CWE-684 · 27 kayıt
Incorrect Provision of Specified Functionality
Bu sınıftaki CVE’ler
27 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2023-24845İstismar yok | A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i802, RUGGEDCOM i802NC,siemens · ruggedcom ros · CWE-684 | Kritik9,8 | — | %0,7 | 8 Ağu 2023 |
39İzleyin | CVE-2026-40685İstismar yok | In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in exim · exim · CWE-684 | Kritik9,8 | — | %0,6 | 30 Nis 2026 |
39İzleyin | CVE-2024-50357İstismar yok | FutureNet NXR series routers provided by Century Systems Co., Ltd.century systems co., ltd. · futurenet nxr-g110 series · CWE-684 | Kritik9,8 | — | %0,6 | 29 Kas 2024 |
37İzleyin | CVE-2026-52735İstismar yok | ZEBRA: Consensus divergence via P2SH sigop undercount in pure-Rust disabled-opcode parserzcashfoundation · zebra · CWE-684 | Kritik9,3 | — | %0,5 | 18 Ağu 2026 |
36İzleyin | CVE-2026-44597İstismar yok | Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload, aka TROVE-2026-011.torproject · tor · CWE-684 | Kritik9,1 | — | %0,6 | 6 May 2026 |
36İzleyin | CVE-2024-6425İstismar yok | Incorrect Provision of Specified Functionality vulnerability in MESbookmesbook · mesbook · CWE-684 | Kritik9,1 | — | %0,5 | 1 Tem 2024 |
32İzleyin | CVE-2025-66384İstismar yok | app/Controller/EventsController.php in MISP before 2.5.24 has invalid logic in checking for uploaded file validity, related to tmp_name.misp · misp · CWE-684 | Yüksek8,2 | — | %0,4 | 28 Kas 2025 |
31İzleyin | CVE-2023-5363İstismar yok | Incorrect cipher key & IV length processingopenssl · openssl · CWE-684 | Yüksek7,5 | — | %3,3 | 25 Eki 2023 |
31İzleyin | CVE-2025-47227Kavram kanıtı | In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), the Administrator password reset mechanism is mishandlescriptcase · scriptcase · CWE-684 | Yüksek7,5 | — | %2,1 | 4 Tem 2025 |
30İzleyin | CVE-2026-40684İstismar yok | In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is presexim · exim · CWE-684 | Yüksek7,5 | — | %0,6 | 30 Nis 2026 |
29İzleyin | CVE-2024-20317İstismar yok | Cisco IOS XR Software Layer 2 Services Denial of Service Vulnerabilitycisco · ios xr · CWE-684 | Yüksek7,4 | — | %0,2 | 11 Eyl 2024 |
26İzleyin | CVE-2023-4258İstismar yok | bt: mesh: vulnerability in provisioning protocol implementation on provisionee sidezephyrproject · zephyr · CWE-684 | Orta6,5 | — | %0,6 | 25 Eyl 2023 |
26İzleyin | CVE-2024-6502İstismar yok | Incorrect Provision of Specified Functionality in GitLabgitlab · gitlab · CWE-684 | Orta6,5 | — | %0,4 | 22 Ağu 2024 |
26İzleyin | CVE-2026-42255İstismar yok | Technitium DNS Server before 15.0 allows DNS traffic amplification via cyclic name server delegation.technitium · dnsserver · CWE-684 | Orta6,5 | — | %0,4 | 26 Nis 2026 |
26İzleyin | CVE-2025-58325İstismar yok | An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2.5 through 7.2.10, 7.0.0fortinet · fortios · CWE-684 | Orta6,7 | — | %0,3 | 14 Eki 2025 |
24İzleyin | CVE-2022-23728İstismar yok | Attacker can reset the device with AT Command in the process of rebooting the device.google · android · CWE-684 | Orta6,1 | — | %0,1 | 21 Oca 2022 |
23İzleyin | CVE-2026-79126İstismar yok | Incorrect provision of specified functionality in Proxy in Google Chrome on on Windows prior to 152.0.7977.65 allowed an adjacent attacker tgoogle · chrome · CWE-684 | Orta5,9 | — | %0,2 | 25 Ağu 2026 |
22İzleyin | CVE-2023-5158İstismar yok | Possible dos from guest to host invringh_kiov_advance in vhost driver at drivers/vhost/vringh.clinux · linux kernel · CWE-684 | Orta5,5 | — | %0,2 | 25 Eyl 2023 |
21İzleyin | CVE-2025-54567İstismar yok | hw/pci/pcie_sriov.c in QEMU through 10.0.3 mishandles the VF Enable bit write mask, a related issue to CVE-2024-26327.qemu · qemu · CWE-684 | Orta5,4 | — | %0,2 | 24 Tem 2025 |
17İzleyin | CVE-2024-5005İstismar yok | Incorrect Provision of Specified Functionality in GitLabgitlab · gitlab · CWE-684 | Orta4,3 | — | %0,4 | 11 Eki 2024 |
17İzleyin | CVE-2024-8974İstismar yok | Incorrect Provision of Specified Functionality in GitLabgitlab · gitlab · CWE-684 | Orta4,3 | — | %0,3 | 26 Eyl 2024 |
14İzleyin | CVE-2020-11054İstismar yok | Incorrect Provision of Specified Functionality in qutebrowserqutebrowser · qutebrowser · CWE-684 | Düşük3,5 | — | %1,5 | 7 May 2020 |
14İzleyin | CVE-2025-54568İstismar yok | Akamai Rate Control alpha before 2025 allows attackers to send requests above the stipulated thresholds because the rate is measured separatakamai · rate control · CWE-684 | Düşük3,7 | — | %0,3 | 25 Tem 2025 |
13İzleyin | CVE-2026-35379İstismar yok | uutils coreutils tr Local Logic Error and Data Integrity Issue in Character Class Handlinguutils · coreutils · CWE-684 | Düşük3,3 | — | %0,2 | 22 Nis 2026 |
13İzleyin | CVE-2026-35381İstismar yok | uutils coreutils cut Local Logic Error and Data Integrity Issue in Output Filteringuutils · coreutils · CWE-684 | Düşük3,3 | — | %0,2 | 22 Nis 2026 |
- CVE-2023-2484539İzleyin
A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i802, RUGGEDCOM i802NC,
KritikCVSS 9,8İstismar yokEPSS %1siemens · ruggedcom ros8 Ağu 2023
- CVE-2026-4068539İzleyin
In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in
KritikCVSS 9,8İstismar yokEPSS %1exim · exim30 Nis 2026
- CVE-2024-5035739İzleyin
FutureNet NXR series routers provided by Century Systems Co., Ltd.
KritikCVSS 9,8İstismar yokEPSS %1century systems co., ltd. · futurenet nxr-g110 series29 Kas 2024
- CVE-2026-5273537İzleyin
ZEBRA: Consensus divergence via P2SH sigop undercount in pure-Rust disabled-opcode parser
KritikCVSS 9,3İstismar yokEPSS %1zcashfoundation · zebra18 Ağu 2026
- CVE-2026-4459736İzleyin
Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload, aka TROVE-2026-011.
KritikCVSS 9,1İstismar yokEPSS %1torproject · tor6 May 2026
- CVE-2024-642536İzleyin
Incorrect Provision of Specified Functionality vulnerability in MESbook
KritikCVSS 9,1İstismar yokEPSS %1mesbook · mesbook1 Tem 2024
- CVE-2025-6638432İzleyin
app/Controller/EventsController.php in MISP before 2.5.24 has invalid logic in checking for uploaded file validity, related to tmp_name.
YüksekCVSS 8,2İstismar yokEPSS %0misp · misp28 Kas 2025
- CVE-2023-536331İzleyin
Incorrect cipher key & IV length processing
YüksekCVSS 7,5İstismar yokEPSS %3openssl · openssl25 Eki 2023
- CVE-2025-4722731İzleyin
In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), the Administrator password reset mechanism is mishandle
YüksekCVSS 7,5Kavram kanıtıEPSS %2scriptcase · scriptcase4 Tem 2025
- CVE-2026-4068430İzleyin
In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is pres
YüksekCVSS 7,5İstismar yokEPSS %1exim · exim30 Nis 2026
- CVE-2024-2031729İzleyin
Cisco IOS XR Software Layer 2 Services Denial of Service Vulnerability
YüksekCVSS 7,4İstismar yokEPSS %0cisco · ios xr11 Eyl 2024
- CVE-2023-425826İzleyin
bt: mesh: vulnerability in provisioning protocol implementation on provisionee side
OrtaCVSS 6,5İstismar yokEPSS %1zephyrproject · zephyr25 Eyl 2023
- CVE-2024-650226İzleyin
Incorrect Provision of Specified Functionality in GitLab
OrtaCVSS 6,5İstismar yokEPSS %0gitlab · gitlab22 Ağu 2024
- CVE-2026-4225526İzleyin
Technitium DNS Server before 15.0 allows DNS traffic amplification via cyclic name server delegation.
OrtaCVSS 6,5İstismar yokEPSS %0technitium · dnsserver26 Nis 2026
- CVE-2025-5832526İzleyin
An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2.5 through 7.2.10, 7.0.0
OrtaCVSS 6,7İstismar yokEPSS %0fortinet · fortios14 Eki 2025
- CVE-2022-2372824İzleyin
Attacker can reset the device with AT Command in the process of rebooting the device.
OrtaCVSS 6,1İstismar yokEPSS %0google · android21 Oca 2022
- CVE-2026-7912623İzleyin
Incorrect provision of specified functionality in Proxy in Google Chrome on on Windows prior to 152.0.7977.65 allowed an adjacent attacker t
OrtaCVSS 5,9İstismar yokEPSS %0google · chrome25 Ağu 2026
- CVE-2023-515822İzleyin
Possible dos from guest to host invringh_kiov_advance in vhost driver at drivers/vhost/vringh.c
OrtaCVSS 5,5İstismar yokEPSS %0linux · linux kernel25 Eyl 2023
- CVE-2025-5456721İzleyin
hw/pci/pcie_sriov.c in QEMU through 10.0.3 mishandles the VF Enable bit write mask, a related issue to CVE-2024-26327.
OrtaCVSS 5,4İstismar yokEPSS %0qemu · qemu24 Tem 2025
- CVE-2024-500517İzleyin
Incorrect Provision of Specified Functionality in GitLab
OrtaCVSS 4,3İstismar yokEPSS %0gitlab · gitlab11 Eki 2024
- CVE-2024-897417İzleyin
Incorrect Provision of Specified Functionality in GitLab
OrtaCVSS 4,3İstismar yokEPSS %0gitlab · gitlab26 Eyl 2024
- CVE-2020-1105414İzleyin
Incorrect Provision of Specified Functionality in qutebrowser
DüşükCVSS 3,5İstismar yokEPSS %2qutebrowser · qutebrowser7 May 2020
- CVE-2025-5456814İzleyin
Akamai Rate Control alpha before 2025 allows attackers to send requests above the stipulated thresholds because the rate is measured separat
DüşükCVSS 3,7İstismar yokEPSS %0akamai · rate control25 Tem 2025
- CVE-2026-3537913İzleyin
uutils coreutils tr Local Logic Error and Data Integrity Issue in Character Class Handling
DüşükCVSS 3,3İstismar yokEPSS %0uutils · coreutils22 Nis 2026
- CVE-2026-3538113İzleyin
uutils coreutils cut Local Logic Error and Data Integrity Issue in Output Filtering
DüşükCVSS 3,3İstismar yokEPSS %0uutils · coreutils22 Nis 2026