CWE-248
192 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-248page 2 of 4
- CVE-2023-2251HIGHCVSS 7.5EG 7.52023-04-24
Uncaught Exception in GitHub repository eemeli/yaml prior to 2.0.0-5.
- CVE-2023-22941MEDIUMCVSS 6.5EG 7.52023-02-14
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, an improperly-formatted ‘INGEST_EVAL’ parameter in a Field Transformation crashes the Splunk daemon (splunkd).
- CVE-2023-23774HIGHCVSS 8.4EG 8.42023-08-29
Motorola EBTS/MBTS Site Controller drops to debug prompt on unhandled exception. The Motorola MBTS Site Controller exposes a debug prompt on the device's serial port in case of an unhandled exception. This allows an attacker with physical …
- CVE-2023-23932MEDIUMCVSS 5.3EG 5.32023-02-03
OpenDDS is an open source C++ implementation of the Object Management Group (OMG) Data Distribution Service (DDS). OpenDDS applications that are exposed to untrusted RTPS network traffic may crash when parsing badly-formed input. This issu…
- CVE-2023-25526MEDIUMCVSS 6.5EG 6.52023-09-20
NVIDIA Cumulus Linux contains a vulnerability in neighmgrd and nlmanager where an attacker on an adjacent network may cause an uncaught exception by injecting a crafted packet. A successful exploit may lead to denial of service.
- CVE-2023-26586MEDIUMCVSS 4.3EG 6.52024-02-14
Uncaught exception for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
- CVE-2023-27318MEDIUMCVSS 6.5EG 6.52024-02-05
StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.13 are susceptible to a Denial of Service (DoS) vulnerability. A successful exploit could lead to a crash of the Local Distribution Router (LDR) service.
- CVE-2023-29520MEDIUMCVSS 4.3EG 4.32023-04-19
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to break many translations coming from wiki pages by creating a corrupted document containing a translation object. This…
- CVE-2023-31125MEDIUMCVSS 6.5EG 6.52023-05-08
Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Socket.IO. An uncaught exception vulnerability was introduced in version 5.1.0 and included in version 4.1.0 of the `socke…
- CVE-2023-3405HIGHCVSS 7.5EG 7.52023-06-27
Unchecked parameter value in M-Files Server in versions before 23.6.12695.3 (excluding 23.2 SR2 and newer) allows anonymous user to cause denial of service
- CVE-2023-3774MEDIUMCVSS 4.9EG 4.92023-07-28
An unhandled error in Vault Enterprise's namespace creation may cause the Vault process to crash, potentially resulting in denial of service. Fixed in 1.14.1, 1.13.5, and 1.12.9.
- CVE-2023-38504HIGHCVSS 7.5EG 7.52023-07-27
Sails is a realtime MVC Framework for Node.js. In Sails apps prior to version 1.5.7,, an attacker can send a virtual request that will cause the node process to crash. This behavior was fixed in Sails v1.5.7. As a workaround, disable the s…
- CVE-2023-3966HIGHCVSS 7.5EG 7.52024-02-22
A flaw was found in Open vSwitch where multiple versions are vulnerable to crafted Geneve packets, which may result in a denial of service and invalid memory accesses. Triggering this issue requires that hardware offloading via the netlink…
- CVE-2023-39945HIGHCVSS 8.2EG 8.22023-08-11
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.11.0, 2.10.2, 2.9.2, and 2.6.5, a data submessage sent to PDP port raises unhandled `BadParamException`…
- CVE-2023-39948HIGHCVSS 7.5EG 7.52023-08-11
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.10.0 and 2.6.5, the `BadParamException` thrown by Fast CDR is not caught in Fast DDS. This can remotely…
- CVE-2023-42444HIGHCVSS 8.6EG 8.62023-09-19
phonenumber is a library for parsing, formatting and validating international phone numbers. Prior to versions `0.3.3+8.13.9` and `0.2.5+8.11.3`, the phonenumber parsing code may panic due to a panic-guarded out-of-bounds access on the pho…
- CVE-2023-42447HIGHCVSS 8.6EG 8.62023-09-19
blurhash-rs is a pure Rust implementation of Blurhash, software for encoding images into ASCII strings that can be turned into a gradient of colors representing the original image. In version 0.1.1, the blurhash parsing code may panic due …
- CVE-2023-46135MEDIUMCVSS 5.3EG 5.32023-10-25
rs-stellar-strkey is a Rust lib for encode/decode of Stellar Strkeys. A panic vulnerability occurs when a specially crafted payload is used.`inner_payload_len` should not above 64. This vulnerability has been patched in version 0.0.8.
- CVE-2023-46239HIGHCVSS 7.5EG 7.52023-10-31
quic-go is an implementation of the QUIC protocol in Go. Starting in version 0.37.0 and prior to version 0.37.3, by serializing an ACK frame after the CRYTPO that allows a node to complete the handshake, a remote node could trigger a nil p…
- CVE-2023-46765HIGHCVSS 7.5EG 7.52023-11-08
Vulnerability of uncaught exceptions in the NFC module. Successful exploitation of this vulnerability can affect NFC availability.
- CVE-2023-4785HIGHCVSS 7.5EG 7.52023-09-13
Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. No…
- CVE-2023-5038HIGHCVSS 7.5EG 7.52024-06-25
badmonkey, a Security Researcher has found a flaw that allows for a unauthenticated DoS attack on the camera. An attacker runs a crafted URL, nobody can access the web management page of the camera. and must manually restart the device or …
- CVE-2023-52342HIGHCVSS 7.5EG 7.52024-04-08
In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no additional execution privileges needed
- CVE-2023-5310MEDIUMCVSS 5.7EG 5.72023-12-15
A denial of service vulnerability exists in all Silicon Labs Z-Wave controller and endpoint devices running Z-Wave SDK v7.20.3 (Gecko SDK v4.3.3) and earlier. This attack can be carried out only by devices on the network sending a stream o…
- CVE-2023-6533MEDIUMCVSS 6.5EG 6.52024-02-21
Malformed Device Reset Locally Command Class packets can be sent to the controller, causing the controller to assume the end device has left the network. After this, frames sent by the end device will not be acknowledged by the controller.…
- CVE-2023-6640MEDIUMCVSS 6.5EG 6.52024-02-21
Malformed S2 Nonce Get Command Class packets can be sent to crash PC Controller v5.54.0 and earlier.
- CVE-2024-0754MEDIUMCVSS 6.5EG 6.52024-01-23
Some WASM source files could have caused a crash when loaded in devtools. This vulnerability affects Firefox < 122.
- CVE-2024-11172HIGHCVSS 7.5EG 7.52025-03-20
A vulnerability in danny-avila/librechat version git a1647d7 allows an unauthenticated attacker to cause a denial of service by sending a crafted payload to the server. The middleware `checkBan` is not surrounded by a try-catch block, and …
- CVE-2024-11173MEDIUMCVSS 6.5EG 6.52025-03-20
An unhandled exception in the danny-avila/librechat repository, version git 600d217, can cause the server to crash, leading to a full denial of service. This issue occurs when certain API endpoints receive malformed input, resulting in an …
- CVE-2024-11738MEDIUMCVSS 5.3EG 5.32024-12-06
A flaw was found in Rustls 0.23.13 and related APIs. This vulnerability allows denial of service (panic) via a fragmented TLS ClientHello message.
- CVE-2024-13417MEDIUMCVSS 4.6EG 4.62025-02-06
Specifically crafted payloads sent to the RFID reader could cause DoS of RFID reader. After the device is restarted, it gets back to fully working state. 2N has released an updated version 2.46 of 2N OS, where this vulnerability is mit…
- CVE-2024-20048MEDIUMCVSS 6.2EG 6.22024-04-01
In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS085…
- CVE-2024-20049MEDIUMCVSS 4.4EG 4.42024-04-01
In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS085…
- CVE-2024-20137HIGHCVSS 7.5EG 7.52024-12-02
In wlan driver, there is a possible client disconnection due to improper handling of exceptional conditions. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exp…
- CVE-2024-20276HIGHCVSS 7.4EG 7.42024-03-27
A vulnerability in Cisco IOS Software for Cisco Catalyst 6000 Series Switches could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly. This vulnerability is due to improper handling of proces…
- CVE-2024-21983MEDIUMCVSS 6.5EG 6.52024-02-16
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8 are susceptible to a Denial of Service (DoS) vulnerability. Successful exploit by an authenticated attacker could lead to an out of memory condition or node reboot.
- CVE-2024-23325HIGHCVSS 7.5EG 7.52024-02-09
Envoy is a high-performance edge/middle/service proxy. Envoy crashes in Proxy protocol when using an address type that isn’t supported by the OS. Envoy is susceptible to crashing on a host with IPv6 disabled and a listener config with pr…
- CVE-2024-23449MEDIUMCVSS 4.3EG 4.32024-03-29
An uncaught exception in Elasticsearch >= 8.4.0 and < 8.11.1 occurs when an encrypted PDF is passed to an attachment processor through the REST API. The Elasticsearch ingest node that attempts to parse the PDF file will crash. This does no…
- CVE-2024-28835MEDIUMCVSS 5.0EG 5.02024-03-21
A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .pem bundle using the "certtool --verify-chain" command.
- CVE-2024-29076MEDIUMCVSS 5.5EG 5.52024-11-13
Uncaught exception for some Intel(R) CST software before version 8.7.10803 may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2024-3051HIGHCVSS 7.5EG 7.52024-04-26
Malformed Device Reset Locally command classes can be sent to temporarily deny service to an end device. Any frames sent by the end device will not be acknowledged by the gateway during this time.
- CVE-2024-3052HIGHCVSS 7.5EG 7.52024-04-26
Malformed S2 Nonce Get command classes can be sent to crash the gateway. A hard reset is required to recover the gateway.
- CVE-2024-31217MEDIUMCVSS 5.3EG 5.32024-06-12
Strapi is an open-source content management system. Prior to version 4.22.0, a denial-of-service vulnerability is present in the media upload process causing the server to crash without restarting, affecting either development and producti…
- CVE-2024-31904MEDIUMCVSS 6.5EG 6.52024-05-22
IBM App Connect Enterprise 11.0.0.1 through 11.0.0.25 and 12.0.1.0 through 12.0.12.0 integration nodes could allow an authenticated user to cause a denial of service due to an uncaught exception. IBM X-Force ID: 289647.
- CVE-2024-32995MEDIUMCVSS 6.2EG 6.22024-05-14
Denial of service (DoS) vulnerability in the AMS module Impact: Successful exploitation of this vulnerability will affect availability.
- CVE-2024-33848MEDIUMCVSS 6.5EG 6.52024-09-16
Uncaught exception in Intel(R) RAID Web Console software all versions may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2024-34363HIGHCVSS 7.5EG 7.52024-06-04
Envoy is a cloud-native, open source edge and service proxy. Due to how Envoy invoked the nlohmann JSON library, the library could throw an uncaught exception from downstream data if incomplete UTF-8 strings were serialized. The uncaught e…
- CVE-2024-38525HIGHCVSS 7.5EG 7.52024-06-28
dd-trace-cpp is the Datadog distributed tracing for C++. When the library fails to extract trace context due to malformed unicode, it logs the list of audited headers and their values using the `nlohmann` JSON library. However, due to the …
- CVE-2024-42037CRITICALCVSS 9.3EG 9.32024-08-08
Vulnerability of uncaught exceptions in the Graphics module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-43357HIGHCVSS 8.6EG 8.62024-08-15
ECMA-262 is the language specification for the scripting language ECMAScript. A problem in the ECMAScript (JavaScript) specification of async generators, introduced by a May 2021 spec refactor, may lead to mis-implementation in a way that …
Map vulnerabilities like CWE-248 to your infrastructure
EchelonGraph correlates every CVE — across CWE-248 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →