CWE-642 · 18 kayıt
External Control of Critical State Data
Bu sınıftaki CVE’ler
18 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
35İzleyin | CVE-2020-27872İstismar yok | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7450 1.2.0.62_1.0.1 routnetgear · ac2100 firmware · CWE-642 | Yüksek8,8 | — | %0,9 | 4 Şub 2021 |
34İzleyin | CVE-2018-15382İstismar yok | Cisco HyperFlex Software Static Signing Key Vulnerabilitycisco · hyperflex hx data platform · CWE-642 | Yüksek8,6 | — | %1,3 | 5 Eki 2018 |
32İzleyin | CVE-2024-8754İstismar yok | External Control of Critical State Data in GitLabgitlab · gitlab · CWE-642 | Yüksek8,1 | — | %0,4 | 12 Eyl 2024 |
31İzleyin | CVE-2019-9496İstismar yok | An invalid authentication sequence could result in the hostapd process terminating due to missing state validation stepsw1.fi · hostapd · CWE-642 | Yüksek7,5 | — | %4,7 | 17 Nis 2019 |
28İzleyin | CVE-2025-49090İstismar yok | The Matrix specification before 1.16 (i.e., with a room version before 12 and State Resolution before 2.1) has deficient state resolution.matrix · matrix specification · CWE-642 | Yüksek7,1 | — | %0,5 | 2 Eki 2025 |
27İzleyin | CVE-2020-26186İstismar yok | Dell Inspiron 5675 BIOS versions prior to 1.4.1 contain a UEFI BIOS RuntimeServices overwrite vulnerability.dell · inspiron 5675 firmware · CWE-642 | Orta6,8 | — | %0,4 | 8 Oca 2021 |
27İzleyin | CVE-2024-22387İstismar yok | External Control of Critical State Data (CWE-642) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticategallagher · controller 6000 and controller 7000 · CWE-642 | Orta6,8 | — | %0,3 | 10 Tem 2024 |
27İzleyin | CVE-2022-22154İstismar yok | Junos Fusion: A Satellite Device can be controlled by rewiring it to a foreign AD causing a DoSjuniper · junos · CWE-642 | Orta6,8 | — | %0,2 | 18 Oca 2022 |
24İzleyin | CVE-2017-0928İstismar yok | html-janitor node module suffers from an External Control of Critical State Data vulnerability via user-control of the '_sanitized' variabletheguardian · html-janitor · CWE-642 | Orta6,1 | — | %1,0 | 4 Haz 2018 |
22İzleyin | CVE-2020-1976İstismar yok | GlobalProtect on MacOS: Local denial-of-service (DoS) vulnerability.paloaltonetworks · globalprotect · CWE-642 | Orta5,5 | — | %0,3 | 12 Şub 2020 |
21İzleyin | CVE-2022-32859İstismar yok | A logic issue was addressed with improved state management.apple · iphone os · CWE-642 | Orta5,3 | — | %0,6 | 1 Kas 2022 |
21İzleyin | CVE-2025-54566İstismar yok | hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, a related issue to CVE-2024-26327.qemu · qemu · CWE-642 | Orta5,4 | — | %0,2 | 24 Tem 2025 |
18İzleyin | CVE-2025-26787İstismar yok | An error in the SignServer container startup logic was found in Keyfactor SignServer versions prior to 7.2.keyfactor · signserver · CWE-642 | Orta4,7 | — | %0,1 | 22 Ara 2025 |
17İzleyin | CVE-2024-58265İstismar yok | The snow crate before 0.9.5 for Rust, when stateful TransportState is used, allows incrementing a nonce and thereby denying message deliverymcginty · snow · CWE-642 | Orta4,3 | — | %0,4 | 27 Tem 2025 |
17İzleyin | CVE-2026-65355İstismar yok | An information disclosure issue was addressed with improved state management.apple · ipados · CWE-642 | Orta4,3 | — | %0,3 | 14 Eyl 2026 |
17İzleyin | CVE-2026-65352İstismar yok | An information disclosure issue was addressed with improved state management.apple · ipados · CWE-642 | Orta4,3 | — | %0,3 | 14 Eyl 2026 |
17İzleyin | CVE-2026-84518İstismar yok | This issue was addressed through improved state management.apple · safari · CWE-642 | Orta4,3 | — | %0,3 | 14 Eyl 2026 |
12İzleyin | GHSA-97f8-h76h-f297İstismar yok | Duplicate Advisory: Unauthenticated Nonce Increment in snowcrates.io · snow · CWE-642 | Düşük3,1 | — | — | 28 Tem 2025 |
- CVE-2020-2787235İzleyin
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7450 1.2.0.62_1.0.1 rout
YüksekCVSS 8,8İstismar yokEPSS %1netgear · ac2100 firmware4 Şub 2021
- CVE-2018-1538234İzleyin
Cisco HyperFlex Software Static Signing Key Vulnerability
YüksekCVSS 8,6İstismar yokEPSS %1cisco · hyperflex hx data platform5 Eki 2018
- CVE-2024-875432İzleyin
External Control of Critical State Data in GitLab
YüksekCVSS 8,1İstismar yokEPSS %0gitlab · gitlab12 Eyl 2024
- CVE-2019-949631İzleyin
An invalid authentication sequence could result in the hostapd process terminating due to missing state validation steps
YüksekCVSS 7,5İstismar yokEPSS %5w1.fi · hostapd17 Nis 2019
- CVE-2025-4909028İzleyin
The Matrix specification before 1.16 (i.e., with a room version before 12 and State Resolution before 2.1) has deficient state resolution.
YüksekCVSS 7,1İstismar yokEPSS %0matrix · matrix specification2 Eki 2025
- CVE-2020-2618627İzleyin
Dell Inspiron 5675 BIOS versions prior to 1.4.1 contain a UEFI BIOS RuntimeServices overwrite vulnerability.
OrtaCVSS 6,8İstismar yokEPSS %0dell · inspiron 5675 firmware8 Oca 2021
- CVE-2024-2238727İzleyin
External Control of Critical State Data (CWE-642) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticate
OrtaCVSS 6,8İstismar yokEPSS %0gallagher · controller 6000 and controller 700010 Tem 2024
- CVE-2022-2215427İzleyin
Junos Fusion: A Satellite Device can be controlled by rewiring it to a foreign AD causing a DoS
OrtaCVSS 6,8İstismar yokEPSS %0juniper · junos18 Oca 2022
- CVE-2017-092824İzleyin
html-janitor node module suffers from an External Control of Critical State Data vulnerability via user-control of the '_sanitized' variable
OrtaCVSS 6,1İstismar yokEPSS %1theguardian · html-janitor4 Haz 2018
- CVE-2020-197622İzleyin
GlobalProtect on MacOS: Local denial-of-service (DoS) vulnerability.
OrtaCVSS 5,5İstismar yokEPSS %0paloaltonetworks · globalprotect12 Şub 2020
- CVE-2022-3285921İzleyin
A logic issue was addressed with improved state management.
OrtaCVSS 5,3İstismar yokEPSS %1apple · iphone os1 Kas 2022
- CVE-2025-5456621İzleyin
hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, a related issue to CVE-2024-26327.
OrtaCVSS 5,4İstismar yokEPSS %0qemu · qemu24 Tem 2025
- CVE-2025-2678718İzleyin
An error in the SignServer container startup logic was found in Keyfactor SignServer versions prior to 7.2.
OrtaCVSS 4,7İstismar yokEPSS %0keyfactor · signserver22 Ara 2025
- CVE-2024-5826517İzleyin
The snow crate before 0.9.5 for Rust, when stateful TransportState is used, allows incrementing a nonce and thereby denying message delivery
OrtaCVSS 4,3İstismar yokEPSS %0mcginty · snow27 Tem 2025
- CVE-2026-6535517İzleyin
An information disclosure issue was addressed with improved state management.
OrtaCVSS 4,3İstismar yokEPSS %0apple · ipados14 Eyl 2026
- CVE-2026-6535217İzleyin
An information disclosure issue was addressed with improved state management.
OrtaCVSS 4,3İstismar yokEPSS %0apple · ipados14 Eyl 2026
- CVE-2026-8451817İzleyin
This issue was addressed through improved state management.
OrtaCVSS 4,3İstismar yokEPSS %0apple · safari14 Eyl 2026
- GHSA-97f8-h76h-f29712İzleyin
Duplicate Advisory: Unauthenticated Nonce Increment in snow
DüşükCVSS 3,1İstismar yokcrates.io · snow28 Tem 2025