Auto-created placeholder
Volume of CVEs assigned to CWE-388 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
42 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1002105CRITICAL In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-apiserver allowed specially crafte | Dec 5, 2018 | 9.8 | 85 | NO | YES |
CVE-2018-0155HIGH A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow | Mar 28, 2018 | 8.6 | 69 | YES | NO |
CVE-2017-5401CRITICAL A crash triggerable by web content in which an "ErrorResult" references unassigned memory due to a logic error. The resulting crash may be exploitable. This vulnerability affects F | Jun 11, 2018 | 9.8 | 32 | NO | NO |
CVE-2016-7990CRITICAL On Samsung Galaxy S4 through S7 devices, an integer overflow condition exists within libomacp.so when parsing OMACP messages (within WAP Push SMS messages) leading to a heap corrup | Oct 31, 2016 | 9.8 | 31 | NO | NO |
CVE-2026-20168MEDIUM A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to retrieve files that t | May 6, 2026 | 6.5 | 30 | NO | NO |
CVE-2016-10466CRITICAL In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM96 | Apr 18, 2018 | 9.8 | 30 | NO | NO |
CVE-2016-10414CRITICAL In Android before 2018-04-05 or earlier security patch level on Qualcomm Small Cell SoC, Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear FSM9055, IPQ4019, MDM9206, MD | Apr 18, 2018 | 9.8 | 27 | NO | NO |
CVE-2014-9826CRITICAL ImageMagick allows remote attackers to have unspecified impact via vectors related to error handling in sun files. | Mar 30, 2017 | 9.8 | 27 | NO | NO |
CVE-2016-9965CRITICAL Lack of appropriate exception handling in some receivers of the Telecom application on Samsung Note devices with L(5.0/5.1), M(6.0), and N(7.0) software allows attackers to crash t | Dec 16, 2016 | 9.8 | 27 | NO | NO |
CVE-2014-9985CRITICAL In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9635M, SD 400, and SD 800, TOCTOU condition may result in bypassing error condition ch | Apr 18, 2018 | 9.8 | 26 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.