← Back
CWE-358

133 CVEs • Abstraction: Base

Improperly Implemented Security Check for Standard

The product does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique.

JSON object

Loading...

CVEs (133)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Canonical
DebianNlnetlabs
3Debian Linux
Ubuntu LinuxUnbound
Nov 21, 2024
Jan 23, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An improperly validated wildcard NSEC record could be used to prove the non-existence (NXDOMAIN answer) of an existing wildcar...Show more
A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An improperly validated wildcard NSEC record could be used to prove the non-existence (NXDOMAIN answer) of an existing wildcard record, or trick unbound into accepting a NODATA proof.Show less
1Powerdns
1Authoritative
Nov 21, 2024
Jan 23, 2018
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
An issue has been found in the API component of PowerDNS Authoritative 4.x up to and including 4.0.4 and 3.x up to and including 3.4.11, where some operations that have an impact on the state of the server are still allo...Show more
An issue has been found in the API component of PowerDNS Authoritative 4.x up to and including 4.0.4 and 3.x up to and including 3.4.11, where some operations that have an impact on the state of the server are still allowed even though the API has been configured as read-only via the api-readonly keyword. This missing check allows an attacker with valid API credentials to flush the cache, trigger a zone transfer or send a NOTIFY.Show less
1Flexense
1Diskboss
Nov 21, 2024
Jan 10, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 8094.
1Flexense
1Syncbreeze
Nov 21, 2024
Jan 10, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Flexense Sync Breeze Enterprise v10.1.16, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 9121.
1Flexense
1Disk Pulse
Nov 21, 2024
Jan 10, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Flexense Disk Pulse Enterprise v10.1.18, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 9120.
1Flexense
1Vx Search
Nov 21, 2024
Jan 10, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Flexense VX Search Enterprise v10.1.12, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 9123.
1Huawei
1Honor 5s Firmware
May 13, 2026
Nov 22, 2017
N/A· v4
4.6 MEDIUM· v3
4.9 MEDIUM· v2
Huawei Honor 5S smart phones with software the versions before TAG-TL00C01B173 have a Factory Reset Protection (FRP) bypass security vulnerability due to the improper design. An attacker can access factory reset page wit...Show more
Huawei Honor 5S smart phones with software the versions before TAG-TL00C01B173 have a Factory Reset Protection (FRP) bypass security vulnerability due to the improper design. An attacker can access factory reset page without authorization by only dial with special code. The attacker can exploit this vulnerability to restore the phone to factory settings.Show less
1Cisco
1Asyncos
May 13, 2026
Nov 16, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability in the Advanced Malware Protection (AMP) file filtering feature of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to bypass a configured AMP...Show more
A vulnerability in the Advanced Malware Protection (AMP) file filtering feature of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to bypass a configured AMP file filtering rule. The file types affected are zipped or archived file types. The vulnerability is due to incorrect and different file hash values when AMP scans the file. An attacker could exploit this vulnerability by sending a crafted email file attachment through the targeted device. An exploit could allow the attacker to bypass a configured AMP file filter. Cisco Bug IDs: CSCvf52943.Show less
1Schneider Electric
1Modbus Firmware
May 13, 2026
Jun 30, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A Violation of Secure Design Principles issue was discovered in Schneider Electric Modicon Modbus Protocol. The Modicon Modbus protocol has a session-related weakness making it susceptible to brute-force attacks.
1Ibm
1Curam Social Program Management
May 13, 2026
Jun 8, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Curam Universal Access in IBM Curam Social Program Management (SPM) 6.0 SP2 before EP26, 6.0.4 before 6.0.4.6, and 6.0.5 before 6.0.5.5 iFix5 allows remote attackers to obtain sensitive information about internal casewor...Show more
Curam Universal Access in IBM Curam Social Program Management (SPM) 6.0 SP2 before EP26, 6.0.4 before 6.0.4.6, and 6.0.5 before 6.0.5.5 iFix5 allows remote attackers to obtain sensitive information about internal caseworker usernames via vectors related to a URL.Show less
2Google
Linux
2Android
Linux Kernel
May 13, 2026
Apr 4, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checksum calculation during execution of a recv system call with the MSG_PEEK flag.
1Openinfosecfoundation
1Suricata
May 13, 2026
Mar 18, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Suricata before 3.2.1 has an IPv4 defragmentation evasion issue caused by lack of a check for the IP protocol during fragment matching.
1Ibm
4Security Access Manager 9.0 Firmware
Security Access Manager For Mobile 8.0 FirmwareSecurity Access Manager For Web 7.0 Firmware+1 more
May 13, 2026
Feb 1, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Security Access Manager for Web could allow a remote attacker to obtain sensitive information due to security misconfigurations.