A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: Fix IPv6 inner_thoff desync
The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model operat
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115
MediaArea MediaInfoLib LXF element parsing heap-based buffer overflow vulnerability
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a writ
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a writ
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a writ
A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-
lz4_flex is a pure Rust implementation of LZ4 compression/decompression. In versions 0.11.5 and below, and 0.12.0, deco
Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 149, Firef
uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buf
Software installed and run as a non-privileged user may conduct improper GPU system calls to cause OOB read kernel memor
NVIDIA SNAP-4 Container contains a vulnerability in the VIRTIO-BLK component where a malicious guest VM may cause use of
A use of out-of-range pointer offset vulnerability has been reported to affect Qsync Central. If a remote attacker gains
A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below
A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an
Kernel software installed and running inside a Guest/Host VM may post improper commands to the GPU Firmware to trigger a
VB-Audio Voicemeeter, Voicemeeter Banana, and Voicemeeter Potato (versions ending in 1.1.1.9, 2.1.1.9, and 3.1.1.9 and e
Frequently Asked Questions
What is CWE-823?
CWE-823 (CWE-823) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-823?
There are 21 CVE records associated with CWE-823 in our database. Of these, 2 are critical severity, 11 are high severity, and 6 are medium severity.
How can I protect against CWE-823 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-823 using AI-powered security agents.
Detect CWE-823 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-823 vulnerabilities across your infrastructure.
Get Started