openshift/ose-rhel-coreos-9

Direct Vulnerabilities

Known vulnerabilities in the openshift/ose-rhel-coreos-9 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
Insufficiently Protected Credentials

*
  • M
Expired Pointer Dereference

*
  • H
Out-of-bounds Write

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • L
Incorrect Permission Assignment for Critical Resource

*
  • H
Out-of-bounds Write

*
  • H
OS Command Injection

*
  • M
Out-of-bounds Read

*
  • M
Buffer Overflow

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Read

*
  • L
Incorrect Synchronization

*
  • M
Out-of-bounds Read

*
  • H
OS Command Injection

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Out-of-bounds Read

*
  • M
Missing Lock Check

*
  • L
Reachable Assertion

*
  • M
Incorrect Behavior Order: Early Validation

*
  • M
Reachable Assertion

*
  • L
Reachable Assertion

*
  • M
Buffer Overflow

*
  • H
Expired Pointer Dereference

*
  • M
Buffer Access with Incorrect Length Value

*
  • H
Reliance on Untrusted Inputs in a Security Decision

*
  • M
Buffer Access with Incorrect Length Value

*
  • M
Incorrect Behavior Order: Early Validation

*
  • M
Reachable Assertion

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • M
Incorrect Privilege Assignment

*
  • M
CVE-2026-6368

*
  • M
Out-of-bounds Read

*
  • M
Improperly Implemented Security Check for Standard

*
  • M
Expired Pointer Dereference

*
  • L
Release of Invalid Pointer or Reference

*
  • L
Reachable Assertion

*
  • M
NULL Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • H
Out-of-bounds Read

*
  • H
Expired Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • H
Out-of-bounds Write

*
  • H
Double Free

*
  • M
Out-of-bounds Read

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • L
Asymmetric Resource Consumption (Amplification)

*
  • L
NULL Pointer Dereference

*
  • M
Race Condition

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Write

*
  • M
NULL Pointer Dereference

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • H
Out-of-bounds Write

*
  • M
NULL Pointer Dereference

*
  • L
NULL Pointer Dereference

*
  • M
Insufficient Verification of Data Authenticity

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • M
Improper Update of Reference Count

*
  • H
Link Following

*
  • L
Reachable Assertion

*
  • H
Expired Pointer Dereference

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • H
Integer Overflow or Wraparound

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • M
Out-of-bounds Write

*
  • M
Reachable Assertion

*
  • M
Expired Pointer Dereference

*
  • M
Reachable Assertion

*
  • L
NULL Pointer Dereference

*
  • M
Improper Update of Reference Count

*
  • M
Improper Resource Locking

*
  • H
Not Failing Securely ('Failing Open')

*
  • L
Reachable Assertion

*
  • L
NULL Pointer Dereference

*
  • H
Link Following

*
  • H
Out-of-bounds Write

*
  • M
Out-of-bounds Write

*
  • M
NULL Pointer Dereference

*
  • M
Missing Lock Check

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Out-of-bounds Read

*
  • H
Improper Handling of Missing Special Element

*
  • M
Access of Uninitialized Pointer

*
  • H
Out-of-bounds Write

*
  • M
Integer Overflow or Wraparound

*
  • L
Use of Less Trusted Source

*
  • H
Incorrect Authorization

*
  • M
Divide By Zero

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
NULL Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • M
Missing Synchronization

*
  • M
Expired Pointer Dereference

*
  • L
Incorrect Privilege Assignment

*
  • M
Incorrect Calculation of Buffer Size

*
  • H
Out-of-bounds Write

*
  • M
Information Exposure

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
NULL Pointer Dereference

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • L
Time-of-check Time-of-use (TOCTOU)

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • M
Expired Pointer Dereference

*
  • M
Out-of-bounds Write

*
  • M
Expired Pointer Dereference

*
  • L
NULL Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • M
Expired Pointer Dereference

*
  • M
Incorrect Synchronization

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • M
Out-of-bounds Read

*
  • H
Link Following

*
  • M
Improper Handling of Structural Elements

*
  • M
Out-of-bounds Read

*
  • M
Incorrect Synchronization

*
  • M
Expired Pointer Dereference

*
  • M
NULL Pointer Dereference

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • M
Out-of-bounds Read

*
  • H
Link Following

*
  • H
Out-of-bounds Read

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • L
Use of Externally-Controlled Format String

*
  • H
OS Command Injection

*
  • H
Link Following

*
  • H
Use After Free

*
  • M
Out-of-bounds Read

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Improper Certificate Validation

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • H
Link Following

*
  • M
Deadlock

*
  • M
Out-of-bounds Write

*
  • M
NULL Pointer Dereference

*
  • M
Missing Handler

*
  • M
Expired Pointer Dereference

*
  • M
Race Condition

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • M
Out-of-bounds Write

*
  • M
Expired Pointer Dereference

*
  • M
Improper Validation of Array Index

*
  • H
Expired Pointer Dereference

*
  • M
Missing Synchronization

*
  • M
Reachable Assertion

*
  • H
Arbitrary Code Injection

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • H
Authentication Bypass

*
  • M
Buffer Overflow

*
  • H
Incorrect Privilege Assignment

*
  • L
Off-by-one Error

*
  • M
Reachable Assertion

*
  • M
Permissive Regular Expression

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Buffer Overflow

*
  • L
Reachable Assertion

*
  • M
HTTP Request Smuggling

*
  • M
Acceptance of Extraneous Untrusted Data With Trusted Data

*
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • L
Information Exposure

*
  • H
Time-of-check Time-of-use (TOCTOU)

*
  • M
Use After Free

*
  • L
NULL Pointer Dereference

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Out-of-bounds Write

*
  • M
Double Free

*
  • M
Out-of-bounds Write

*
  • M
Use of Out-of-range Pointer Offset

*
  • H
Improperly Implemented Security Check for Standard

*
  • M
Expired Pointer Dereference

*
  • H
Authentication Bypass by Primary Weakness

*
  • H
Information Exposure

*
  • M
Information Exposure

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Resource Exhaustion

*
  • M
Improper Verification of Cryptographic Signature

*
  • H
Improper Validation of Specified Type of Input

*
  • M
OS Command Injection

*
  • H
Improper Verification of Cryptographic Signature

*
  • H
Improper Certificate Validation

*
  • L
Incorrect Calculation of Buffer Size

*
  • H
Access of Uninitialized Pointer

*
  • M
Improper Verification of Cryptographic Signature

*
  • H
Improper Update of Reference Count

*
  • M
NULL Pointer Dereference

*
  • M
Integer Overflow or Wraparound

*
  • M
Use After Free

*
  • M
Use of Insufficiently Random Values

*
  • M
Improper Access Control

*
  • H
Expired Pointer Dereference

*
  • M
Improper Handling of Case Sensitivity

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • H
Buffer Access with Incorrect Length Value

*
  • H
Out-of-bounds Read

*
  • M
Expired Pointer Dereference

*
  • M
Reliance on Cookies without Validation and Integrity Checking

*
  • H
Integer Underflow

*
  • H
Improper Input Validation

*
  • M
Out-of-bounds Write

*
  • H
Arbitrary Code Injection

*
  • H
Expired Pointer Dereference

*
  • L
Integer Overflow or Wraparound

*
  • M
Buffer Access with Incorrect Length Value

*
  • M
Directory Traversal

*
  • H
Reachable Assertion

*
  • M
Out-of-bounds Read

*
  • H
Excessive Platform Resource Consumption within a Loop

*
  • H
Improper Validation of Integrity Check Value

*
  • H
OS Command Injection

*
  • M
Incorrect Calculation of Buffer Size

*
  • H
Resource Exhaustion

*
  • H
Use of Incorrect Operator

*
  • M
Improper Handling of Length Parameter Inconsistency

*
  • M
Arbitrary Code Injection

*
  • M
Generation of Weak Initialization Vector (IV)

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • H
NULL Pointer Dereference

*
  • H
OS Command Injection

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • H
Function Call with Incorrectly Specified Arguments

*
  • M
Insufficient Verification of Data Authenticity

*
  • H
OS Command Injection

*
  • M
Use After Free

*
  • H
Improper Handling of Length Parameter Inconsistency

*
  • H
Improper Handling of Length Parameter Inconsistency

*
  • M
Buffer Access with Incorrect Length Value

*
  • H
Integer Underflow

*
  • M
Out-of-bounds Read

*
  • M
Improper Validation of Specified Type of Input

*
  • L
NULL Pointer Dereference

*
  • L
NULL Pointer Dereference

*
  • H
Integer Overflow or Wraparound

*
  • M
Integer Overflow or Wraparound

*
  • H
Off-by-one Error

*
  • H
Insufficient Verification of Data Authenticity

*
  • H
Symlink Following

*
  • M
OS Command Injection

*
  • H
Use After Free

*
  • M
Directory Traversal

*
  • H
Insufficient Verification of Data Authenticity

*
  • M
Reachable Assertion

*
  • M
Buffer Overflow

*
  • M
Improper Certificate Validation

*
  • M
Expired Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • L
Information Exposure

*
  • M
Buffer Access with Incorrect Length Value

*
  • M
Out-of-bounds Write

*
  • M
Integer Overflow or Wraparound

*
  • M
Integer Overflow or Wraparound

*
  • M
Improper Input Validation

*
  • M
Arbitrary Code Injection

*
  • M
Out-of-bounds Read

*
  • M
Directory Traversal

*
  • M
Cleartext Transmission of Sensitive Information

*
  • L
Use After Free

*
  • M
Improper Preservation of Permissions

*
  • L
Improperly Implemented Security Check for Standard

*
  • M
Improper Restriction of Excessive Authentication Attempts

*
  • M
Integer Overflow or Wraparound

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Out-of-bounds Write

*
  • M
Out-of-bounds Write

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Out-of-bounds Read

*
  • M
Improper Cross-boundary Removal of Sensitive Data

*
  • M
Reachable Assertion

*
  • M
OS Command Injection

*
  • L
Out-of-bounds Read

*
  • M
Comparison Using Wrong Factors

*
  • M
Double Free

*
  • M
Authentication Bypass

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Incorrect Execution-Assigned Permissions

*
  • H
Link Following

*
  • M
Buffer Overflow

*
  • M
Insufficient Control of Network Message Volume (Network Amplification)

*
  • M
Improper Neutralization of Null Byte or NUL Character

*
  • H
Improper Neutralization

*
  • M
Expired Pointer Dereference

*
  • M
Incorrect Privilege Assignment

*
  • H
Improper Preservation of Permissions

*
  • L
Improper Verification of Cryptographic Signature

*
  • H
Improper Handling of Highly Compressed Data (Data Amplification)

*
  • L
Expired Pointer Dereference

*
  • L
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • H
Improper Update of Reference Count

*
  • L
OS Command Injection

*
  • L
Incorrect Implementation of Authentication Algorithm

*
  • M
External Control of File Name or Path

*
  • M
Information Exposure

*
  • L
Integer Overflow or Wraparound

*
  • M
Arbitrary Argument Injection

*
  • M
Buffer Overflow

*
  • H
Expired Pointer Dereference

*
  • H
OS Command Injection

*
  • M
Integer Overflow or Wraparound

*
  • H
Expired Pointer Dereference

*
  • L
Incorrect Calculation of Multi-Byte String Length

*
  • M
Use of Externally-Controlled Format String

*
  • M
Improper Handling of Insufficient Permissions or Privileges

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Out-of-bounds Read

*
  • L
Stack-based Buffer Overflow

*
  • L
Buffer Access with Incorrect Length Value

*
  • L
Improper Validation of Integrity Check Value

*
  • M
Out-of-bounds Read

*
  • M
HTTP Request Smuggling

*
  • M
Heap-based Buffer Overflow

*
  • M
Improper Certificate Validation

*
  • M
Improper Null Termination

*
  • M
Missing Initialization of Resource

*
  • L
Improper Validation of Specified Type of Input

*
  • M
Improper Privilege Management

*
  • M
Use of Uninitialized Resource

*
  • M
Out-of-bounds Write

*
  • M
Incorrect Bitwise Shift of Integer

*
  • M
Directory Traversal

*
  • M
Buffer Overflow

*
  • L
Stack-based Buffer Overflow

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • L
Unchecked Input for Loop Condition

*
  • M
Release of Invalid Pointer or Reference

*
  • M
CVE-2026-64535

*
  • L
Incorrect Calculation of Buffer Size

*
  • M
Arbitrary Code Injection

*
  • L
Use of Uninitialized Resource

*
  • M
Use After Free

*
  • M
Incorrect Calculation of Buffer Size

*
  • H
Excessive Platform Resource Consumption within a Loop

*
  • L
External Control of System or Configuration Setting

*
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • L
Improper Update of Reference Count

*
  • M
Access of Uninitialized Pointer

*
  • M
Expired Pointer Dereference

*
  • M
Improper Validation of Specified Type of Input

*
  • L
Buffer Access with Incorrect Length Value

*
  • M
Out-of-bounds Read

*
  • L
CVE-2026-28387

*
  • H
Predictable from Observable State

*
  • M
Reachable Assertion

*
  • L
Incorrect Behavior Order: Early Validation

*
  • M
Integer Overflow or Wraparound

*
  • M
Expired Pointer Dereference

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
NULL Pointer Dereference

*
  • H
Out-of-bounds Write

*
  • L
Origin Validation Error

*
  • M
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • L
Missing Authentication for Critical Function

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Information Exposure

*
  • H
CRLF Injection

*
  • L
NULL Pointer Dereference

*
  • H
Access of Uninitialized Pointer

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Out-of-bounds Read

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Directory Traversal

*
  • L
Improper Null Termination

*
  • M
Directory Traversal

*
  • M
NULL Pointer Dereference

*
  • M
CVE-2026-23865

*
  • M
Out-of-bounds Read

*
  • M
OS Command Injection

*
  • M
Uncontrolled Recursion

*
  • M
Link Following

*
  • M
Improper Restriction of Communication Channel to Intended Endpoints

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Read

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • H
Expired Pointer Dereference

*
  • H
Improper Access Control

*
  • M
OS Command Injection

*
  • M
Integer Underflow

*
  • H
Out-of-bounds Read

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • H
Improper Null Termination

*
  • L
Integer Overflow or Wraparound

*
  • M
Buffer Over-read

*
  • M
Double Free

*
  • L
NULL Pointer Dereference

*
  • M
Information Exposure

*
  • H
Time-of-check Time-of-use (TOCTOU)

*
  • M
Out-of-bounds Read

*
  • H
Directory Traversal

*
  • M
Integer Overflow or Wraparound

*
  • M
Improper Certificate Validation

*
  • M
Integer Overflow or Wraparound

*
  • H
Undefined Behavior for Input to API

*
  • H
Stack-based Buffer Overflow

*
  • M
Reversible One-Way Hash

*
  • C
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • M
Out-of-bounds Read

*
  • M
Improper Certificate Validation

*
  • L
NULL Pointer Dereference

*
  • M
Out-of-bounds Write

*
  • L
Stack-based Buffer Overflow

*
  • H
Time-of-check Time-of-use (TOCTOU)

*
  • L
Inefficient Regular Expression Complexity

*
  • M
Improper Access Control

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • M
Improper Handling of Case Sensitivity

*
  • L
Access of Uninitialized Pointer

*
  • M
Out-of-bounds Read

*
  • M
Integer Overflow or Wraparound

*
  • M
Acceptance of Extraneous Untrusted Data With Trusted Data

*
  • M
Out-of-bounds Read

*
  • H
Premature Release of Resource During Expected Lifetime

*
  • H
Heap-based Buffer Overflow

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Use After Free

*
  • H
Out-of-bounds Write

*
  • M
Improper Update of Reference Count

*
  • M
Incorrect Calculation of Buffer Size

*
  • M
Off-by-one Error

*
  • M
Information Exposure

*
  • M
Buffer Over-read

*
  • L
Out-of-bounds Write

*
  • M
Integer Overflow or Wraparound

*
  • M
NULL Pointer Dereference

*
  • L
Memory Leak

*
  • M
Authentication Bypass by Primary Weakness

*
  • M
Buffer Overflow

*
  • H
Buffer Access with Incorrect Length Value

*
  • M
Link Following

*
  • M
Improper Input Validation

*
  • H
OS Command Injection

*
  • H
Arbitrary Code Injection

*
  • M
Use After Free

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • M
Improper Handling of Inconsistent Special Elements

*
  • L
NULL Pointer Dereference

*
  • H
Arbitrary Code Injection

*
  • H
Write-what-where Condition

*
  • M
Improper Validation of Syntactic Correctness of Input

*
  • M
Improper Restriction of Excessive Authentication Attempts

*
  • M
Link Following

*
  • M
Out-of-bounds Write

*
  • M
OS Command Injection

*
  • M
Unrestricted Externally Accessible Lock

*
  • M
XML External Entity (XXE) Injection

*
  • M
Exposure of Data Element to Wrong Session

*
  • M
OS Command Injection

*
  • M
Resource Exhaustion

*
  • L
Out-of-bounds Write

*
  • M
Out-of-bounds Read

*
  • M
Integer Overflow or Wraparound

*
  • M
Double Free

*
  • M
Comparison Using Wrong Factors

*
  • M
Directory Traversal

*
  • M
Improper Validation of Specified Quantity in Input

*
  • M
Arbitrary Argument Injection

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Read

*
  • L
Out-of-bounds Read

*
  • H
Write-what-where Condition

*
  • M
NULL Pointer Dereference

*
  • M
Buffer Overflow

*
  • M
Directory Traversal

*
  • L
Integer Overflow or Wraparound

*
  • M
Directory Traversal

*
  • L
Improper Validation of Integrity Check Value

*
  • L
Misinterpretation of Input

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Directory Traversal

*
  • M
Uncontrolled Recursion

*
  • L
Authentication Bypass

*
  • M
Improper Validation of Integrity Check Value

*
  • L
NULL Pointer Dereference

*
  • M
Uncontrolled Recursion

*
  • H
Out-of-bounds Read

*
  • M
Improper Handling of Parameters

*
  • H
Out-of-bounds Read

*
  • M
Expired Pointer Dereference

*
  • M
Incorrect Calculation of Buffer Size

*
  • L
NULL Pointer Dereference

*
  • H
Buffer Overflow

*
  • H
Arbitrary Code Injection

*
  • M
Integer Overflow or Wraparound

*
  • M
Out-of-bounds Write

*
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • H
Race Condition

*
  • L
NULL Pointer Dereference

*
  • H
Improper Privilege Management

*
  • M
Memory Leak

*
  • L
Use After Free

*
  • H
Reachable Assertion

*
  • H
Arbitrary Code Injection

*
  • H
Use of Uninitialized Resource

*
  • M
Buffer Overflow

*
  • M
Memory Leak

*
  • L
Out-of-bounds Read

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • L
Use After Free

*
  • L
Out-of-bounds Write

*
  • M
Buffer Overflow

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • H
Link Following

*
  • L
Improper Cross-boundary Removal of Sensitive Data

*
  • H
Execution with Unnecessary Privileges

*
  • M
Improper Certificate Validation

*
  • L
Stack-based Buffer Overflow

*
  • M
Heap-based Buffer Overflow

*
  • M
Out-of-bounds Read

*
  • H
Symlink Following

*
  • M
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

*
  • M
Improper Validation of Consistency within Input

*
  • H
Out-of-bounds Write

*
  • M
Uncontrolled Recursion

*
  • M
Out-of-bounds Write

*
  • M
NULL Pointer Dereference

*
  • L
Inappropriate Encoding for Output Context

*
  • L
Buffer Overflow

*
  • M
Use After Free

*
  • M
Integer Underflow

*
  • M
Out-of-bounds Read

*
  • H
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

*
  • H
Insufficient Granularity of Access Control

*
  • M
Incorrect Calculation of Buffer Size

*
  • L
Improper Certificate Validation

*
  • L
Integer Overflow or Wraparound

*
  • M
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

*
  • M
OS Command Injection

*
  • M
Directory Traversal

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Information Exposure

*
  • L
Resource Exhaustion

*
  • L
Out-of-bounds Write

*
  • M
Execution with Unnecessary Privileges

*
  • L
Buffer Access with Incorrect Length Value

*
  • L
Use of Uninitialized Resource

*
  • L
Out-of-bounds Read

*
  • L
Arbitrary Argument Injection

*
  • M
Link Following

*
  • L
Information Exposure

*
  • H
Reachable Assertion

*
  • L
Improper Verification of Cryptographic Signature

*
  • M
Misinterpretation of Input

*
  • M
Detection of Error Condition Without Action

*
  • M
Buffer Underflow

*
  • M
Return of Wrong Status Code

*
  • L
Improper Validation of Specified Index, Position, or Offset in Input

*
  • M
Off-by-one Error

*
  • L
Buffer Access with Incorrect Length Value

*
  • L
Uncontrolled Recursion

*
  • L
Out-of-bounds Read

*
  • M
Out-of-bounds Read

*
  • H
Improper Validation of Consistency within Input

*
  • L
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • M
Integer Underflow

*
  • H
Numeric Truncation Error

*
  • M
Out-of-bounds Read

*
  • L
Out-of-bounds Read

*
  • M
Failure to Sanitize Special Element

*
  • H
Improper Handling of Highly Compressed Data (Data Amplification)

*
  • M
Out-of-bounds Read

*
  • M
Directory Traversal

*
  • M
Integer Overflow or Wraparound

*
  • M
Resource Exhaustion

*
  • M
Improper Use of Validation Framework

*
  • L
NULL Pointer Dereference

*
  • L
Unchecked Input for Loop Condition

*
  • M
Improper Certificate Validation

*
  • M
Buffer Overflow

*
  • M
Integer Overflow or Wraparound

*
  • M
Unchecked Input for Loop Condition

*
  • H
Out-of-bounds Write

*
  • L
Out-of-bounds Read

*
  • L
Improper Certificate Validation

*
  • M
Expired Pointer Dereference

*
  • M
Uncontrolled Recursion

*
  • M
Insufficient Granularity of Access Control

*
  • M
Improper Neutralization of Null Byte or NUL Character

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • L
Integer Overflow or Wraparound

*
  • M
NULL Pointer Dereference

*
  • M
Incorrect Calculation of Buffer Size

*
  • M
Out-of-bounds Read

*
  • H
Out-of-Bounds

*
  • H
Integer Overflow or Wraparound

*
  • M
Incorrect Calculation

*
  • H
Least Privilege Violation

*
  • H
Out-of-bounds Read

*
  • M
Out-of-bounds Write

*
  • M
Buffer Underflow

*
  • M
Out-of-bounds Write

*
  • M
Reachable Assertion

*
  • L
Authentication Bypass by Primary Weakness

*
  • M
Out-of-bounds Write

*
  • M
Integer Underflow

*
  • L
Improper Handling of Missing Special Element

*
  • M
Reachable Assertion

*
  • M
Uncontrolled Search Path Element

*
  • L
Out-of-bounds Read

*
  • H
Out-of-bounds Read

*
  • H
Insecure Default Initialization of Resource

*
  • M
Improper Input Validation

*
  • M
Out-of-bounds Read

*
  • H
Insufficient Verification of Data Authenticity

*
  • M
Expired Pointer Dereference

*
  • M
Processor Optimization Removal or Modification of Security-critical Code

*
  • H
Out-of-bounds Read

*
  • M
Improper Finite State Machines (FSMs) in Hardware Logic

*
  • H
Use After Free

*
  • L
NULL Pointer Dereference

*
  • L
Heap-based Buffer Overflow

*
  • M
Untrusted Search Path

*
  • H
Expired Pointer Dereference

*
  • L
Out-of-bounds Read

*
  • L
Integer Underflow

*
  • H
CRLF Injection

*
  • M
Unchecked Return Value

*
  • M
Reachable Assertion

*
  • M
Incorrect Privilege Assignment

*
  • M
Directory Traversal

*
  • M
Information Exposure

*
  • H
Resource Exhaustion

*
  • M
Improper Handling of Exceptional Conditions

*
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • H
Buffer Overflow

*
  • L
External Control of File Name or Path

*
  • M
Expired Pointer Dereference

*
  • L
Integer Overflow or Wraparound

*
  • M
Unchecked Input for Loop Condition

*
  • L
Information Exposure

*
  • M
Improper Certificate Validation

*
  • L
Expired Pointer Dereference

*
  • H
Incorrect Authorization

*
  • M
Double Free

*
  • M
Out-of-bounds Write

*
  • M
Out-of-bounds Read

*
  • M
Uncontrolled Recursion

*
  • M
Reachable Assertion

*
  • L
Use of Uninitialized Resource

*
  • H
Use After Free

*
  • M
CVE-2025-61662

*
  • M
Stack-based Buffer Overflow

*
  • M
Heap-based Buffer Overflow

*
  • M
Symlink Following

*
  • H
Improper Authentication

*
  • H
Resource Exhaustion

*
  • L
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • H
Improper Input Validation

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • H
Arbitrary Argument Injection

*
  • L
Unchecked Return Value

*
  • M
Information Exposure

*
  • M
Race Condition

*
  • M
Missing Authentication for Critical Function

*
  • H
Improper Authentication

*
  • H
Resource Exhaustion

*
  • M
Incorrect Implementation of Authentication Algorithm

*
  • M
Incorrect Execution-Assigned Permissions

*
  • M
Integer Overflow or Wraparound

*
  • M
Out-of-bounds Write

*
  • M
Resource Exhaustion

*
  • M
Out-of-bounds Read

*
  • M
Arbitrary Argument Injection

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • H
Incorrect Privilege Assignment

*
  • L
Reachable Assertion

*
  • H
Resource Exhaustion

*
  • H
Acceptance of Extraneous Untrusted Data With Trusted Data

*
  • M
NULL Pointer Dereference

*
  • L
Out-of-bounds Read

*
  • M
Incorrect Calculation of Buffer Size

*
  • M
Improper Synchronization

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Expired Pointer Dereference

*
  • M
Integer Overflow or Wraparound

*
  • L
Out-of-bounds Read

*
  • M
Use of Uninitialized Resource

*
  • H
Use After Free

*
  • L
Out-of-bounds Write

*
  • H
Use After Free

*
  • M
Return of Wrong Status Code

*
  • M
Stack-based Buffer Overflow

*
  • M
Buffer Overflow

*
  • H
Use After Free

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Improper Check for Unusual or Exceptional Conditions

*
  • M
Out-of-Bounds

*
  • M
Out-of-Bounds

*
  • M
Uncontrolled Recursion

*
  • L
Improper Validation of Specified Quantity in Input

*
  • H
Improper Verification of Cryptographic Signature

*
  • M
Integer Overflow or Wraparound

*
  • L
Algorithmic Complexity

*
  • M
Expired Pointer Dereference

*
  • L
Missing Required Cryptographic Step

*
  • L
Improperly Implemented Security Check for Standard

*
  • M
Race Condition

*
  • M
Expected Behavior Violation

*
  • H
Resource Exhaustion

*
  • L
NULL Pointer Dereference

*
  • M
Double Free

*
  • L
Out-of-Bounds

*
  • M
Algorithmic Complexity

*
  • M
Buffer Overflow

*
  • M
Integer Overflow or Wraparound

*
  • L
Out-of-bounds Write

*
  • M
CVE-2024-26602

*
  • L
Out-of-bounds Read

*
  • L
Buffer Overflow

*
  • L
Out-of-bounds Read

*
  • L
Improper Check for Unusual or Exceptional Conditions

*
  • M
Out-of-bounds Read

*
  • M
Acceptance of Extraneous Untrusted Data With Trusted Data

*
  • L
Out-of-bounds Read

*
  • M
Invokable Control Element in Multi-Thread Context with non-Final Static Storable or Member Element

*
  • H
Out-of-bounds Write

*
  • M
Information Exposure

*
  • H
Resource Exhaustion

*
  • L
Out-of-bounds Write

*
  • M
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • M
Buffer Overflow

*
  • M
Use After Free

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*