Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-197

MITRE ↗

CWE-197

14
HIGH
12
MEDIUM
1
LOW
30 CVEs
7.8
CVE-2026-40404

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

7.8
CVE-2026-40409

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

7.8
CVE-2026-44823

Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-49792

Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.

7.8
CVE-2026-50332

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50357

Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.

7.8
CVE-2026-56650

Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-62698

Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-62739

Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-63525

Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-68804

Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.5
CVE-2026-42944

NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in heap overflow when enco

7.5
CVE-2026-6679

A heap buffer overflow could occur in the DTLS 1.3 ACK serialization path before the connecting peer is authenticated. T

7.5
CVE-2026-73523

COVESA Open1722 through 0.9.2 contains an integer truncation vulnerability in acf-can-listener.c that allows unauthentic

6.7
CVE-2026-62769

Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

6.7
CVE-2026-62881

Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

6.7
CVE-2026-62883

Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

6.7
CVE-2026-65795

Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.

6.7
CVE-2026-65797

Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

6.7
CVE-2026-65798

Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

6.5
CVE-2026-32240

Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, when using Transfer-Encoding:

6.2
CVE-2026-40380

Heap-based buffer overflow in Volume Manager Extension Driver allows an authorized attacker to execute code with a physi

5.5
CVE-2026-55142

Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

5.3
CVE-2026-77014

A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-head

5.1
CVE-2026-42371

uriparser before 1.0.1 has numeric truncation in text range comparison, if an application accepts URIs with a length in

4.0
CVE-2026-80213

An issue was discovered in the resolv gem before 0.7.2 for Ruby. Resolv::DNS::MessageEncoder wrote a DNS label's length

2.9
CVE-2026-44927

In uriparser before 1.0.2, there is pointer difference truncation to int in various places.

CVE-2026-6039

LibreOffice can import drawings in the DXF format used by CAD software. A heap buffer overflow existed when importing a

CVE-2026-49263

Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's WebAssembly backend accepts attacker-cont

CVE-2026-65610

nnn stores homelen variable as uchar_t, which can only represent values in the range 0-255. An attacker who can influenc

Frequently Asked Questions

What is CWE-197?

CWE-197 (CWE-197) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-197?

There are 30 CVE records associated with CWE-197 in our database. Of these, 0 are critical severity, 14 are high severity, and 12 are medium severity.

How can I protect against CWE-197 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-197 using AI-powered security agents.

Detect CWE-197 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-197 vulnerabilities across your infrastructure.

Get Started