CWE-1282
8 CVEs • Abstraction: Base
Assumed-Immutable Data is Stored in Writable Memory
Immutable data, such as a first-stage bootloader, device identifiers, and "write-once" configuration settings are stored in writable memory that can be re-programmed or updated in the field.
CVEs (8)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Bpftpserver 1Bulletproof Ftp Server Mar 31, 2026 Mar 30, 2026 6.8 MEDIUM· v4 7.1 HIGH· v3 N/A· v2 BulletProof FTP Server 2019.0.0.50 contains a denial of service vulnerability in the SMTP configuration interface that allows local attackers to crash the application by supplying an oversized string. Attackers can input...Show more |
Axessh 4.2 contains a denial of service vulnerability in the logging configuration that allows local attackers to crash the application by supplying an excessively long string in the log file name field. Attackers can en...Show more |
1Bpftpserver 1Bulletproof Ftp Server Jun 17, 2026 Mar 22, 2026 6.9 MEDIUM· v4 5.5 MEDIUM· v3 N/A· v2 BulletProof FTP Server 2019.0.0.50 contains a denial of service vulnerability in the DNS Address field that allows local attackers to crash the application by supplying an excessively long string. Attackers can enable th...Show more |
1Bpftpserver 1Bulletproof Ftp Server Jun 17, 2026 Mar 22, 2026 6.9 MEDIUM· v4 5.5 MEDIUM· v3 N/A· v2 BulletProof FTP Server 2019.0.0.50 contains a denial of service vulnerability in the Storage-Path configuration parameter that allows local attackers to crash the application by supplying an excessively long string value...Show more |
RarmaRadio 2.72.3 contains a denial of service vulnerability in the Username field that allows local attackers to crash the application by submitting excessively long input. Attackers can paste a buffer of 5000 bytes int...Show more |
Sandboxie 5.30 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Program Alerts configuration field. Attackers can paste a buff...Show more |
FileOptimizer 14.00.2524 contains a denial of service vulnerability that allows attackers to crash the application by manipulating the FileOptimizer32.ini configuration file. Attackers can overwrite the TempDirectory par...Show more |
1Nokia 2Asik Airscale 474021a.101 Firmware Asik Airscale 474021a.102 FirmwareJun 17, 2026 Jan 6, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 The bootloader in the Nokia ASIK AirScale system module (versions 474021A.101 and 474021A.102) loads public keys for firmware verification signature. If an attacker modifies the flash contents to corrupt the keys, secur...Show more |