CWE-129 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-129 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 실제 악용이 확인됨CVE-2022-48503The issue was addressed with improved bounds checks. This issue is fixed in tvOS 15.6, watchOS 8.7, …3.2%높음8.8CVE-2026-91101HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The find…1.0%보통5.1CVE-2026-65653github.com/temporalio/tchannel-go did not reject TChannel call fragments containing checksum metadat…0.7%높음8.7CVE-2026-65652github.com/temporalio/tchannel-go did not validate the one-byte checksum-type field in inbound TChan…0.7%높음8.7CVE-2026-84445gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and 1.83.2, servers created with …0.7%높음8.7CVE-2026-61695Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.1 and 7.0…0.6%높음7.5CVE-2026-93592vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and …0.5%높음8.7CVE-2026-55209resdata is software for reading and writing result files from the Eclipse reservoir simulator. Prior…0.4%심각9.8
전체 목록
33건
CVE-2026-93840vLLM before 0.29.0 validates allowed_token_ids against tokenizer length instead of model output logits width i…0.4%보통6.3
CVE-2023-54396PocketMine-MP versions before 4.8.1 fail to validate dye color IDs in banner NBT data during deserialization. …0.4%높음7.1
CVE-2026-93841vLLM through 0.29.0 contains a memory corruption vulnerability in the Triton _bincount_kernel where prompt tok…0.4%보통6.3
CVE-2026-16651temporalio/sqlparser can panic when Parse, ParseStrictDDL, or ParseNext processes a MySQL version comment whos…0.4%높음8.7
CVE-2026-87500Improper validation of array index in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker …0.3%심각9.6
CVE-2026-49838GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to …0.3%보통5.9
CVE-2026-57159PJSIP is a free and open source multimedia communication library written in C. Prior to commit 673b978, a remo…0.3%높음8.4
CVE-2026-102510Integer Overflow, Improper Validation of Array Index, Uncontrolled Recursion and Memory Allocation with Excess…0.3%높음8.7
CVE-2026-102822Russh is a Rust SSH client and server library. Prior to 0.63.1, a connection configured to permit mac=none can…0.3%낮음3.7
CVE-2026-93989vLLM through 0.29.0 fails to properly validate bad_words token indices against the model's generation output w…0.3%낮음2.3
CVE-2026-100654vLLM before 0.29.0 accepts user-controlled stop_token_ids on the OpenAI-compatible POST /v1/completions and PO…0.3%높음7.1
CVE-2026-63635OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant …0.2%보통5.5
CVE-2026-62866Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0…0.2%보통6.2
CVE-2026-102511Improper Verification of Source of a Communication Channel in the ADS discovery of the Go implementation of Ap…0.2%높음8.5
CVE-2026-63420OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant …0.2%보통5.5
CVE-2026-100836Contrast through 1.20.0 contains a panic vulnerability in the transit-engine endpoint's ciphertextContainer.Un…0.1%보통5.3
CVE-2026-85084Out-of-bounds Write and Improper Validation of Array Index vulnerability in Samsung Open Source TizenFX Samsun…0.1%보통6.3
CVE-2026-47507NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a use…0.1%높음7.8
CVE-2026-47533NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an att…0.1%보통6.7
CVE-2026-47525NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an att…0.1%보통6.7
CVE-2026-88052Tesseract is an open source OCR engine. In version 5.5.3 and earlier, UNICHARSET::load_via_fgets in src/ccutil…0.1%높음7.8
CVE-2026-0799In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigne…0.1%높음8.7
CVE-2026-96675alsa-lib through 1.2.16.1 contains a denial of service vulnerability in the multi PCM plugin that fails to val…0.1%보통4.8
CVE-2026-17413IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, …0.1%보통5.1
CVE-2026-20527In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of …미평가
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.