İçeriğe atla
Noroxi

CWE-642 · 18 kayıt

External Control of Critical State Data

Bu sınıftaki CVE’ler

18 kayıt

  • CVE-2020-27872
    35İzleyin

    This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7450 1.2.0.62_1.0.1 rout

    YüksekCVSS 8,8İstismar yokEPSS %1

    netgear · ac2100 firmware4 Şub 2021

  • CVE-2018-15382
    34İzleyin

    Cisco HyperFlex Software Static Signing Key Vulnerability

    YüksekCVSS 8,6İstismar yokEPSS %1

    cisco · hyperflex hx data platform5 Eki 2018

  • CVE-2024-8754
    32İzleyin

    External Control of Critical State Data in GitLab

    YüksekCVSS 8,1İstismar yokEPSS %0

    gitlab · gitlab12 Eyl 2024

  • CVE-2019-9496
    31İzleyin

    An invalid authentication sequence could result in the hostapd process terminating due to missing state validation steps

    YüksekCVSS 7,5İstismar yokEPSS %5

    w1.fi · hostapd17 Nis 2019

  • CVE-2025-49090
    28İzleyin

    The Matrix specification before 1.16 (i.e., with a room version before 12 and State Resolution before 2.1) has deficient state resolution.

    YüksekCVSS 7,1İstismar yokEPSS %0

    matrix · matrix specification2 Eki 2025

  • CVE-2020-26186
    27İzleyin

    Dell Inspiron 5675 BIOS versions prior to 1.4.1 contain a UEFI BIOS RuntimeServices overwrite vulnerability.

    OrtaCVSS 6,8İstismar yokEPSS %0

    dell · inspiron 5675 firmware8 Oca 2021

  • CVE-2024-22387
    27İzleyin

    External Control of Critical State Data (CWE-642) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticate

    OrtaCVSS 6,8İstismar yokEPSS %0

    gallagher · controller 6000 and controller 700010 Tem 2024

  • CVE-2022-22154
    27İzleyin

    Junos Fusion: A Satellite Device can be controlled by rewiring it to a foreign AD causing a DoS

    OrtaCVSS 6,8İstismar yokEPSS %0

    juniper · junos18 Oca 2022

  • CVE-2017-0928
    24İzleyin

    html-janitor node module suffers from an External Control of Critical State Data vulnerability via user-control of the '_sanitized' variable

    OrtaCVSS 6,1İstismar yokEPSS %1

    theguardian · html-janitor4 Haz 2018

  • CVE-2020-1976
    22İzleyin

    GlobalProtect on MacOS: Local denial-of-service (DoS) vulnerability.

    OrtaCVSS 5,5İstismar yokEPSS %0

    paloaltonetworks · globalprotect12 Şub 2020

  • CVE-2022-32859
    21İzleyin

    A logic issue was addressed with improved state management.

    OrtaCVSS 5,3İstismar yokEPSS %1

    apple · iphone os1 Kas 2022

  • CVE-2025-54566
    21İzleyin

    hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, a related issue to CVE-2024-26327.

    OrtaCVSS 5,4İstismar yokEPSS %0

    qemu · qemu24 Tem 2025

  • CVE-2025-26787
    18İzleyin

    An error in the SignServer container startup logic was found in Keyfactor SignServer versions prior to 7.2.

    OrtaCVSS 4,7İstismar yokEPSS %0

    keyfactor · signserver22 Ara 2025

  • CVE-2024-58265
    17İzleyin

    The snow crate before 0.9.5 for Rust, when stateful TransportState is used, allows incrementing a nonce and thereby denying message delivery

    OrtaCVSS 4,3İstismar yokEPSS %0

    mcginty · snow27 Tem 2025

  • CVE-2026-65355
    17İzleyin

    An information disclosure issue was addressed with improved state management.

    OrtaCVSS 4,3İstismar yokEPSS %0

    apple · ipados14 Eyl 2026

  • CVE-2026-65352
    17İzleyin

    An information disclosure issue was addressed with improved state management.

    OrtaCVSS 4,3İstismar yokEPSS %0

    apple · ipados14 Eyl 2026

  • CVE-2026-84518
    17İzleyin

    This issue was addressed through improved state management.

    OrtaCVSS 4,3İstismar yokEPSS %0

    apple · safari14 Eyl 2026

  • Duplicate Advisory: Unauthenticated Nonce Increment in snow

    DüşükCVSS 3,1İstismar yok

    crates.io · snow28 Tem 2025

Tüm zafiyet sınıfları