessive Platform Resource Consumption within a Loop

*
  • L
External Control of System or Configuration Setting

*
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • L
Improper Update of Reference Count

*
  • M
Access of Uninitialized Pointer

*
  • M
Expired Pointer Dereference

*
  • M
Improper Validation of Specified Type of Input

*
  • L
Buffer Access with Incorrect Length Value

*
  • M
Out-of-bounds Read

*
  • L
CVE-2026-28387

*
  • H
Predictable from Observable State

*
  • M
Reachable Assertion

*
  • L
Incorrect Behavior Order: Early Validation

*
  • M
Integer Overflow or Wraparound

*
  • M
Expired Pointer Dereference

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
NULL Pointer Dereference

*
  • H
Out-of-bounds Write

*
  • L
Origin Validation Error

*
  • M
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • L
Missing Authentication for Critical Function

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Information Exposure

*
  • H
CRLF Injection

*
  • L
NULL Pointer Dereference

*
  • H
Access of Uninitialized Pointer

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Out-of-bounds Read

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Directory Traversal

*
  • L
Improper Null Termination

*
  • M
NULL Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • M
OS Command Injection

*
  • M
Uncontrolled Recursion

*
  • M
Link Following

*
  • M
Improper Restriction of Communication Channel to Intended Endpoints

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Read

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • H
Expired Pointer Dereference

*
  • H
Improper Access Control

*
  • M
OS Command Injection

*
  • M
Integer Underflow

*
  • H
Out-of-bounds Read

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • H
Improper Null Termination

*
  • L
Integer Overflow or Wraparound

*
  • M
Buffer Over-read

*
  • M
Double Free

*
  • L
NULL Pointer Dereference

*
  • M
Information Exposure

*
  • H
Time-of-check Time-of-use (TOCTOU)

*
  • M
Out-of-bounds Read

*
  • H
Directory Traversal

*
  • M
Integer Overflow or Wraparound

*
  • M
Improper Certificate Validation

*
  • M
Integer Overflow or Wraparound

*
  • H
Undefined Behavior for Input to API

*
  • H
Stack-based Buffer Overflow

*
  • M
Reversible One-Way Hash

*
  • C
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • M
Out-of-bounds Read

*
  • M
Improper Certificate Validation

*
  • L
NULL Pointer Dereference

*
  • M
Out-of-bounds Write

*
  • L
Stack-based Buffer Overflow

*
  • H
Time-of-check Time-of-use (TOCTOU)

*
  • L
Inefficient Regular Expression Complexity

*
  • M
Improper Access Control

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • L
Access of Uninitialized Pointer

*
  • M
Out-of-bounds Read

*
  • M
Integer Overflow or Wraparound

*
  • M
Acceptance of Extraneous Untrusted Data With Trusted Data

*
  • M
Out-of-bounds Read

*
  • H
Heap-based Buffer Overflow

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Use After Free

*
  • M
Improper Update of Reference Count

*
  • M
Incorrect Calculation of Buffer Size

*
  • M
Off-by-one Error

*
  • M
Information Exposure

*
  • M
Buffer Over-read

*
  • L
Out-of-bounds Write

*
  • M
Integer Overflow or Wraparound

*
  • M
NULL Pointer Dereference

*
  • L
Memory Leak

*
  • M
Authentication Bypass by Primary Weakness

*
  • M
Buffer Overflow

*
  • H
Buffer Access with Incorrect Length Value

*
  • M
Link Following

*
  • M
Improper Input Validation

*
  • H
OS Command Injection

*
  • H
Arbitrary Code Injection

*
  • M
Use After Free

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • M
Improper Handling of Inconsistent Special Elements

*
  • L
NULL Pointer Dereference

*
  • H
Arbitrary Code Injection

*
  • H
Write-what-where Condition

*
  • M
Improper Validation of Syntactic Correctness of Input

*
  • M
Improper Restriction of Excessive Authentication Attempts

*
  • M
Link Following

*
  • M
Out-of-bounds Write

*
  • M
OS Command Injection

*
  • M
XML External Entity (XXE) Injection

*
  • M
Exposure of Data Element to Wrong Session

*
  • M
OS Command Injection

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • L
Out-of-bounds Write

*
  • M
Out-of-bounds Read

*
  • M
Integer Overflow or Wraparound

*
  • M
Double Free

*
  • M
Comparison Using Wrong Factors

*
  • M
Directory Traversal

*
  • M
Improper Validation of Specified Quantity in Input

*
  • M
Arbitrary Argument Injection

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Read

*
  • H
Write-what-where Condition

*
  • M
NULL Pointer Dereference

*
  • M
Buffer Overflow

*
  • M
Directory Traversal

*
  • L
Integer Overflow or Wraparound

*
  • M
Directory Traversal

*
  • L
Improper Validation of Integrity Check Value

*
  • L
Misinterpretation of Input

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Directory Traversal

*
  • M
Uncontrolled Recursion

*
  • L
Authentication Bypass

*
  • M
Improper Validation of Integrity Check Value

*
  • L
NULL Pointer Dereference

*
  • M
Uncontrolled Recursion

*
  • H
Out-of-bounds Read

*
  • H
Out-of-bounds Read

*
  • M
Expired Pointer Dereference

*
  • M
Incorrect Calculation of Buffer Size

*
  • L
NULL Pointer Dereference

*
  • H
Buffer Overflow

*
  • H
Arbitrary Code Injection

*
  • M
Integer Overflow or Wraparound

*
  • M
Out-of-bounds Write

*
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • H
Race Condition

*
  • L
NULL Pointer Dereference

*
  • H
Improper Privilege Management

*
  • M
Memory Leak

*
  • L
Use After Free

*
  • H
Reachable Assertion

*
  • H
Arbitrary Code Injection

*
  • H
Use of Uninitialized Resource

*
  • M
Buffer Overflow

*
  • M
Memory Leak

*
  • L
Out-of-bounds Read

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • L
Use After Free

*
  • L
Out-of-bounds Write

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • L
Improper Cross-boundary Removal of Sensitive Data

*
  • H
Execution with Unnecessary Privileges

*
  • M
Improper Certificate Validation

*
  • L
Stack-based Buffer Overflow

*
  • M
Heap-based Buffer Overflow

*
  • M
Out-of-bounds Read

*
  • H
Symlink Following

*
  • M
Improper Validation of Consistency within Input

*
  • H
Out-of-bounds Write

*
  • M
Uncontrolled Recursion

*
  • M
Out-of-bounds Write

*
  • M
NULL Pointer Dereference

*
  • L
Inappropriate Encoding for Output Context

*
  • L
Buffer Overflow

*
  • M
Use After Free

*
  • M
Integer Underflow

*
  • H
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

*
  • M
Incorrect Calculation of Buffer Size

*
  • L
Improper Certificate Validation

*
  • L
Integer Overflow or Wraparound

*
  • M
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

*
  • M
OS Command Injection

*
  • M
Directory Traversal

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Information Exposure

*
  • L
Resource Exhaustion

*
  • L
Out-of-bounds Write

*
  • M
Execution with Unnecessary Privileges

*
  • M
Buffer Access with Incorrect Length Value

*
  • L
Use of Uninitialized Resource

*
  • L
Out-of-bounds Read

*
  • L
Arbitrary Argument Injection

*
  • M
Link Following

*
  • L
Information Exposure

*
  • H
Reachable Assertion

*
  • L
Improper Verification of Cryptographic Signature

*
  • M
Misinterpretation of Input

*
  • M
Detection of Error Condition Without Action

*
  • M
Buffer Underflow

*
  • M
Return of Wrong Status Code

*
  • L
Improper Validation of Specified Index, Position, or Offset in Input

*
  • M
Off-by-one Error

*
  • L
Buffer Access with Incorrect Length Value

*
  • L
Uncontrolled Recursion

*
  • L
Out-of-bounds Read

*
  • M
Out-of-bounds Read

*
  • H
Improper Validation of Consistency within Input

*
  • L
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • H
Numeric Truncation Error

*
  • M
Out-of-bounds Read

*
  • L
Out-of-bounds Read

*
  • M
Failure to Sanitize Special Element

*
  • H
Improper Handling of Highly Compressed Data (Data Amplification)

*
  • M
Out-of-bounds Read

*
  • M
Directory Traversal

*
  • M
Integer Overflow or Wraparound

*
  • M
Resource Exhaustion

*
  • L
NULL Pointer Dereference

*
  • L
Unchecked Input for Loop Condition

*
  • M
Improper Certificate Validation

*
  • M
Buffer Overflow

*
  • M
Integer Overflow or Wraparound

*
  • M
Unchecked Input for Loop Condition

*
  • M
Out-of-bounds Write

*
  • L
Out-of-bounds Read

*
  • L
Improper Certificate Validation

*
  • M
Expired Pointer Dereference

*
  • M
Uncontrolled Recursion

*
  • M
Insufficient Granularity of Access Control

*
  • M
Improper Neutralization of Null Byte or NUL Character

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • L
Integer Overflow or Wraparound

*
  • M
NULL Pointer Dereference

*
  • M
Incorrect Calculation of Buffer Size

*
  • M
Out-of-bounds Read

*
  • H
Out-of-Bounds

*
  • H
Integer Overflow or Wraparound

*
  • H
Least Privilege Violation

*
  • H
Out-of-bounds Read

*
  • M
Out-of-bounds Write

*
  • M
Buffer Underflow

*
  • M
Out-of-bounds Write

*
  • M
Reachable Assertion

*
  • L
Authentication Bypass by Primary Weakness

*
  • M
Out-of-bounds Write

*
  • M
Integer Underflow

*
  • L
Improper Handling of Missing Special Element

*
  • M
Reachable Assertion

*
  • M
Uncontrolled Search Path Element

*
  • L
Out-of-bounds Read

*
  • H
Out-of-bounds Read

*
  • H
Insecure Default Initialization of Resource

*
  • M
Improper Input Validation

*
  • H
Insufficient Verification of Data Authenticity

*
  • M
Expired Pointer Dereference

*
  • M
Processor Optimization Removal or Modification of Security-critical Code

*
  • H
Out-of-bounds Read

*
  • M
Improper Finite State Machines (FSMs) in Hardware Logic

*
  • H
Use After Free

*
  • L
NULL Pointer Dereference

*
  • L
Heap-based Buffer Overflow

*
  • M
Untrusted Search Path

*
  • H
Expired Pointer Dereference

*
  • L
Out-of-bounds Read

*
  • L
Integer Underflow

*
  • H
CRLF Injection

*
  • M
Unchecked Return Value

*
  • M
Reachable Assertion

*
  • M
Incorrect Privilege Assignment

*
  • M
Directory Traversal

*
  • M
Information Exposure

*
  • H
Resource Exhaustion

*
  • M
Improper Handling of Exceptional Conditions

*
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • H
Buffer Overflow

*
  • L
External Control of File Name or Path

*
  • M
Expired Pointer Dereference

*
  • L
Integer Overflow or Wraparound

*
  • M
Unchecked Input for Loop Condition

*
  • L
Information Exposure

*
  • M
Improper Certificate Validation

*
  • L
Expired Pointer Dereference

*
  • H
Incorrect Authorization

*
  • M
Double Free

*
  • M
Out-of-bounds Write

*
  • M
Out-of-bounds Read

*
  • M
Uncontrolled Recursion

*
  • M
Reachable Assertion

*
  • L
Use of Uninitialized Resource

*
  • H
Use After Free

*
  • M
CVE-2025-61662

*
  • M
Stack-based Buffer Overflow

*
  • M
Heap-based Buffer Overflow

*
  • M
Symlink Following

*
  • H
Improper Authentication

*
  • H
Resource Exhaustion

*
  • L
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • H
Improper Input Validation

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • H
Arbitrary Argument Injection

*
  • L
Unchecked Return Value

*
  • M
Race Condition

*
  • M
Missing Authentication for Critical Function

*
  • H
Improper Authentication

*
  • H
Resource Exhaustion

*
  • M
Incorrect Implementation of Authentication Algorithm

*
  • M
Incorrect Execution-Assigned Permissions

*
  • M
Out-of-bounds Write

*
  • M
Out-of-bounds Read

*
  • M
Arbitrary Argument Injection

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • H
Incorrect Privilege Assignment

*
  • L
Reachable Assertion

*
  • H
Resource Exhaustion

*
  • H
Acceptance of Extraneous Untrusted Data With Trusted Data

*
  • M
NULL Pointer Dereference

*
  • L
Out-of-bounds Read

*
  • M
Incorrect Calculation of Buffer Size

*
  • M
Improper Synchronization

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Expired Pointer Dereference

*
  • M
Integer Overflow or Wraparound

*
  • L
Out-of-bounds Read

*
  • M
Use of Uninitialized Resource

*
  • H
Use After Free

*
  • L
Out-of-bounds Write

*
  • H
Use After Free

*
  • M
Return of Wrong Status Code

*
  • M
Stack-based Buffer Overflow

*
  • M
Buffer Overflow

*
  • H
Use After Free

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Improper Check for Unusual or Exceptional Conditions

*
  • M
Out-of-Bounds

*
  • M
Out-of-Bounds

*
  • M
Uncontrolled Recursion

*
  • L
Improper Validation of Specified Quantity in Input

*
  • H
Improper Verification of Cryptographic Signature

*
  • M
Integer Overflow or Wraparound

*
  • L
Algorithmic Complexity

*
  • M
Expired Pointer Dereference

*
  • L
Missing Required Cryptographic Step

*
  • L
Improperly Implemented Security Check for Standard

*
  • M
Race Condition

*
  • M
Expected Behavior Violation

*
  • H
Resource Exhaustion

*
  • L
NULL Pointer Dereference

*
  • M
Double Free

*
  • L
Out-of-Bounds

*
  • M
Algorithmic Complexity

*
  • M
Buffer Overflow

*
  • M
Integer Overflow or Wraparound

*
  • L
Out-of-bounds Write

*
  • M
CVE-2024-26602

*
  • L
Out-of-bounds Read

*
  • L
Buffer Overflow

*
  • L
Out-of-bounds Read

*
  • L
Improper Check for Unusual or Exceptional Conditions

*
  • M
Out-of-bounds Read

*
  • M
Acceptance of Extraneous Untrusted Data With Trusted Data

*
  • L
Out-of-bounds Read

*
  • M
Invokable Control Element in Multi-Thread Context with non-Final Static Storable or Member Element

*
  • H
Out-of-bounds Write

*
  • M
Information Exposure

*
  • H
Resource Exhaustion

*
  • L
Out-of-bounds Write

*
  • M
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • M
Buffer Overflow

*
  • M
Use After Free

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*