CWE-789 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-789 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
CVE-2026-62370KubeEdge is an open source system for extending native containerized application orchestration capab…0.9%보통6.5CVE-2026-53717Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based…0.7%보통6.5CVE-2026-53716Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based…0.7%보통6.5CVE-2026-93019Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 327…0.7%심각9.1CVE-2026-94626vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatib…0.6%높음8.7CVE-2026-82435Description The worker's Netty message decoder is installed ahead of the SASL authentication handler…0.6%심각9.8CVE-2026-58268SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.1, ParserStream.parseSi…0.6%높음7.5CVE-2026-77301adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js. Prior to 0.6.1,…0.6%높음7.5
전체 목록
45건
CVE-2026-20295A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software and Cisco Sec…0.5%높음8.6
CVE-2026-88045rclone is a command-line program to sync files and directories to and from different cloud storage providers. …0.5%높음7.5
CVE-2026-93307A vulnerability has been found in O-RAN-SC SMO OAM 2025-06-10. Affected is an unknown function of the componen…0.5%낮음2.1
CVE-2026-77322SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.3, WSConnection.Read in sip/trans…0.5%높음7.5
CVE-2026-77619Vector is a high-performance observability data pipeline. From 0.15.0 until 0.57.0, the logstash source reads …0.5%높음8.7
CVE-2026-59991psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to 1.17.4, PSDImage.composite(…0.5%높음7.5
CVE-2026-102809PX4 Autopilot through 1.17.0 contains an uncontrolled stack allocation vulnerability in the file2 test command…0.5%높음7.1
CVE-2026-47321The CompressionFilter class uses ZLib to deflate and inflate data sent and received. When we inflate incoming …0.5%높음7.5
CVE-2026-85715ExifReader is a JavaScript Exif information parser. Prior to 4.41.1, ExifReader parses attacker-controlled HEI…0.4%높음7.5
CVE-2026-77410RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.recvContent in channel.go preallocates…0.4%높음8.9
CVE-2026-94633Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability…0.4%높음8.7
CVE-2026-85494Improper handling of length parameter inconsistency, Uncaught exception, Inefficient Algorithmic Complexity, M…0.4%높음8.7
CVE-2026-83745Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability…0.4%높음8.7
CVE-2026-82458Memory allocation with excessive size value, Allocation of resources without limits or throttling vulnerabilit…0.4%높음8.7
CVE-2026-85442MOOS core-moos through 10.4.0 fails to validate packet length declarations in CMOOSCommPkt::OnBytesWritten(), …0.4%높음8.7
CVE-2026-42528A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to c…0.4%보통4.3
CVE-2026-55149Vouch Proxy is an SSO and OAuth/OIDC login solution for Nginx using the auth_request module. Prior to 0.48.0, …0.4%높음7.5
CVE-2026-103603Memory allocation with excessive size value in the HSS/LMS signature code (HssPublicKeyParameters, HssSignatur…0.4%높음8.7
CVE-2026-96260Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to enforce …0.4%보통6.5
CVE-2026-91752GNU libextractor before 1.15 contains a stack-based buffer overflow vulnerability in the process_star_office f…0.4%높음8.7
CVE-2026-102509Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits, and Uncontrolled Recursio…0.4%높음8.7
CVE-2026-102504Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachanne…0.4%높음7.5
CVE-2026-88382hiredis commit 29ea279 (post-v1.5.0) contains an uncontrolled memory allocation vulnerability in its RESP aggr…0.4%높음7.5
CVE-2026-63566Memory allocation with excessive size value in the DTLS handshake reassembly (DtlsReliableHandshake, DtlsReass…0.4%높음8.7
CVE-2026-92550A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to…0.4%높음7.5
CVE-2026-85445MOOS-IvP through 24.8.1 contains a denial of service vulnerability in the Demuxer::addMuxPacket() function tha…0.4%높음8.7
CVE-2026-67211OOM Denial of Service via Unbounded Map Pre-Sizing in Apache OpenNLP SymSpellModelSerializer Versions Affected…0.3%미평가
CVE-2026-102510Integer Overflow, Improper Validation of Array Index, Uncontrolled Recursion and Memory Allocation with Excess…0.3%높음8.7
CVE-2026-63574Memory allocation with excessive size value in the OpenPGP signature and user attribute subpacket parsers (Sig…0.3%높음8.7
CVE-2026-19204A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing J…0.3%높음8.7
CVE-2026-84888A weakness has been identified in RightNow-AI OpenFang up to 0.6.9. This vulnerability affects the function sh…0.3%낮음2.1
CVE-2026-89092The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack overflow when a malicious DNS ser…0.2%보통4.2
CVE-2026-83530A user could provide an expression whose string length is longer than the ParserExpressionSizeLimit() configur…0.2%보통6.9
CVE-2026-102731Memory allocation with excessive size value vulnerability in Apache Directory LDAP API. A malicious peer (or a…0.2%미평가
CVE-2026-102820pageant provides a [PageantStream] type that implements [AsyncRead] and [AsyncWrite] traits and can be used to…0.1%보통6.2
CVE-2026-86776KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the …0.1%보통4.6
CVE-2026-85201In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent does not limit the length declared by a workload in…0.1%보통6.8
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.