← Back
CWE-242

10 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Inherently Dangerous Function

The product calls a function that can never be guaranteed to work safely.

JSON object

Loading...

CVEs (10)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Postgresql
1Postgresql
Jul 24, 2026
May 14, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with...Show more
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.Show less
1Ibm
1Cognos Command Center
Jun 17, 2026
Aug 26, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a local user to execute arbitrary code on the system due to the use of unsafe use of the BinaryFormatter function.
1Trendmicro
1Trend Micro Endpoint Encryption
Jun 17, 2026
Jun 17, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the abi...Show more
A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.Show less
1Ibm
1Cics Tx
Jun 17, 2026
May 8, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1 could allow a local user to execute arbitrary code on the system due to the use of unsafe use of the gets function.
1Ruijienetworks
1Reyee Os
Jun 17, 2026
Dec 6, 2024
9.2 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x uses an inherently dangerous function which could allow an attacker to send a malicious MQTT message resulting in devices executing arbitrary OS commands.
1Adobe
1Coldfusion
Jun 17, 2026
Sep 7, 2023
N/A· v4
7.4 HIGH· v3
N/A· v2
ColdFusion version 2021 update 1 (and earlier) and versions 2018.10 (and earlier) are impacted by an Use of Inherently Dangerous Function vulnerability that can lead to a security feature bypass  . An authenticated attac...Show more
ColdFusion version 2021 update 1 (and earlier) and versions 2018.10 (and earlier) are impacted by an Use of Inherently Dangerous Function vulnerability that can lead to a security feature bypass  . An authenticated attacker could leverage this vulnerability to access and manipulate arbitrary data on the environment. Show less
1Airspan
1Airvelocity 1500 Firmware
Jun 17, 2026
Aug 16, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Airspan AirVelocity 1500 software prior to version 15.18.00.2511 had NET-SNMP-EXTEND-MIB enabled on its snmpd service, enabling an attacker with SNMP write abilities to execute commands as root on the eNodeB. This issue...Show more
Airspan AirVelocity 1500 software prior to version 15.18.00.2511 had NET-SNMP-EXTEND-MIB enabled on its snmpd service, enabling an attacker with SNMP write abilities to execute commands as root on the eNodeB. This issue may affect other AirVelocity and AirSpeed models.Show less
1Azeotech
1Daqfactory
Jun 17, 2026
Nov 5, 2021
N/A· v4
7.8 HIGH· v3
7.5 HIGH· v2
The affected application uses specific functions that could be abused through a crafted project file, which could lead to code execution, system reboot, and system shutdown.
1Redhat
1Modulemd
Nov 21, 2024
Jan 10, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
modulemd 1.3.1 and earlier uses an unsafe function for processing externally provided data, leading to remote code execution.
1Private Address Check Project
1Private Address Check
May 13, 2026
Nov 13, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The private_address_check ruby gem before 0.4.0 is vulnerable to a bypass due to use of Ruby's Resolv.getaddresses method, which is OS-dependent and should not be relied upon for security measures, such as when used to b...Show more
The private_address_check ruby gem before 0.4.0 is vulnerable to a bypass due to use of Ruby's Resolv.getaddresses method, which is OS-dependent and should not be relied upon for security measures, such as when used to blacklist private network addresses to prevent server-side request forgery.Show less