phonenumber is a library for parsing, formatting and validating international phone numbers. Prior to versions `0.3.3+8.
blurhash-rs is a pure Rust implementation of Blurhash, software for encoding images into ASCII strings that can be turne
A vulnerability in ICMPv6 processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defe
Motorola EBTS/MBTS Site Controller drops to debug prompt on unhandled exception. The Motorola MBTS Site Controller expos
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prio
Uncaught Exception in GitHub repository thorsten/phpmyfaq prior to 3.1.11.
NLnet Labs Krill supports direct access to the RRDP repository content through its built-in web server at the "/rrdp" en
Uncaught Exception in GitHub repository eemeli/yaml prior to 2.0.0-5.
Unchecked parameter value in M-Files Server in versions before 23.6.12695.3 (excluding 23.2 SR2 and newer) allows anonym
Vulnerability of failures to capture exceptions in the communication framework. Successful exploitation of this vulnerab
Sails is a realtime MVC Framework for Node.js. In Sails apps prior to version 1.5.7,, an attacker can send a virtual req
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prio
Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux
quic-go is an implementation of the QUIC protocol in Go. Starting in version 0.37.0 and prior to version 0.37.3, by seri
Uncaught exception for some Intel Unison software may allow an authenticated user to potentially enable escalation of pr
In thermal, there is a possible memory corruption due to an uncaught exception. This could lead to local escalation of p
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, an improperly-formatted ‘INGEST_EVAL’ parameter in a Fiel
Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Soc
NVIDIA Cumulus Linux contains a vulnerability in neighmgrd and nlmanager where an attacker on an adjacent network may ca
Uncaught exception for some Intel Unison software may allow an authenticated user to potentially enable denial of servic
A denial of service vulnerability exists in all Silicon Labs Z-Wave controller and endpoint devices running Z-Wave SDK v
In PreferencesHelper.java, an uncaught exception may cause the device to get stuck in a boot loop. This could lead to lo
Mercurius is a GraphQL adapter for Fastify. Any users of Mercurius until version 10.5.0 are subjected to a denial of ser
OpenDDS is an open source C++ implementation of the Object Management Group (OMG) Data Distribution Service (DDS). OpenD
rs-stellar-strkey is a Rust lib for encode/decode of Stellar Strkeys. A panic vulnerability occurs when a specially craf
An unhandled error in Vault Enterprise's namespace creation may cause the Vault process to crash, potentially resulting
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible t
A vulnerability in the processing of malformed Common Industrial Protocol (CIP) packets that are sent to Cisco IOS Softw
An exception is thrown from a function in AVEVA System Platform versions 2017 through 2020 R2 P01, but it is not caught,
Podium is a library for building micro frontends. @podium/layout is a module for building a Podium layout server, and @p
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.
@fastify/websocket provides WebSocket support for Fastify. Any application using @fastify/websocket could crash if a spe
In F-Secure Endpoint Protection for Windows and macOS before channel with Capricorn database 2022-11-22_07, the aerdl.dl
A vulnerability in the integrated wireless access point (AP) packet processing of the Cisco 1000 Series Connected Grid R
Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Soc
Waitress is a Web Server Gateway Interface server for Python 2 and 3. Waitress versions 2.1.0 and 2.1.1 may terminate ea
There is a sleep-in-atomic bug in /net/nfc/netlink.c that allows an attacker to crash the Linux kernel by simulating a n
A vulnerability in the TCP/IP stack of Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cis
Next.js is a React framework that can provide building blocks to create web applications. All of the following must be t
A vulnerability was found in keylime. This security issue happens in some circumstances, due to some improperly handled
jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML
Akaunting version 2.1.12 and earlier suffers from a denial-of-service issue that is triggered by setting a malformed 'lo
A denial-of-service (DoS) vulnerability in Palo Alto Networks GlobalProtect app on Windows systems allows a limited Wind
In Camaleon CMS, versions 2.0.1 to 2.6.0 are vulnerable to an Uncaught Exception. The app's media upload feature crashes
Nextcloud Android app is the Android client for Nextcloud. In versions prior to 3.15.1, a malicious application on the s
Visual Components (owned by KUKA) is a robotic simulator that allows simulating factories and robots in order toimprove
A vulnerability in the SonicWall SMA1000 HTTP Extraweb server allows an unauthenticated remote attacker to cause HTTP se
In OSIsoft PI System multiple products and versions, a remote, unauthenticated attacker could crash PI Network Manager s
Valve's Game Networking Sockets prior to version v1.2.0 improperly handles inlined statistics messages in function CConn
A vulnerability has been identified in SIMATIC ET 200SP Open Controller (incl. SIPLUS variants) (V20.8), SIMATIC S7-1500
Frequently Asked Questions
What is CWE-248?
CWE-248 (CWE-248) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-248?
There are 271 CVE records associated with CWE-248 in our database. Of these, 3 are critical severity, 125 are high severity, and 112 are medium severity.
How can I protect against CWE-248 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-248 using AI-powered security agents.
Detect CWE-248 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-248 vulnerabilities across your infrastructure.
Get Started