gpsd before commit dc966aa contains a heap-based out-of-bounds write vulnerability in the drivers/driver_nmea2000.c file
A possible security vulnerability has been identified in Apache Kafka. By default, the broker property `sasl.oauthbeare
Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted
In imgsys, there is a possible out of bounds write due to improper input validation. This could lead to local escalation
There is a local privilege escalation vulnerability recently discovered in the NI-PAL kernel driver. This may allow a l
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 3.
The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative
The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can s
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, sandboxed code can call Buffer.alloc() with an arbitrary
Improper input validation in NI-PAL may allow a local authenticated user to access arbitrary system memory, potentially
In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of
In MAE, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr
Paint Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by pro
Blob Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by prov
Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Mitsubishi Electric CNC M800V Seri
The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without adequate validation.
jetCast Server 2.0 contains a denial of service vulnerability that allows local attackers to crash the application by su
Softros LAN Messenger 9.2 contains a denial of service vulnerability that allows local attackers to crash the applicatio
A maliciously crafted input, when processed by the Autodesk Installer IPC frame parser, may trigger improper validation
Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.43.4, negative chunk-size i
Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Google go-attestation. parseEfiSig
RaTeX is a KaTeX-compatible math rendering engine written in Rust. Prior to version 0.1.11, the public parser entrypoint
Frequently Asked Questions
What is CWE-1285?
CWE-1285 (CWE-1285) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-1285?
There are 23 CVE records associated with CWE-1285 in our database. Of these, 2 are critical severity, 8 are high severity, and 11 are medium severity.
How can I protect against CWE-1285 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-1285 using AI-powered security agents.
Detect CWE-1285 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-1285 vulnerabilities across your infrastructure.
Get Started