CWE-670: CWE-670

25
Total CVEs
3
Critical
17
High
7.3
Avg CVSS

Yearly Trend

2026
1
2025
5
2024
9
2023
4
2022
4

Top Affected Vendors

1 Envoyproxy 3
2 Vyperlang 3
3 Linux 2
4 Openzeppelin 1
5 Stellar 1
6 Stargate Bukkit Project 1
7 Ultrajson Project 1
8 F5 1
9 Fedoraproject 1
10 Hcltech 1

All CWE-670 CVEs (25)

CVE-2025-43359
9.8

This CVE describes a UDP socket binding vulnerability in Apple operating systems where a UDP server socket bound to a local interface may unexpectedly...

Sep 15, 2025
CVE-2020-1914
9.8

A logic vulnerability in Facebook Hermes JavaScript engine allows attackers to potentially read out of bounds or execute arbitrary code via crafted Ja...

Oct 8, 2020
CVE-2025-29312
9.1

This vulnerability in ONOS (Open Network Operating System) v2.7.0 allows attackers to trigger unexpected behavior in devices connected to legacy switc...

Mar 24, 2025
CVE-2023-20558
8.8

This vulnerability in AMD's CPM OEM SMM (System Management Mode) firmware allows a privileged attacker to manipulate control flow and tamper with SMM ...

Apr 2, 2023
CVE-2024-52811
8.2

A heap buffer overflow vulnerability in ngtcp2's qlog functionality allows attackers to potentially execute arbitrary code or crash applications when ...

Nov 25, 2024
CVE-2022-29255
8.2

CVE-2022-29255 is a vulnerability in Vyper smart contract language where external contract calls without return values could cause the contract addres...

Jun 9, 2022
CVE-2024-47745
7.8

This Linux kernel vulnerability allows local attackers to bypass SELinux W^X (Write XOR Execute) memory protection policies by using the remap_file_pa...

Oct 21, 2024
CVE-2026-26267
7.5

This vulnerability in soroban-sdk allows attackers to bypass security checks in Soroban smart contracts when trait and inherent functions share the sa...

Feb 19, 2026
CVE-2025-21607
7.5

The Vyper compiler fails to check success flags when using EcRecover and Identity precompiles, allowing attackers to deliberately cause these calls to...

Jan 14, 2025
CVE-2024-53270
7.5

Envoy proxy versions before 1.32.3, 1.31.5, 1.30.9, and 1.29.12 contain a null pointer dereference vulnerability when the http1_server_abort_dispatch ...

Dec 18, 2024
CVE-2024-45807
7.5

Envoy proxy versions using the default oghttp2 HTTP/2 codec contain stream management bugs that can cause crashes. This affects all Envoy 1.31 deploym...

Sep 20, 2024
CVE-2024-45311
7.5

This vulnerability in Quinn's QUIC implementation allows attackers to cause server panics by exploiting improper connection validation. Servers using ...

Sep 2, 2024
CVE-2023-41058
7.5

Parse Server deployments using the beforeFind Cloud Code trigger as a security layer are vulnerable to query manipulation bypass. This allows attacker...

Sep 4, 2023
CVE-2023-30629
7.5

The Vyper compiler generates incorrect bytecode for contracts using raw_call with revert_on_failure=False and max_outsize=0, causing unpredictable boo...

Apr 24, 2023
CVE-2021-43819
7.5

This vulnerability in Stargate-Bukkit Minecraft mod allows minecarts with chests to duplicate items when teleporting through portals, breaking game ec...

Apr 19, 2023
CVE-2022-31116
7.5

UltraJSON versions before 5.4.0 improperly decode JSON strings containing escaped surrogate characters, potentially corrupting data and allowing dicti...

Jul 5, 2022
CVE-2022-26890
7.5

This vulnerability in F5 BIG-IP Advanced WAF, ASM, and APM allows remote attackers to cause denial of service by terminating the bd process. It affect...

May 5, 2022
CVE-2022-21655
7.5

This vulnerability in Envoy proxy causes a segmentation fault when internal redirects select routes configured with direct response or redirect action...

Feb 22, 2022
CVE-2021-37604
7.5

This vulnerability in Microchip MiWi software allows attackers to manipulate frame counters before message authentication, potentially causing denial ...

Aug 5, 2021
CVE-2025-32942
7.2

This vulnerability in SSH Tectia Server allows attackers to intercept and manipulate SSH session traffic between clients and servers. It affects all u...

Oct 2, 2025
CVE-2023-52781
5.5

A Linux kernel vulnerability in the USB subsystem allows an infinite loop condition when processing BOS descriptors. This can lead to denial of servic...

May 21, 2024
CVE-2024-30133
5.3

HCL Traveler for Microsoft Outlook (HTMO) contains a control flow vulnerability where the application fails to properly manage execution flow, potenti...

Nov 12, 2024
CVE-2024-45304
5.3

This vulnerability in Cairo-Contracts for Starknet allows unauthorized ownership transfer after an owner renounces ownership. A pending owner can gain...

Aug 31, 2024
CVE-2024-45298
4.3

Wiki.js versions 2.5.303 and earlier contain an authentication bypass vulnerability where disabled users can regain access by using the password reset...

Sep 18, 2024
CVE-2025-32996
4.0

This vulnerability in http-proxy-middleware allows writeBody to be called twice due to a missing 'else if' statement, potentially causing unexpected b...

Apr 15, 2025

About CWE-670 (CWE-670)

Our database tracks 25 CVEs classified as CWE-670, with 3 rated critical and 17 rated high severity. The average CVSS score for CWE-670 vulnerabilities is 7.3.

External reference: View CWE-670 on MITRE CWE →

Monitor CWE-670 Vulnerabilities

Get alerted when new CWE-670 CVEs affect your infrastructure.

Start Monitoring Free