← Back
CWE-1038

6 CVEs • Abstraction: Class • Likelihood of Exploit: Low

Insecure Automated Optimizations

The product uses a mechanism that automatically optimizes code, e.g. to improve a characteristic such as performance, but the optimizations can have an unintended side effect that might violate an intended security assumption.

JSON object

Loading...

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Discourse
1Discourse
Jun 17, 2026
Jun 9, 2025
8.1 HIGH· v4
9.8 CRITICAL· v3
N/A· v2
Discourse is an open-source discussion platform. Prior to version 3.4.4 of the `stable` branch, version 3.5.0.beta5 of the `beta` branch, and version 3.5.0.beta6-dev of the `tests-passed` branch, Codepen is present in th...Show more
Discourse is an open-source discussion platform. Prior to version 3.4.4 of the `stable` branch, version 3.5.0.beta5 of the `beta` branch, and version 3.5.0.beta6-dev of the `tests-passed` branch, Codepen is present in the default `allowed_iframes` site setting, and it can potentially auto-run arbitrary JS in the iframe scope, which is unintended. This issue is patched in version 3.4.4 of the `stable` branch, version 3.5.0.beta5 of the `beta` branch, and version 3.5.0.beta6-dev of the `tests-passed` branch. As a workaround, the Codepen prefix can be removed from a site's `allowed_iframes`.Show less
-
-
Jun 17, 2026
Mar 8, 2025
N/A· v4
4.9 MEDIUM· v3
N/A· v2
MariaDB Server 10.10 through 10.11.* and 11.0 through 11.4.* crashes in JOIN::fix_all_splittings_in_plan.
-
-
Jun 17, 2026
Mar 8, 2025
N/A· v4
4.9 MEDIUM· v3
N/A· v2
MariaDB Server 10.4 through 10.5.*, 10.6 through 10.6.*, 10.7 through 10.11.*, 11.0 through 11.0.*, and 11.1 through 11.4.* crashes in Item_direct_view_ref::derived_field_transformer_for_where.
-
-
Jun 17, 2026
Mar 8, 2025
N/A· v4
4.9 MEDIUM· v3
N/A· v2
MariaDB Server 10.4 through 10.5.*, 10.6 through 10.6.*, 10.7 through 10.11.*, and 11.0 through 11.0.* can sometimes crash with an empty backtrace log. This may be related to make_aggr_tables_info and optimize_stage2.
1Dell
25Chengming 3900 Firmware
Inspiron 14 Plus 7420 FirmwareInspiron 16 Plus 7620 Firmware+22 more
Jun 17, 2026
Sep 12, 2022
N/A· v4
5.1 MEDIUM· v3
N/A· v2
Dell BIOS versions contain an Unchecked Return Value vulnerability. A local authenticated administrator user could potentially exploit this vulnerability in order to change the state of the system or cause unexpected fai...Show more
Dell BIOS versions contain an Unchecked Return Value vulnerability. A local authenticated administrator user could potentially exploit this vulnerability in order to change the state of the system or cause unexpected failures.Show less
1Dell
399Alienware M15 R6 Firmware
Chengming 3980 FirmwareChengming 3988 Firmware+396 more
Jun 17, 2026
Sep 6, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Dell BIOS versions contain an Insecure Automated Optimization vulnerability. A local authenticated malicious user could exploit this vulnerability by sending malicious input via SMI to obtain arbitrary code execution dur...Show more
Dell BIOS versions contain an Insecure Automated Optimization vulnerability. A local authenticated malicious user could exploit this vulnerability by sending malicious input via SMI to obtain arbitrary code execution during SMM.Show less