$_SecureScope악용 확인 · 악용 확률 · 한국어 권고
CVE Ledger

CWE-409 관련 취약점

같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.

원장 17,280건이 중 악용 확인 1,734건분류: CWE-409

전체 목록

33건

CVE-2026-46387Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring …0.5%높음7.5
CVE-2026-77620Vector is a high-performance observability data pipeline. From 0.15.0 until 0.57.0, the logstash source feeds …0.5%높음8.7
CVE-2026-77528Autobahn Python is a WebSocket and WAMP implementation for Python that supports Twisted and asyncio. Prior to …0.5%보통5.3
CVE-2026-47321The CompressionFilter class uses ZLib to deflate and inflate data sent and received. When we inflate incoming …0.5%높음7.5
CVE-2026-53659http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.49.0.0, Server…0.4%높음7.5
CVE-2026-82520parsedmarc before 11.0.1 decompresses gzip and ZIP attachments in a single unbounded read with no limit on dec…0.4%높음8.7
CVE-2026-66054Allocation of Resources Without Limits or Throttling, Improper Handling of Highly Compressed Data (Data Amplif…0.4%보통6.9
CVE-2026-94636Improper handling of highly compressed data (data amplification), Function call with incorrectly specified arg…0.4%높음8.2
CVE-2026-94637Improper handling of highly compressed data (data amplification) vulnerability in Apache Thrift Go bindings. T…0.4%높음8.2
CVE-2026-92000adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare …0.4%높음8.7
CVE-2026-77021Improper handling of highly compressed data (data amplification) in Checkmk <2.5.0p14, <2.4.0p37, <2.3.0p51 an…0.4%보통5.3
CVE-2026-44162fluent-plugin-s3 is an Amazon S3 input and output plugin for Fluentd. From 0.7.0 to 1.8.4, the in_s3 input plu…0.4%낮음2.7
CVE-2026-85721The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously …0.4%높음7.5
CVE-2026-67232RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, The…0.4%높음8.2
CVE-2026-86104An uncontrolled resource consumption vulnerability in the Fireware OS login process (wgagent) allows a remote,…0.4%높음8.7
CVE-2026-44163fluent-plugin-opentelemetry is a Fluentd input and output plugin for forwarding OpenTelemetry Protocol data. P…0.3%보통5.3
CVE-2026-85786Improper handling of highly compressed data in Amazon ion-java before 1.12.1 might allow remote attackers to c…0.3%높음8.7
CVE-2026-68911Nicotine+ is a graphical client for the Soulseek peer-to-peer network. Prior to version 3.3.11, a modified rem…0.3%높음8.7
CVE-2026-65827Docmost is open-source collaborative wiki and documentation software. From 0.21.0 until 0.95.0, any authentica…0.3%보통6.5
CVE-2026-90555vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing…0.3%높음7.1
CVE-2026-92573Improper handling of compressed data in the shared GZIP decompressor used for AMQP 0-8/0-9/0-9-1 and AMQP 0-10…0.3%보통6.5
CVE-2026-89321Publishing limits the compressed size of a VSIX (ovsx.publishing.max-content-size, 512 MB by default) but noth…0.3%보통4.3
CVE-2026-5132Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit si…0.2%보통6.5
CVE-2026-15814Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit th…0.2%보통6.5
CVE-2026-79695Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.2%높음7.3
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.