Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisa
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird
An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very
Luanti 5 before 5.15.2 sometimes allows unintended access to an insecure environment. If at least one mod is listed as s
The IPv6 Neighbor Discovery handlers in subsys/net/ip/ipv6_nbr.c (handle_ra_input, handle_ns_input, handle_na_input) use
soroban-sdk is a Rust SDK for Soroban contracts. Prior to versions 22.0.10, 23.5.2, and 25.1.1, the `#[contractimpl]` ma
Always-Incorrect Control Flow Implementation vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENE
Nest is a framework for building scalable Node.js server-side applications. In versions 11.1.15 and below, a NestJS appl
A bug in POST request handling causes a crash under a certain condition. This issue affects Apache Traffic Server: from
Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Winch compiler conta
Deadwood in MaraDNS 3.5.0036 allows attackers to exhaust connection slots via a zone whose authoritative nameserver addr
Multiple unauthenticated denial-of-service (DoS) issues in fohrloop dash-uploader v0.1.0 through v0.7.0a2. The chunked-u
Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues o
Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first cond
KDE Kleopatra before 26.08.0 on Windows allows local users to obtain the privileges of a Kleopatra user, because there i
A vulnerability in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco Nexus 3000 Series Switc
Capgo before 12.128.2 allows multiple public channels for the same app and platform to coexist simultaneously, while unn
The guard checker in Rocq Prover treats a parameter of a nested mutual fixpoint as uniform without examining calls betwe
The guard checker in Rocq Prover does not recheck the recursive tree representation of an inductive type parameter after
The guard checker in Rocq Prover does not follow recursive calls made through a fixpoint's own arguments. A fixpoint may
JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 152 and Thunderbird
A vulnerability was detected in lm-sys fastchat up to 0.2.36. Impacted is the function add_text of the component Arena S
Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends
PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, A logic error in the PX4 Autopilot MAVLink F
Cap-go before 12.128.12 contains a broken cursor pagination vulnerability in the /private/devices endpoint on the Cloudf
OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list i
Varnish Cache 9 before 9.0.1 and Varnish Enterprise before 6.0.16r11 allows a "workspace overflow" denial of service (da
Varnish Cache 9 before 9.0.1 allows a "workspace overflow" denial of service (daemon panic) after timeout_linger. A mali
A logic vulnerability was found in GStreamer's webrtcbin component. The _check_sdp_crypto() function contains an inverte
The cut utility in uutils coreutils incorrectly handles the -s (only-delimited) option when a newline character is speci
uuid before 14.0.0 can make unexpected writes when external output buffers are used, and the UUID version is 3, 5, or 6.
OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any ECDSA algorithm in PubkeyAcceptedAlgorithms or H
In uriparser before 1.0.2, the function family EqualsUri can misclassify two unequal URIs as equal.
In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwar
The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Pr
Always-incorrect control flow implementation in some firmware for some Intel(R) Xeon(R) processors may allow an escalati
MintyItanium Lost-Auction is an auction plugin for Minecraft. Prior to commit 88c920b05042929db334ba06d57f052b42d6b3f8,
Frequently Asked Questions
What is CWE-670?
CWE-670 (CWE-670) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-670?
There are 38 CVE records associated with CWE-670 in our database. Of these, 2 are critical severity, 12 are high severity, and 14 are medium severity.
How can I protect against CWE-670 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-670 using AI-powered security agents.
Detect CWE-670 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-670 vulnerabilities across your infrastructure.
Get Started