Incorrect Calculation of Buffer Size vulnerability in Apache NimBLE when processing Legacy Advertising Report HCI event.
rsync 3.2.3 before 3.5.0 contains an out-of-bounds write in parse_size_arg() where the return value of snprintf() is use
TwistedBrush Pro Studio 24.06 contains a denial of service vulnerability in the Script Recorder component that allows lo
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, pixel data from adjacent heap
A flaw was found in GIMP. Processing a specially crafted PVR image file with large dimensions can lead to a denial of se
In the Linux kernel, the following vulnerability has been resolved: xfrm: account XFRMA_IF_ID in aevent size calculatio
In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Set DMA segment size to avoid debug warnin
Incorrect calculation of buffer size in Windows VMSwitch allows an authorized attacker to deny service locally.
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 1.0.0 until 4.14.6 an
A security vulnerability has been detected in sonos tract up to 0.23.4. This impacts the function Tensor::from_raw_dt_al
Ruby JSON is a JSON implementation for Ruby. Versions 2.9.0 through 2.19.8 are vulnerable to heap buffer overflow when t
Buffer overflow in ovpn‑dco‑win version 2.8.0 allows local attackers to cause a system crash by sending too large packet
Noir is a Domain Specific Language for SNARK proving systems that is designed to use any ACIR compatible proving system,
Integer overflow to buffer overflow vulnerability in PostScript image handling code used by the PostScript- and PDF-comp
While processing MT Secondary PDP request, Buffer overflow will happen due to incorrect calculation of buffer size in Sn
An improperly performed length calculation on a buffer in PlaintextRecordLayer could lead to an infinite loop and denial
NVIDIA Virtual GPU Manager, all versions, contains a vulnerability in which the provision of an incorrectly sized buffer
rpcapd/daemon.c in libpcap before 1.9.1 mishandles certain length values because of reuse of a variable. This may open u
An integer overflow in curl's URL API results in a buffer overflow in libcurl 7.62.0 to and including 7.64.1.
In writeToParcel and createFromParcel of RttManager.java, there is a permission bypass due to a write size mismatch. Thi
An exploitable arbitrary write vulnerability exists in the open document format parser of the Atlantis Word Processor, v
Godot Engine version All versions prior to 2.1.5, all 3.0 versions prior to 3.0.6. contains a Signed/unsigned comparison
curl before version 7.61.1 is vulnerable to a buffer overrun in the NTLM authentication code. The internal function Curl
An elevation of privilege vulnerability exists in Windows when LDAP request buffer lengths are improperly calculated. In
A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7
An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execu
An elevation of privilege vulnerability in the Qualcomm Secure Channel Manager driver could enable a local malicious app
process_debug_info in dwarf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2
Frequently Asked Questions
What is CWE-131?
CWE-131 (CWE-131) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-131?
There are 99 CVE records associated with CWE-131 in our database. Of these, 11 are critical severity, 44 are high severity, and 21 are medium severity.
How can I protect against CWE-131 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-131 using AI-powered security agents.
Detect CWE-131 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-131 vulnerabilities across your infrastructure.
Get Started