CWE-684 · 27 записей
Incorrect Provision of Specified Functionality
CVE этого класса
27 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2023-24845Эксплойта нет | A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i802, RUGGEDCOM i802NC,siemens · ruggedcom ros · CWE-684 | Критическая9,8 | — | 0,7 % | 8 авг. 2023 г. |
39Наблюдать | CVE-2026-40685Эксплойта нет | In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in exim · exim · CWE-684 | Критическая9,8 | — | 0,6 % | 30 апр. 2026 г. |
39Наблюдать | CVE-2024-50357Эксплойта нет | FutureNet NXR series routers provided by Century Systems Co., Ltd.century systems co., ltd. · futurenet nxr-g110 series · CWE-684 | Критическая9,8 | — | 0,6 % | 29 нояб. 2024 г. |
37Наблюдать | CVE-2026-52735Эксплойта нет | ZEBRA: Consensus divergence via P2SH sigop undercount in pure-Rust disabled-opcode parserzcashfoundation · zebra · CWE-684 | Критическая9,3 | — | 0,5 % | 18 авг. 2026 г. |
36Наблюдать | CVE-2026-44597Эксплойта нет | Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload, aka TROVE-2026-011.torproject · tor · CWE-684 | Критическая9,1 | — | 0,6 % | 6 мая 2026 г. |
36Наблюдать | CVE-2024-6425Эксплойта нет | Incorrect Provision of Specified Functionality vulnerability in MESbookmesbook · mesbook · CWE-684 | Критическая9,1 | — | 0,5 % | 1 июл. 2024 г. |
32Наблюдать | CVE-2025-66384Эксплойта нет | app/Controller/EventsController.php in MISP before 2.5.24 has invalid logic in checking for uploaded file validity, related to tmp_name.misp · misp · CWE-684 | Высокая8,2 | — | 0,4 % | 28 нояб. 2025 г. |
31Наблюдать | CVE-2023-5363Эксплойта нет | Incorrect cipher key & IV length processingopenssl · openssl · CWE-684 | Высокая7,5 | — | 3,3 % | 25 окт. 2023 г. |
31Наблюдать | CVE-2025-47227Proof of concept | In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), the Administrator password reset mechanism is mishandlescriptcase · scriptcase · CWE-684 | Высокая7,5 | — | 2,1 % | 4 июл. 2025 г. |
30Наблюдать | CVE-2026-40684Эксплойта нет | In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is presexim · exim · CWE-684 | Высокая7,5 | — | 0,6 % | 30 апр. 2026 г. |
29Наблюдать | CVE-2024-20317Эксплойта нет | Cisco IOS XR Software Layer 2 Services Denial of Service Vulnerabilitycisco · ios xr · CWE-684 | Высокая7,4 | — | 0,2 % | 11 сент. 2024 г. |
26Наблюдать | CVE-2023-4258Эксплойта нет | bt: mesh: vulnerability in provisioning protocol implementation on provisionee sidezephyrproject · zephyr · CWE-684 | Средняя6,5 | — | 0,6 % | 25 сент. 2023 г. |
26Наблюдать | CVE-2024-6502Эксплойта нет | Incorrect Provision of Specified Functionality in GitLabgitlab · gitlab · CWE-684 | Средняя6,5 | — | 0,4 % | 22 авг. 2024 г. |
26Наблюдать | CVE-2026-42255Эксплойта нет | Technitium DNS Server before 15.0 allows DNS traffic amplification via cyclic name server delegation.technitium · dnsserver · CWE-684 | Средняя6,5 | — | 0,4 % | 26 апр. 2026 г. |
26Наблюдать | CVE-2025-58325Эксплойта нет | An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2.5 through 7.2.10, 7.0.0fortinet · fortios · CWE-684 | Средняя6,7 | — | 0,3 % | 14 окт. 2025 г. |
24Наблюдать | CVE-2022-23728Эксплойта нет | Attacker can reset the device with AT Command in the process of rebooting the device.google · android · CWE-684 | Средняя6,1 | — | 0,1 % | 21 янв. 2022 г. |
23Наблюдать | CVE-2026-79126Эксплойта нет | Incorrect provision of specified functionality in Proxy in Google Chrome on on Windows prior to 152.0.7977.65 allowed an adjacent attacker tgoogle · chrome · CWE-684 | Средняя5,9 | — | 0,2 % | 25 авг. 2026 г. |
22Наблюдать | CVE-2023-5158Эксплойта нет | Possible dos from guest to host invringh_kiov_advance in vhost driver at drivers/vhost/vringh.clinux · linux kernel · CWE-684 | Средняя5,5 | — | 0,2 % | 25 сент. 2023 г. |
21Наблюдать | CVE-2025-54567Эксплойта нет | hw/pci/pcie_sriov.c in QEMU through 10.0.3 mishandles the VF Enable bit write mask, a related issue to CVE-2024-26327.qemu · qemu · CWE-684 | Средняя5,4 | — | 0,2 % | 24 июл. 2025 г. |
17Наблюдать | CVE-2024-5005Эксплойта нет | Incorrect Provision of Specified Functionality in GitLabgitlab · gitlab · CWE-684 | Средняя4,3 | — | 0,4 % | 11 окт. 2024 г. |
17Наблюдать | CVE-2024-8974Эксплойта нет | Incorrect Provision of Specified Functionality in GitLabgitlab · gitlab · CWE-684 | Средняя4,3 | — | 0,3 % | 26 сент. 2024 г. |
14Наблюдать | CVE-2020-11054Эксплойта нет | Incorrect Provision of Specified Functionality in qutebrowserqutebrowser · qutebrowser · CWE-684 | Низкая3,5 | — | 1,5 % | 7 мая 2020 г. |
14Наблюдать | CVE-2025-54568Эксплойта нет | Akamai Rate Control alpha before 2025 allows attackers to send requests above the stipulated thresholds because the rate is measured separatakamai · rate control · CWE-684 | Низкая3,7 | — | 0,3 % | 25 июл. 2025 г. |
13Наблюдать | CVE-2026-35379Эксплойта нет | uutils coreutils tr Local Logic Error and Data Integrity Issue in Character Class Handlinguutils · coreutils · CWE-684 | Низкая3,3 | — | 0,2 % | 22 апр. 2026 г. |
13Наблюдать | CVE-2026-35381Эксплойта нет | uutils coreutils cut Local Logic Error and Data Integrity Issue in Output Filteringuutils · coreutils · CWE-684 | Низкая3,3 | — | 0,2 % | 22 апр. 2026 г. |
- CVE-2023-2484539Наблюдать
A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i802, RUGGEDCOM i802NC,
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %siemens · ruggedcom ros8 авг. 2023 г.
- CVE-2026-4068539Наблюдать
In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %exim · exim30 апр. 2026 г.
- CVE-2024-5035739Наблюдать
FutureNet NXR series routers provided by Century Systems Co., Ltd.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %century systems co., ltd. · futurenet nxr-g110 series29 нояб. 2024 г.
- CVE-2026-5273537Наблюдать
ZEBRA: Consensus divergence via P2SH sigop undercount in pure-Rust disabled-opcode parser
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %zcashfoundation · zebra18 авг. 2026 г.
- CVE-2026-4459736Наблюдать
Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload, aka TROVE-2026-011.
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %torproject · tor6 мая 2026 г.
- CVE-2024-642536Наблюдать
Incorrect Provision of Specified Functionality vulnerability in MESbook
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %mesbook · mesbook1 июл. 2024 г.
- CVE-2025-6638432Наблюдать
app/Controller/EventsController.php in MISP before 2.5.24 has invalid logic in checking for uploaded file validity, related to tmp_name.
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %misp · misp28 нояб. 2025 г.
- CVE-2023-536331Наблюдать
Incorrect cipher key & IV length processing
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %openssl · openssl25 окт. 2023 г.
- CVE-2025-4722731Наблюдать
In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), the Administrator password reset mechanism is mishandle
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %scriptcase · scriptcase4 июл. 2025 г.
- CVE-2026-4068430Наблюдать
In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is pres
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %exim · exim30 апр. 2026 г.
- CVE-2024-2031729Наблюдать
Cisco IOS XR Software Layer 2 Services Denial of Service Vulnerability
ВысокаяCVSS 7,4Эксплойта нетEPSS 0 %cisco · ios xr11 сент. 2024 г.
- CVE-2023-425826Наблюдать
bt: mesh: vulnerability in provisioning protocol implementation on provisionee side
СредняяCVSS 6,5Эксплойта нетEPSS 1 %zephyrproject · zephyr25 сент. 2023 г.
- CVE-2024-650226Наблюдать
Incorrect Provision of Specified Functionality in GitLab
СредняяCVSS 6,5Эксплойта нетEPSS 0 %gitlab · gitlab22 авг. 2024 г.
- CVE-2026-4225526Наблюдать
Technitium DNS Server before 15.0 allows DNS traffic amplification via cyclic name server delegation.
СредняяCVSS 6,5Эксплойта нетEPSS 0 %technitium · dnsserver26 апр. 2026 г.
- CVE-2025-5832526Наблюдать
An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2.5 through 7.2.10, 7.0.0
СредняяCVSS 6,7Эксплойта нетEPSS 0 %fortinet · fortios14 окт. 2025 г.
- CVE-2022-2372824Наблюдать
Attacker can reset the device with AT Command in the process of rebooting the device.
СредняяCVSS 6,1Эксплойта нетEPSS 0 %google · android21 янв. 2022 г.
- CVE-2026-7912623Наблюдать
Incorrect provision of specified functionality in Proxy in Google Chrome on on Windows prior to 152.0.7977.65 allowed an adjacent attacker t
СредняяCVSS 5,9Эксплойта нетEPSS 0 %google · chrome25 авг. 2026 г.
- CVE-2023-515822Наблюдать
Possible dos from guest to host invringh_kiov_advance in vhost driver at drivers/vhost/vringh.c
СредняяCVSS 5,5Эксплойта нетEPSS 0 %linux · linux kernel25 сент. 2023 г.
- CVE-2025-5456721Наблюдать
hw/pci/pcie_sriov.c in QEMU through 10.0.3 mishandles the VF Enable bit write mask, a related issue to CVE-2024-26327.
СредняяCVSS 5,4Эксплойта нетEPSS 0 %qemu · qemu24 июл. 2025 г.
- CVE-2024-500517Наблюдать
Incorrect Provision of Specified Functionality in GitLab
СредняяCVSS 4,3Эксплойта нетEPSS 0 %gitlab · gitlab11 окт. 2024 г.
- CVE-2024-897417Наблюдать
Incorrect Provision of Specified Functionality in GitLab
СредняяCVSS 4,3Эксплойта нетEPSS 0 %gitlab · gitlab26 сент. 2024 г.
- CVE-2020-1105414Наблюдать
Incorrect Provision of Specified Functionality in qutebrowser
НизкаяCVSS 3,5Эксплойта нетEPSS 2 %qutebrowser · qutebrowser7 мая 2020 г.
- CVE-2025-5456814Наблюдать
Akamai Rate Control alpha before 2025 allows attackers to send requests above the stipulated thresholds because the rate is measured separat
НизкаяCVSS 3,7Эксплойта нетEPSS 0 %akamai · rate control25 июл. 2025 г.
- CVE-2026-3537913Наблюдать
uutils coreutils tr Local Logic Error and Data Integrity Issue in Character Class Handling
НизкаяCVSS 3,3Эксплойта нетEPSS 0 %uutils · coreutils22 апр. 2026 г.
- CVE-2026-3538113Наблюдать
uutils coreutils cut Local Logic Error and Data Integrity Issue in Output Filtering
НизкаяCVSS 3,3Эксплойта нетEPSS 0 %uutils · coreutils22 апр. 2026 г.