CWE-67
4 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-67page 1 of 1
- CVE-2024-35197MEDIUMCVSS 5.4EG 5.42024-05-23
gitoxide is a pure Rust implementation of Git. On Windows, fetching refs that clash with legacy device names reads from the devices, and checking out paths that clash with such names writes arbitrary data to the devices. This allows a repo…
- CVE-2024-51745CRITICALCVSS 10.0EG 10.02024-11-05
Wasmtime is a fast and secure runtime for WebAssembly. Wasmtime's filesystem sandbox implementation on Windows blocks access to special device filenames such as "COM1", "COM2", "LPT0", "LPT1", and so on, however it did not block access to …
- CVE-2025-66221MEDIUMCVSS 5.3EG 5.32025-11-29
Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.4, Werkzeug's safe_join function allows path segments with Windows device names. On Windows, there are special device names such as CON, AUX, etc that are impli…
- CVE-2026-21860MEDIUMCVSS 5.3EG 5.32026-01-08
Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.5, Werkzeug's safe_join function allows path segments with Windows device names that have file extensions or trailing spaces. On Windows, there are special devi…
Map vulnerabilities like CWE-67 to your infrastructure
EchelonGraph correlates every CVE — across CWE-67 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →