Auto-created placeholder
Volume of CVEs assigned to CWE-18 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-7263CRITICAL Linear eMerge E3-Series devices have a Version Control Failure. | Jul 2, 2019 | 9.8 | 31 | NO | NO |
NTP before 4.2.8p9 changes the peer structure to the interface it receives the response from a source, which allows remote attackers to cause a denial of service (prevent communica | Jan 13, 2017 | 3.7 | 20 | NO | NO |
CVE-2015-2696HIGH lib/gssapi/krb5/iakerb.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect p | Nov 9, 2015 | 7.1 | 20 | NO | NO |
CVE-2015-7262HIGH QNAP iArtist Lite before 1.4.54, as distributed with QNAP Signage Station before 2.0.1, allows remote authenticated users to gain privileges by registering an executable file, and | Feb 27, 2016 | 7.5 | 19 | NO | NO |
CVE-2015-0962MEDIUM Barracuda Web Filter 7.x and 8.x before 8.1.0.005, when SSL Inspection is enabled, uses the same root Certification Authority certificate across different customers' installations, | May 25, 2015 | 4.3 | 14 | NO | NO |
The check_diskio plugin 3.2.6 and earlier for Nagios and Icinga allows local users to write to arbitrary files via a symlink attack on a temporary file with a predictable name (tmp | Nov 28, 2014 | 3.6 | 13 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.