CWE-758 · 19 records
Reliance on Undefined, Unspecified, or Implementation-Defined Behavior
CVEs in this class
19 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2026-4705No exploit | Undefined behavior in the WebRTC: Signaling componentmozilla · firefox · CWE-758 | Critical9.8 | — | 0.6% | Mar 24, 2026 |
38Monitor | GHSA-5w5r-mf82-595pNo exploit | Cap'n Proto has Undefined Behavior in constant::Reader and StructSchemacrates.io · capnp · CWE-758 | Critical9.5 | — | — | Jan 28, 2026 |
36Monitor | CVE-2026-4724No exploit | Undefined behavior in the Audio/Video componentmozilla · firefox · CWE-758 | Critical9.1 | — | 0.4% | Mar 24, 2026 |
35Monitor | CVE-2023-30624No exploit | Wasmtime has Undefined Behavior in Rust runtime functionsbytecodealliance · wasmtime · CWE-758 | High8.8 | — | 0.5% | Apr 27, 2023 |
32Monitor | CVE-2026-4718No exploit | Undefined behavior in the WebRTC: Signaling componentmozilla · firefox · CWE-758 | High8.1 | — | 0.5% | Mar 24, 2026 |
32Monitor | GHSA-gfxp-f68g-8x78No exploit | LibYML: `libyml::string::yaml_string_extend` is unsound and unmaintainedcrates.io · libyml · CWE-758 | High8.0 | — | — | Sep 15, 2025 |
27Monitor | CVE-2026-16441No exploit | Eclipse OpenJ9 : Method resolution default method precedence failureeclipse · openj9 · CWE-758 | Medium6.9 | — | 0.5% | Jul 21, 2026 |
26Monitor | CVE-2024-4774No exploit | The `ShmemCharMapHashEntry()` code was susceptible to potentially undefined behavior by bypassing the move semantics for one of its data memmozilla · firefox · CWE-758 | Medium6.5 | — | 0.4% | May 14, 2024 |
24Monitor | CVE-2025-54811No exploit | OpenPLC_V3 has a vulnerability in the enipThread function that occurs due to the lack of a return value.openplc_v3 · openplc_v3 · CWE-758 | Medium6.1 | — | 0.2% | Oct 1, 2025 |
22Monitor | CVE-2026-34533No exploit | iccDEV: UB in CIccCalculatorFunc::ApplySequence()color · iccdev · CWE-758 | Medium5.5 | — | 0.2% | Mar 31, 2026 |
22Monitor | CVE-2026-34537No exploit | iccDEV: UB in CIccOpDefEnvVar::Exec()color · iccdev · CWE-758 | Medium5.5 | — | 0.2% | Mar 31, 2026 |
22Monitor | CVE-2026-34547No exploit | iccDEV: UB at IccUtil.cppcolor · iccdev · CWE-758 | Medium5.5 | — | 0.2% | Mar 31, 2026 |
22Monitor | CVE-2026-34549No exploit | iccDEV: UB at IccUtil.cppcolor · iccdev · CWE-758 | Medium5.5 | — | 0.2% | Mar 31, 2026 |
21Monitor | CVE-2026-54604No exploit | OpenSlide: openslide_read_region() returns uninitialized memory with libtiff 4.7.1openslide · openslide · CWE-758 | Medium5.3 | — | 0.5% | Sep 17, 2026 |
21Monitor | CVE-2025-55160No exploit | ImageMagick Undefined Behavior (function-type-mismatch) in CloneSplayTreeimagemagick · imagemagick · CWE-758 | Medium5.3 | — | 0.4% | Aug 13, 2025 |
14Monitor | CVE-2026-40279No exploit | BACnet Stack: Undefined-behavior signed left shift in `decode_signed32()`bacnetstack · bacnet stack · CWE-758 | Low3.7 | — | 0.3% | Apr 21, 2026 |
10Monitor | GHSA-3288-p39f-rqpvNo exploit | Unsoundness in opt-in ARMv8 assembly backend for `keccak`crates.io · keccak · CWE-758 | Low2.5 | — | — | Feb 19, 2026 |
8Monitor | CVE-2026-50185No exploit | RustCrypto Cmov/CmovEq on aarch64 can produce wrong results if high-bits of registers are setrustcrypto · cmov · CWE-758 | Low2.0 | — | 0.2% | Jul 17, 2026 |
8Monitor | CVE-2024-58350No exploit | Ghidra < 11.2 - Use After Free in Sleigh Backend via Static Initialization Ordernsa · ghidra · CWE-758 | Low2.1 | — | 0.1% | Jun 10, 2026 |
- CVE-2026-470539Monitor
Undefined behavior in the WebRTC: Signaling component
CriticalCVSS 9.8No exploitEPSS 1%mozilla · firefoxMar 24, 2026
- GHSA-5w5r-mf82-595p38Monitor
Cap'n Proto has Undefined Behavior in constant::Reader and StructSchema
CriticalCVSS 9.5No exploitcrates.io · capnpJan 28, 2026
- CVE-2026-472436Monitor
Undefined behavior in the Audio/Video component
CriticalCVSS 9.1No exploitEPSS 0%mozilla · firefoxMar 24, 2026
- CVE-2023-3062435Monitor
Wasmtime has Undefined Behavior in Rust runtime functions
HighCVSS 8.8No exploitEPSS 0%bytecodealliance · wasmtimeApr 27, 2023
- CVE-2026-471832Monitor
Undefined behavior in the WebRTC: Signaling component
HighCVSS 8.1No exploitEPSS 0%mozilla · firefoxMar 24, 2026
- GHSA-gfxp-f68g-8x7832Monitor
LibYML: `libyml::string::yaml_string_extend` is unsound and unmaintained
HighCVSS 8.0No exploitcrates.io · libymlSep 15, 2025
- CVE-2026-1644127Monitor
Eclipse OpenJ9 : Method resolution default method precedence failure
MediumCVSS 6.9No exploitEPSS 1%eclipse · openj9Jul 21, 2026
- CVE-2024-477426Monitor
The `ShmemCharMapHashEntry()` code was susceptible to potentially undefined behavior by bypassing the move semantics for one of its data mem
MediumCVSS 6.5No exploitEPSS 0%mozilla · firefoxMay 14, 2024
- CVE-2025-5481124Monitor
OpenPLC_V3 has a vulnerability in the enipThread function that occurs due to the lack of a return value.
MediumCVSS 6.1No exploitEPSS 0%openplc_v3 · openplc_v3Oct 1, 2025
- CVE-2026-3453322Monitor
iccDEV: UB in CIccCalculatorFunc::ApplySequence()
MediumCVSS 5.5No exploitEPSS 0%color · iccdevMar 31, 2026
- CVE-2026-3453722Monitor
iccDEV: UB in CIccOpDefEnvVar::Exec()
MediumCVSS 5.5No exploitEPSS 0%color · iccdevMar 31, 2026
- CVE-2026-3454722Monitor
iccDEV: UB at IccUtil.cpp
MediumCVSS 5.5No exploitEPSS 0%color · iccdevMar 31, 2026
- CVE-2026-3454922Monitor
iccDEV: UB at IccUtil.cpp
MediumCVSS 5.5No exploitEPSS 0%color · iccdevMar 31, 2026
- CVE-2026-5460421Monitor
OpenSlide: openslide_read_region() returns uninitialized memory with libtiff 4.7.1
MediumCVSS 5.3No exploitEPSS 1%openslide · openslideSep 17, 2026
- CVE-2025-5516021Monitor
ImageMagick Undefined Behavior (function-type-mismatch) in CloneSplayTree
MediumCVSS 5.3No exploitEPSS 0%imagemagick · imagemagickAug 13, 2025
- CVE-2026-4027914Monitor
BACnet Stack: Undefined-behavior signed left shift in `decode_signed32()`
LowCVSS 3.7No exploitEPSS 0%bacnetstack · bacnet stackApr 21, 2026
- GHSA-3288-p39f-rqpv10Monitor
Unsoundness in opt-in ARMv8 assembly backend for `keccak`
LowCVSS 2.5No exploitcrates.io · keccakFeb 19, 2026
- CVE-2026-501858Monitor
RustCrypto Cmov/CmovEq on aarch64 can produce wrong results if high-bits of registers are set
LowCVSS 2.0No exploitEPSS 0%rustcrypto · cmovJul 17, 2026
- CVE-2024-583508Monitor
Ghidra < 11.2 - Use After Free in Sleigh Backend via Static Initialization Order
LowCVSS 2.1No exploitEPSS 0%nsa · ghidraJun 10, 2026