The behavior of this function is undefined unless its control parameter is set to a specific value.
Volume of CVEs assigned to CWE-475 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-42009HIGH A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible f | May 18, 2026 | 7.5 | 35 | NO | NO |
CVE-2026-8391HIGH Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderbird 140.11. | May 12, 2026 | 7.5 | 32 | NO | NO |
CVE-2025-47865CRITICAL A Local File Inclusion vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker to gain remote code execution on affected installations. | Jun 17, 2025 | 9.8 | 26 | NO | NO |
CVE-2026-34379HIGH OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, | Apr 6, 2026 | 7.1 | 25 | NO | NO |
CVE-2024-20380HIGH A vulnerability in the HTML parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
The vulnerability | Apr 18, 2024 | 7.5 | 24 | NO | NO |
CVE-2023-4874MEDIUM Null pointer dereference when viewing a specially crafted email in Mutt >1.5.2 <2.2.12 | Sep 9, 2023 | 6.5 | 23 | NO | NO |
CVE-2025-47866HIGH An unrestricted file upload vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker to upload arbitrary files on affected installations. | Jun 17, 2025 | 7.5 | 22 | NO | NO |
CVE-2024-10569HIGH A vulnerability in the dataframe component of gradio-app/gradio (version git 98cbcae) allows for a zip bomb attack. The component uses pd.read_csv to process input values, which ca | Mar 20, 2025 | 7.5 | 21 | NO | NO |
CVE-2023-2253MEDIUM A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records returned (query string: `n`). This | Jun 6, 2023 | 6.5 | 21 | NO | NO |
CVE-2026-21690MEDIUM iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versio | Jan 7, 2026 | 6.3 | 20 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.