CWE-440
44 CVEs • Abstraction: Base
Expected Behavior Violation
A feature, API, or function does not perform according to its specification.
CVEs (44)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An exploitable denial-of-service vulnerability exists in the 802.11w security state handling for hostapd 2.6 connected clients with valid 802.11w sessions. By simulating an incomplete new association, an attacker can tri...Show more |
An exploitable denial-of-service vulnerability exists in the hostapd 2.6, where an attacker could trigger AP to send IAPP location updates for stations, before the required authentication process has completed. This coul...Show more |
When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use an ACL file, and that ACL file is empty, or contains only comments or blank lines, then Mosquitto will treat this as though no ACL file has bee...Show more |
1Siemens 5Scalance X 200 Firmware Scalance X 300 FirmwareScalance Xc 200 Firmware+2 moreJun 17, 2026 Mar 26, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 The monitor barrier of the affected products insufficiently blocks data from being forwarded over the mirror port into the mirrored network. An attacker could use this behavior to transmit malicious packets to systems in...Show more |