Skip to content
Noroxi

CWE-684 · 27 records

Incorrect Provision of Specified Functionality

CVEs in this class

27 records

  • A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i802, RUGGEDCOM i802NC,

    CriticalCVSS 9.8No exploitEPSS 1%

    siemens · ruggedcom rosAug 8, 2023

  • In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in

    CriticalCVSS 9.8No exploitEPSS 1%

    exim · eximApr 30, 2026

  • FutureNet NXR series routers provided by Century Systems Co., Ltd.

    CriticalCVSS 9.8No exploitEPSS 1%

    century systems co., ltd. · futurenet nxr-g110 seriesNov 29, 2024

  • ZEBRA: Consensus divergence via P2SH sigop undercount in pure-Rust disabled-opcode parser

    CriticalCVSS 9.3No exploitEPSS 1%

    zcashfoundation · zebraAug 18, 2026

  • Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload, aka TROVE-2026-011.

    CriticalCVSS 9.1No exploitEPSS 1%

    torproject · torMay 6, 2026

  • CVE-2024-6425
    36Monitor

    Incorrect Provision of Specified Functionality vulnerability in MESbook

    CriticalCVSS 9.1No exploitEPSS 1%

    mesbook · mesbookJul 1, 2024

  • app/Controller/EventsController.php in MISP before 2.5.24 has invalid logic in checking for uploaded file validity, related to tmp_name.

    HighCVSS 8.2No exploitEPSS 0%

    misp · mispNov 28, 2025

  • CVE-2023-5363
    31Monitor

    Incorrect cipher key & IV length processing

    HighCVSS 7.5No exploitEPSS 3%

    openssl · opensslOct 25, 2023

  • In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), the Administrator password reset mechanism is mishandle

    HighCVSS 7.5Proof of conceptEPSS 2%

    scriptcase · scriptcaseJul 4, 2025

  • In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is pres

    HighCVSS 7.5No exploitEPSS 1%

    exim · eximApr 30, 2026

  • Cisco IOS XR Software Layer 2 Services Denial of Service Vulnerability

    HighCVSS 7.4No exploitEPSS 0%

    cisco · ios xrSep 11, 2024

  • CVE-2023-4258
    26Monitor

    bt: mesh: vulnerability in provisioning protocol implementation on provisionee side

    MediumCVSS 6.5No exploitEPSS 1%

    zephyrproject · zephyrSep 25, 2023

  • CVE-2024-6502
    26Monitor

    Incorrect Provision of Specified Functionality in GitLab

    MediumCVSS 6.5No exploitEPSS 0%

    gitlab · gitlabAug 22, 2024

  • Technitium DNS Server before 15.0 allows DNS traffic amplification via cyclic name server delegation.

    MediumCVSS 6.5No exploitEPSS 0%

    technitium · dnsserverApr 26, 2026

  • An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2.5 through 7.2.10, 7.0.0

    MediumCVSS 6.7No exploitEPSS 0%

    fortinet · fortiosOct 14, 2025

  • Attacker can reset the device with AT Command in the process of rebooting the device.

    MediumCVSS 6.1No exploitEPSS 0%

    google · androidJan 21, 2022

  • Incorrect provision of specified functionality in Proxy in Google Chrome on on Windows prior to 152.0.7977.65 allowed an adjacent attacker t

    MediumCVSS 5.9No exploitEPSS 0%

    google · chromeAug 25, 2026

  • CVE-2023-5158
    22Monitor

    Possible dos from guest to host invringh_kiov_advance in vhost driver at drivers/vhost/vringh.c

    MediumCVSS 5.5No exploitEPSS 0%

    linux · linux kernelSep 25, 2023

  • hw/pci/pcie_sriov.c in QEMU through 10.0.3 mishandles the VF Enable bit write mask, a related issue to CVE-2024-26327.

    MediumCVSS 5.4No exploitEPSS 0%

    qemu · qemuJul 24, 2025

  • CVE-2024-5005
    17Monitor

    Incorrect Provision of Specified Functionality in GitLab

    MediumCVSS 4.3No exploitEPSS 0%

    gitlab · gitlabOct 11, 2024

  • CVE-2024-8974
    17Monitor

    Incorrect Provision of Specified Functionality in GitLab

    MediumCVSS 4.3No exploitEPSS 0%

    gitlab · gitlabSep 26, 2024

  • Incorrect Provision of Specified Functionality in qutebrowser

    LowCVSS 3.5No exploitEPSS 2%

    qutebrowser · qutebrowserMay 7, 2020

  • Akamai Rate Control alpha before 2025 allows attackers to send requests above the stipulated thresholds because the rate is measured separat

    LowCVSS 3.7No exploitEPSS 0%

    akamai · rate controlJul 25, 2025

  • uutils coreutils tr Local Logic Error and Data Integrity Issue in Character Class Handling

    LowCVSS 3.3No exploitEPSS 0%

    uutils · coreutilsApr 22, 2026

  • uutils coreutils cut Local Logic Error and Data Integrity Issue in Output Filtering

    LowCVSS 3.3No exploitEPSS 0%

    uutils · coreutilsApr 22, 2026

All vulnerability classes