An authenticated administrator is able to crash Zabbix server or proxy by creating specifically crafted preprocessing/sc
ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a consensus-valid block containing a long chain of trans
RaTeX is a KaTeX-compatible math rendering engine written in Rust. Prior to version 0.1.11, the public parser entrypoint
Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the server is vulnerable to an unauth
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remo
A vulnerability in the SNMP subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allo
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remo
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remo
Kyverno is a policy engine designed for cloud native platform engineering teams. In versions 1.14.1 and below, a Denial
In network HW, there is a possible system hang due to an uncaught exception. This could lead to remote denial of service
A vulnerability in danny-avila/librechat version git a1647d7 allows an unauthenticated attacker to cause a denial of ser
A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sendi
mintplex-labs/anything-llm version git 6dc3642 contains an unauthenticated Denial of Service (DoS) vulnerability in the
Specifically crafted MongoDB wire protocol messages can cause mongos to crash during command validation. This can occur
Exception capture failure vulnerability in the SVG parsing module of the ArkUI framework Impact: Successful exploitation
Exception capture failure vulnerability in the SVG parsing module of the ArkUI framework Impact: Successful exploitation
In wlan AP driver, there is a possible information disclosure due to an uncaught exception. This could lead to remote (p
In wlan AP driver, there is a possible information disclosure due to an uncaught exception. This could lead to remote (p
A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to
The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executi
Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1
quic-go is an implementation of the QUIC protocol in Go. The loss recovery logic for path probe packets that was added i
Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1
A denial-of-service vulnerability exists in Sysax Multi-Server version 6.10 via its SSH daemon. A specially crafted SSH
A syntax error in the component proxy_tensor.py of pytorch v2.7.0 allows attackers to cause a Denial of Service (DoS).
A Name Error occurs in pytorch v2.7.0 when a PyTorch model consists of torch.cummin and is compiled by Inductor, leading
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. For versions 2.9.0-rc1 through 2.14.19, 3.0.0-
Alloy Core libraries at the root of the Rust Ethereum ecosystem. Prior to 0.8.26 and 1.4.1, an uncaught panic triggered
Protocol manipulation might lead to denial of service.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.
With a specially crafted Python script, an attacker could send continuous startMeasurement commands over an unencrypted
AVEVA PI Data Archive products are vulnerable to an uncaught exception that, if exploited, could allow an authenticated
An unhandled exception in the danny-avila/librechat repository, version git 600d217, can cause the server to crash, lead
Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to client-side Denial of Servise (DoS) attacks. A
The vulnerability allows any authenticated user to cause the PeerTube server to stop functioning in a persistent manner.
Uncaught exception in the core management mechanism for some Intel(R) Processors may allow an authenticated user to pote
vLLM is an inference and serving engine for large language models (LLMs). In versions 0.8.0 up to but excluding 0.9.0, h
vLLM is an inference and serving engine for large language models (LLMs). Version 0.8.0 up to but excluding 0.9.0 have a
AVEVA PI Data Archive products are vulnerable to an uncaught exception that, if exploited, could allow an authenticate
HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.8 and below, the
An attacker who tampers with the C++ CLI client may crash the UpdateService during file transfers, disrupting updates an
Deserialization vulnerability in the IPC module Impact: Successful exploitation of this vulnerability may affect availab
xmlseclibs is a library written in PHP for working with XML Encryption and Signatures. Versions 3.1.3 contain an authent
Part-DB is an open source inventory management system for electronic components. Prior to version 1.17.3, any authentica
IBM EntireX 11.1 could allow a local user to cause a denial of service due to an unhandled error and fault isolation.
Uncaught exception in Microsoft Office allows an unauthorized attacker to deny service locally.
Uncaught Exception (CWE-248) in the Command Centre Server allows an Authorized and Privileged Operator to crash the Comm
Denial of service in DNS-over-QUIC in Technitium DNS Server <= v13.2.2 allows remote attackers to permanently stop the s
IBM Db2 for Linux, UNIX and Windows 12.1.0 and 12.1.1 is vulnerable to a denial of service as the server may crash under
CISA Thorium uses '.unwrap()' to handle errors related to account verification email messages. An unauthenticated remote
In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if
Frequently Asked Questions
What is CWE-248?
CWE-248 (CWE-248) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-248?
There are 271 CVE records associated with CWE-248 in our database. Of these, 3 are critical severity, 125 are high severity, and 112 are medium severity.
How can I protect against CWE-248 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-248 using AI-powered security agents.
Detect CWE-248 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-248 vulnerabilities across your infrastructure.
Get Started