Skip to main content

CWE archive

CWE-617 CVEs

Programmatic archive

789 CVEs tagged with CWE-6174 Critical, 327 High, 428 Medium, 30 Low, 0 Unrated.

CVE-2026-22990

Published Jan 23, 2026

In the Linux kernel, the following vulnerability has been resolved: libceph: replace overzealous BUG_ON in osdmap_apply_incremental() If the osdmap is (maliciously) corrupted su…

CVSS 7.5 · High
evidence mentions
7
Buzz score
25.8
Vendor/product tagsBeta · best-effort

CVE-2026-23991

Published Jan 22, 2026

go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, if the TUF repository (or any of its mirrors) returns invalid TU…

CVSS 5.9 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-13878

Published Jan 21, 2026

Malformed BRID/HHIT records can cause `named` to terminate unexpectedly. This issue affects BIND 9 versions 9.18.40 through 9.18.43, 9.20.13 through 9.20.17, 9.21.12 through 9.21.…

CVSS 7.5 · High
evidence mentions
9
Buzz score
42.5

CVE-2025-61684

Published Jan 19, 2026

Quicly, an IETF QUIC protocol implementation, is susceptible to a denial-of-service attack prior to commit d9d3df6a8530a102b57d840e39b0311ce5c9e14e. A remote attacker can exploit…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-15531

Published Jan 17, 2026

A vulnerability was identified in Open5GS up to 2.7.5. This vulnerability affects the function sgwc_bearer_add of the file src/sgwc/context.c. The manipulation leads to reachable…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-15530

Published Jan 17, 2026

A vulnerability was determined in Open5GS up to 2.7.6. This affects the function sgwc_s11_handle_create_indirect_data_forwarding_tunnel_request of the file /src/sgwc/s11-handler.c…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-71085

Published Jan 13, 2026

In the Linux kernel, the following vulnerability has been resolved: ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr() There exists a kernel oops caused by a…

CVSS 5.5 · Medium
evidence mentions
8
Buzz score
32.0
Vendor/product tagsBeta · best-effort

CVE-2025-71080

Published Jan 13, 2026

In the Linux kernel, the following vulnerability has been resolved: ipv6: fix a BUG in rt6_get_pcpu_route() under PREEMPT_RT On PREEMPT_RT kernels, after rt6_get_pcpu_route() re…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-68471

Published Jan 12, 2026

Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending 2 unsol…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-68468

Published Jan 12, 2026

Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolic…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-68276

Published Jan 12, 2026

Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, an unprivileged local users can crash avahi-da…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-20762

Published Jan 6, 2026

In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled b…

CVSS 6.5 · Medium

CVE-2025-15176

Published Dec 29, 2025

A flaw has been found in Open5GS up to 2.7.5. This affects the function decode_ipv6_header/ogs_pfcp_pdr_rule_find_by_packet of the file lib/pfcp/rule-match.c of the component PFCP…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66443

Published Dec 25, 2025

Pexip Infinity 35.0 through 38.1 before 39.0, in non-default configurations that use Direct Media for WebRTC, has Improper Input Validation in signalling that allows an attacker t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-66379

Published Dec 25, 2025

Pexip Infinity before 39.0 has Improper Input Validation in the media implementation, allowing a remote attacker to trigger a software abort via a crafted media stream, resulting…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-49088

Published Dec 25, 2025

Pexip Infinity 32.0 through 37.1 before 37.2, in certain configurations of OTJ (One Touch Join) for Teams SIP Guest Join, has Improper Input Validation in the OTJ service, allowin…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48704

Published Dec 25, 2025

Pexip Infinity 35.0 through 37.2 before 38.0 has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in a denial of service.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-32096

Published Dec 25, 2025

Pexip Infinity 33.0 through 37.0 before 37.1 has improper input validation in signaling that allows an attacker to trigger a software abort, resulting in a denial of service.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-32095

Published Dec 25, 2025

Pexip Infinity before 37.0 has improper input validation in signalling that allows a remote attacker to trigger a software abort via a crafted signalling message, resulting in a d…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-34458

Published Dec 22, 2025

wb2osz/direwolf (Dire Wolf) versions up to and including 1.8, prior to commit 3658a87, contain a reachable assertion vulnerability in the APRS MIC-E decoder function aprs_mic_e()…

CVSS 8.7 · High

CVE-2025-14954

Published Dec 19, 2025

A vulnerability has been found in Open5GS up to 2.7.6. Affected is the function ogs_pfcp_pdr_find_or_add/ogs_pfcp_far_find_or_add/ogs_pfcp_urr_find_or_add/ogs_pfcp_qer_find_or_add…

CVSS 2.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-65559

Published Dec 18, 2025

An issue was discovered in Open5GS 2.7.5-49-g465e90f, when processing a PFCP Session Establishment Request (type=50), the UPF crashes with a reachable assertion in `lib/pfcp/conte…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-59029

Published Dec 9, 2025

An attacker can trigger an assertion failure by requesting crafted DNS records, waiting for them to be inserted into the records cache, then send a query with qtype set to ANY.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 126-150 of 789 CVEsPage 6 of 32