In enableSystemPackageLPw of Settings.java, there is a possible way to prevent location access from working due to a log
Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the refresh sits in the 10
chetans9 core-php-admin-panel through commit a94a780d6 contains an authentication bypass vulnerability in includes/auth_
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPad
Fleet is open source device management software. Prior to 4.81.0, a denial-of-service vulnerability in Fleet's gRPC Laun
Netty is a network application framework for development of protocol servers and clients. In netty-codec-haproxy prior t
Tenda CP3 V3.0 firmware V31.1.9.91 does not validate the Content-Length header field in RTSP requests (including DESCRIB
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly handle decryption errors and allows encrypted v
Stomper 5e2741e is vulnerable to Denial of Service. When a broker sends data to a client whose TCP connection was alread
Incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 152, Firef
XiangShan (Open-source high-performance RISC-V processor) commit edb1dfaf7d290ae99724594507dc46c2c2125384 (2024-11-28) c
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below
EVerest is an EV charging software stack. Prior to version 2025.10.0, C++ exceptions are not properly handled for and by
Decidim is a participatory democracy framework. In versions from 0.30.0 to before 0.30.4 and from 0.31.0.rc1 to before 0
2N Access Commander application version 3.4.2 and prior returns HTTP 500 Internal Server Error responses when receiving
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the Redis
Any authenticated Velociraptor user — including one holding only the readerrole — can terminate the entire server proces
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is
Improper Check or Handling of Exceptional Conditions vulnerability in Samsung Open Source Escargot allows Input Data Man
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to cause a denial of service via the
The `rsa` crate is an RSA implementation written in rust. Prior to version 0.9.10, when creating a RSA private key from
Certain HP OfficeJet Pro printers may be vulnerable to potential denial of service when the IPP requests are mishandled,
malcontent is software for discovering supply-chain compromises through context, differential analysis, and YARA. Prior
Capgo before 12.128.2 contains a denial of service vulnerability in the /auth/v1/otp endpoint that prevents email verifi
### Summary `qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a t
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 26.3 and i
This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS
This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS
This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS
This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS
This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS
A vulnerability was detected in hunvreus devpush up to 0.4.6. Affected by this issue is the function reset_storage of th
Frequently Asked Questions
What is CWE-703?
CWE-703 (CWE-703) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-703?
There are 34 CVE records associated with CWE-703 in our database. Of these, 0 are critical severity, 12 are high severity, and 21 are medium severity.
How can I protect against CWE-703 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-703 using AI-powered security agents.
Detect CWE-703 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-703 vulnerabilities across your infrastructure.
Get Started