CWE-241
32 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-241page 1 of 1
- CVE-2021-0242MEDIUMCVSS 6.5EG 6.52021-04-22
A vulnerability due to the improper handling of direct memory access (DMA) buffers on EX4300 switches on Juniper Networks Junos OS allows an attacker sending specific unicast frames to trigger a Denial of Service (DoS) condition by exhaust…
- CVE-2021-0243MEDIUMCVSS 4.7EG 4.72021-04-22
Improper Handling of Unexpected Data in the firewall policer of Juniper Networks Junos OS on EX4300 switches allows matching traffic to exceed set policer limits, possibly leading to a limited Denial of Service (DoS) condition. When the fi…
- CVE-2021-32655LOWCVSS 3.5EG 3.52021-06-01
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.11, 20.0.10, and 21.0.2, an attacker is able to convert a Files Drop link to a federated share. This causes an issue on the UI side of the sharing…
- CVE-2021-32696LOWCVSS 3.7EG 3.72021-06-18
The npm package "striptags" is an implementation of PHP's strip_tags in Typescript. In striptags before version 3.2.0, a type-confusion vulnerability can cause `striptags` to concatenate unsanitized strings when an array-like object is pas…
- CVE-2021-39131HIGHCVSS 7.5EG 7.52021-08-17
ced detects character encoding using Google’s compact_enc_det library. In ced v0.1.0, passing data types other than `Buffer` causes the Node.js process to crash. The problem has been patched in ced v1.0.0. As a workaround, before passing…
- CVE-2021-40116HIGHCVSS 8.6EG 7.52021-10-27
Multiple Cisco products are affected by a vulnerability in Snort rules that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.The vulnerability is due to improper handling of…
- CVE-2022-1642HIGHCVSS 7.5EG 7.52022-06-16
A program using swift-corelibs-foundation is vulnerable to a denial of service attack caused by a potentially malicious source producing a JSON document containing a type mismatch. This vulnerability is caused by the interaction between a …
- CVE-2022-20730MEDIUMCVSS 4.0EG 7.52022-05-03
A vulnerability in the Security Intelligence feed feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the Security Intelligence DNS feed. This vulnerability is due to incorrect…
- CVE-2022-22193MEDIUMCVSS 5.5EG 5.52022-04-14
An Improper Handling of Unexpected Data Type vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenticated attacker with low privileges to cause a Denial of Service (DoS…
- CVE-2022-22219MEDIUMCVSS 5.9EG 5.92022-10-18
Due to the Improper Handling of an Unexpected Data Type in the processing of EVPN routes on Juniper Networks Junos OS and Junos OS Evolved, an attacker in direct control of a BGP client connected to a route reflector, or via a machine in t…
- CVE-2022-24668HIGHCVSS 7.5EG 7.52022-02-09
A program using swift-nio-http2 is vulnerable to a denial of service attack caused by a network peer sending ALTSVC or ORIGIN frames. This attack affects all swift-nio-http2 versions from 1.0.0 to 1.19.1. This vulnerability is caused by a …
- CVE-2022-29181HIGHCVSS 8.2EG 8.22022-05-20
Nokogiri is an open source XML and HTML library for Ruby. Nokogiri prior to version 1.13.6 does not type-check all inputs into the XML and HTML4 SAX parsers, allowing specially crafted untrusted inputs to cause illegal memory access errors…
- CVE-2022-3029HIGHCVSS 7.5EG 7.52022-09-13
In NLnet Labs Routinator 0.9.0 up to and including 0.11.2, due to a mistake in error handling, data in RRDP snapshot and delta files that isn’t correctly base 64 encoded is treated as a fatal error and causes Routinator to exit. Worst ca…
- CVE-2022-39064HIGHCVSS 8.1EG 8.12022-10-14
An attacker sending a single malformed IEEE 802.15.4 (Zigbee) frame makes the TRÅDFRI bulb blink, and if they replay (i.e. resend) the same frame multiple times, the bulb performs a factory reset. This causes the bulb to lose configuratio…
- CVE-2022-39065MEDIUMCVSS 6.5EG 6.52022-10-14
A single malformed IEEE 802.15.4 (Zigbee) frame makes the TRÅDFRI gateway unresponsive, such that connected lighting cannot be controlled with the IKEA Home Smart app and TRÅDFRI remote control. The malformed Zigbee frame is an unauthent…
- CVE-2023-28961MEDIUMCVSS 5.8EG 5.82023-04-17
An Improper Handling of Unexpected Data Type vulnerability in IPv6 firewall filter processing of Juniper Networks Junos OS on the ACX Series devices will prevent a firewall filter with the term 'from next-header ah' from being properly ins…
- CVE-2023-30591HIGHCVSS 7.5EG 7.52023-09-29
Denial-of-service in NodeBB <= v2.8.10 allows unauthenticated attackers to trigger a crash, when invoking `eventName.startsWith()` or `eventName.toString()`, while processing Socket.IO messages via crafted Socket.IO messages containing arr…
- CVE-2023-5215MEDIUMCVSS 5.3EG 5.32023-09-28
A flaw was found in libnbd. A server can reply with a block size larger than 2^63 (the NBD spec states the size is a 64-bit unsigned value). This issue could lead to an application crash or other unintended behavior for NBD clients that do…
- CVE-2024-0151MEDIUMCVSS 6.5EG 6.52024-04-24
Insufficient argument checking in Secure state Entry functions in software using Cortex-M Security Extensions (CMSE), that has been compiled using toolchains that implement 'Arm v8-M Security Extensions Requirements on Development Tools' p…
- CVE-2024-21523HIGHCVSS 7.5EG 7.52024-07-10
All versions of the package images are vulnerable to Denial of Service (DoS) due to providing unexpected input types to several different functions. This makes it possible to reach an assert macro, leading to a process crash. **Note:** By…
- CVE-2024-21526HIGHCVSS 7.5EG 7.52024-07-10
All versions of the package speaker are vulnerable to Denial of Service (DoS) when providing unexpected input types to the channels property of the Speaker object makes it possible to reach an assert macro. Exploiting this vulnerability ca…
- CVE-2024-21927MEDIUMCVSS 5.0EG 5.02025-09-23
Improper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to use certain special characters in manipulated Redfish® API commands, causing service processes like OpenBMC to crash and reset, po…
- CVE-2024-21935MEDIUMCVSS 5.0EG 5.02025-09-23
Improper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to manipulate Redfish® API commands to remove files from the local root directory, potentially resulting in data corruption.
- CVE-2024-25966MEDIUMCVSS 5.3EG 5.32024-05-14
Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains an improper handling of unexpected data type vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service.
- CVE-2024-32268LOWCVSS 3.3EG 3.32024-04-29
An issue in Tuya Smart camera U6N v.3.2.5 allows a remote attacker to cause a denial of service via a crafted packet to the network connection component.
- CVE-2024-37316MEDIUMCVSS 4.6EG 4.62024-06-14
Nextcloud Calendar is a calendar app for Nextcloud. Authenticated users could create an event with manipulated attachment data leading to a bad redirect for participants when clicked. It is recommended that the Nextcloud Calendar App is up…
- CVE-2024-9423MEDIUMCVSS 5.3EG 5.32024-10-02
Certain HP LaserJet printers may potentially experience a denial of service when a user sends a raw JPEG file to the printer. The printer displays a “JPEG Unsupported” message which may not clear, potentially blocking queued print jobs.
- CVE-2025-1004MEDIUMCVSS 5.3EG 5.32025-02-06
Certain HP LaserJet Pro printers may potentially experience a denial of service when a user sends a raw JPEG file to the printer via IPP (Internet Printing Protocol).
- CVE-2025-2268HIGHCVSS 7.5EG 7.52025-03-14
The HP LaserJet MFP M232-M237 Printer Series may be vulnerable to a denial of service attack when a specially crafted request message is sent via Internet Printing Protocol (IPP).
- CVE-2025-63548HIGHCVSS 7.5EG 7.52026-05-01
An issue in Eprosima Micro-XREC-DDS Agent v.3.0.1 allows a remote attacker to cause a denial of service via a packet specially crafted to bear a non-valid value in any Boolean field.
- CVE-2025-66550MEDIUMCVSS 5.7EG 5.72025-12-05
Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.17 and 5.2.4, when a malicious user creates a calendar event with a crafted attachment that links to a download link of a file on the same Nextcloud server, the file would be…
- CVE-2025-7339LOWCVSS 3.4EG 3.42025-07-17
on-headers is a node.js middleware for listening to when a response writes headers. A bug in on-headers versions `<1.1.0` may result in response headers being inadvertently modified when an array is passed to `response.writeHead()`. Users…
Map vulnerabilities like CWE-241 to your infrastructure
EchelonGraph correlates every CVE — across CWE-241 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →