Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-1285

MITRE ↗

CWE-1285

2
CRITICAL
8
HIGH
11
MEDIUM
23 CVEs
9.8
CVE-2025-67268

gpsd before commit dc966aa contains a heap-based out-of-bounds write vulnerability in the drivers/driver_nmea2000.c file

9.1
CVE-2026-33557

A possible security vulnerability has been identified in Apache Kafka. By default, the broker property `sasl.oauthbeare

8.8
CVE-2026-2006

Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted

7.8
CVE-2025-20796

In imgsys, there is a possible out of bounds write due to improper input validation. This could lead to local escalation

7.8
CVE-2026-18485

There is a local privilege escalation vulnerability recently discovered in the NI-PAL kernel driver.  This may allow a l

7.7
CVE-2026-40886

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 3.

7.5
CVE-2026-32285

The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative

7.5
CVE-2026-32286

The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can s

7.5
CVE-2026-44004

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, sandboxed code can call Buffer.alloc() with an arbitrary

7.1
CVE-2026-8036

Improper input validation in NI-PAL may allow a local authenticated user to access arbitrary system memory, potentially

6.7
CVE-2026-20413

In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of

6.7
CVE-2026-20440

In MAE, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr

6.2
CVE-2019-25622

Paint Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by pro

6.2
CVE-2019-25625

Blob Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by prov

5.9
CVE-2025-2399

Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Mitsubishi Electric CNC M800V Seri

5.9
CVE-2026-9100

The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without adequate validation.

5.5
CVE-2019-25593

jetCast Server 2.0 contains a denial of service vulnerability that allows local attackers to crash the application by su

5.5
CVE-2018-25232

Softros LAN Messenger 9.2 contains a denial of service vulnerability that allows local attackers to crash the applicatio

5.5
CVE-2026-14479

A maliciously crafted input, when processed by the Autodesk Installer IPC frame parser, may trigger improper validation

5.3
CVE-2026-43868

Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.

5.3
CVE-2026-45352

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.43.4, negative chunk-size i

CVE-2026-12681

Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Google go-attestation. parseEfiSig

CVE-2026-53530

RaTeX is a KaTeX-compatible math rendering engine written in Rust. Prior to version 0.1.11, the public parser entrypoint

Frequently Asked Questions

What is CWE-1285?

CWE-1285 (CWE-1285) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-1285?

There are 23 CVE records associated with CWE-1285 in our database. Of these, 2 are critical severity, 8 are high severity, and 11 are medium severity.

How can I protect against CWE-1285 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-1285 using AI-powered security agents.

Detect CWE-1285 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-1285 vulnerabilities across your infrastructure.

Get Started