iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.
An Unchecked Return Value vulnerability in the DNS module of Juniper Networks Junos OS on SRX Series allows an unauthent
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
sigstore-ruby is a pure Ruby implementation of the sigstore verify command from the sigstore/cosign project. Prior to 0.
nimiq-primitives contains primitives (e.g., block, account, transaction) to be used in Nimiq's Rust implementation. Prio
When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the
nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In versions 1.3.0 and below, a malic
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.4, 18.7 before 18.7.2, and 1
A potential vulnerability was reported in the BIOS of L13 Gen 6, L13 Gen 6 2-in-1, L14 Gen 6, and L16 Gen 2 ThinkPads wh
Kirby CMS through 5.1.4 allows an authenticated user with 'Editor' permissions to cause a persistent Denial of Service (
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, progressive_decompress_tile_up
tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails. The return value of re
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
In the Linux kernel, the following vulnerability has been resolved: ASoC: SDCA: Add allocation failure check for Entity
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus a
Nokogiri versions before 1.19.1 fail to check the return value from xmlC14NExecute in the canonicalize method, returning
MyBB is free and open source forum software. Prior to 1.8.40, the User CP Buddy/Ignore List component does not validate
ImageMagick before 7.1.2-26 contains a heap use-after-free vulnerability caused by missing null check when parsing XMP p
HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAPro
The dd utility in uutils coreutils suppresses errors during file truncation operations by unconditionally calling Result
Unchecked return value for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applic
An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to read or modify
An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to write to an arbi
When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly h
Unchecked Return Value vulnerability in ash-project ash_postgres allows a user who can drive a tenant rename to a name t
Frequently Asked Questions
What is CWE-252?
CWE-252 (CWE-252) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-252?
There are 34 CVE records associated with CWE-252 in our database. Of these, 0 are critical severity, 12 are high severity, and 14 are medium severity.
How can I protect against CWE-252 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-252 using AI-powered security agents.
Detect CWE-252 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-252 vulnerabilities across your infrastructure.
Get Started