CWE-703: CWE-703
Yearly Trend
Top Affected Vendors
All CWE-703 CVEs (39)
A critical vulnerability in Firefox and Thunderbird's WebGPU component allows memory corruption due to incorrect boundary conditions. Attackers can ex...
Nov 11, 2025A critical vulnerability in Firefox and Thunderbird's WebGPU component allows memory corruption due to incorrect boundary conditions. Attackers can ex...
Nov 11, 2025A sandbox escape vulnerability in Firefox and Thunderbird's WebGPU component allows attackers to execute arbitrary code outside browser sandbox restri...
Nov 11, 2025This CVE describes a sandbox escape vulnerability in Firefox and Thunderbird's WebGPU component due to incorrect boundary conditions. Attackers can ex...
Nov 11, 2025CVE-2021-3329 is a critical vulnerability in the Zephyr RTOS Bluetooth HCI Host stack initialization that lacks proper input validation, allowing atta...
Feb 26, 2023CVE-2023-45927 is an arithmetic exception vulnerability in S-Lang 2.3.2's tt_sprintf() function that can lead to denial of service or potentially arbi...
Mar 27, 2024An unauthenticated attacker can send a special HTTP request to crash the service, potentially enabling further unauthenticated commands on standalone ...
Dec 8, 2021CVE-2024-21525 is a buffer overflow vulnerability in the node-twain package where input validation fails to check string length for productName, produ...
Jul 10, 2024The CleanTalk WordPress plugin has a vulnerability that allows unauthenticated attackers to install and activate arbitrary plugins. This can lead to r...
Nov 26, 2024This CVE describes an authentication bypass vulnerability in chetans9 core-php-admin-panel where the authentication validation script sends a redirect...
Feb 3, 2026A denial-of-service vulnerability in Nodemailer allows attackers to crash email-sending applications by sending specially crafted email addresses that...
Dec 18, 2025This vulnerability involves incorrect boundary conditions in the WebAssembly component of Firefox and Thunderbird, potentially allowing memory corrupt...
Nov 11, 2025This vulnerability allows any authenticated user in a BigBlueButton virtual classroom meeting to crash the chat functionality for all participants by ...
Oct 9, 2025Argo CD versions 1.2.0 through 3.2.0-rc1 contain a vulnerability where unauthenticated API requests with malformed Bitbucket Server payloads can crash...
Oct 1, 2025This vulnerability in Snowbridge setups sending data to Google Tag Manager Server Side allows attackers to attach invalid GTM SS preview headers to ev...
Apr 3, 2025A vulnerability in XINJE XL5E-16T and XD5E-24R-E programmable logic controllers allows attackers to crash the PLC by sending specific Modbus messages ...
Jan 15, 2025This vulnerability in MediaTek Wi-Fi drivers allows remote attackers to cause denial of service without authentication or user interaction. It affects...
Sep 2, 2024This vulnerability allows remote unauthenticated attackers to send specially crafted requests to Ivanti Connect Secure and Ivanti Policy Secure gatewa...
Apr 25, 2024This vulnerability allows unauthenticated attackers to remotely crash the PI Message Subsystem in AVEVA PI Server, causing denial-of-service. It affec...
Jan 18, 2024An unauthenticated attacker can send a malformed API request to Bosch BT software products, causing a Denial of Service (DoS) by crashing or disruptin...
Dec 18, 2023A race condition in Asterisk's DTLS-SRTP handshake allows attackers to cause denial of service by preventing new encrypted calls from being establishe...
Dec 14, 2023A memory leak vulnerability in Juniper SRX Series firewalls with SSL Proxy and UTM Web-Filtering enabled causes gradual memory exhaustion when accessi...
Jul 14, 2023A local privilege escalation vulnerability in Palo Alto Networks GlobalProtect app's Connect Before Logon feature allows attackers to gain SYSTEM or r...
Feb 10, 2022A vulnerability in Juniper Networks Junos OS DHCPv6 service allows remote attackers to cause a denial of service by sending malformed DHCPv6 packets. ...
Apr 22, 2021This vulnerability in the Zephyr RTOS SJA1000 CAN controller driver causes a fatal exception when attempting automatic bus-off recovery in interrupt c...
Oct 13, 2023This vulnerability in EVerest EV charging software allows unhandled C++ exceptions in the TbdController loop to cause silent termination of the contro...
Jan 21, 2026This vulnerability allows attackers to crash Bluetooth Low Energy (BLE) peripherals by sending malformed connection requests with illegal parameters. ...
Nov 7, 2025This CVE describes a logic flaw in Safari that could be exploited by malicious web content to cause unexpected crashes. The vulnerability affects Safa...
Jul 30, 2025This CVE describes a logic flaw in macOS and Safari where a download's origin may be incorrectly associated, potentially allowing malicious downloads ...
Jul 30, 2025This vulnerability allows unauthenticated attackers to reset passwords for subscriber accounts in WordPress UltimateAI plugin. Attackers can take over...
Oct 16, 2024This Android vulnerability allows an attacker to set a touchable region beyond its own SurfaceControl due to a logic error in WindowManagerService. Th...
Mar 24, 2023This vulnerability in Android's BitmapExport.java allows attackers to bypass image truncation, potentially causing memory corruption or denial of serv...
Mar 24, 2023This vulnerability in KubeVirt allows attackers to disrupt virtual machine control by creating malicious pods with matching labels. Attackers can caus...
Nov 7, 2025This vulnerability in ywxbear PHP-Bookstore-Website-Example and PHP Basic BookStore Website allows remote attackers to manipulate quantity values in t...
Oct 11, 2025IBM Security Verify Access versions 10.0.0.0 through 10.0.7.1, under certain configurations, are vulnerable to asymmetric resource consumption denial-...
Jun 27, 2024An unauthenticated attacker can send crafted HTTP requests to the FortiOS administrative interface, causing a denial of service (DoS) that disrupts ma...
May 14, 2024This vulnerability affects multiple Siemens SIMATIC RFID reader models where improper SNMP error handling causes application restart when character li...
Sep 10, 2024An attacker with physical access to an iPhone can take and view screenshots of sensitive data during iPhone Mirroring with a Mac. This vulnerability a...
Feb 11, 2026The rsa crate versions before 0.9.10 panic when creating RSA private keys with a prime value of 1 instead of returning an error. This affects Rust app...
Jan 8, 2026About CWE-703 (CWE-703)
Our database tracks 39 CVEs classified as CWE-703, with 7 rated critical and 18 rated high severity. The average CVSS score for CWE-703 vulnerabilities is 7.3.
External reference: View CWE-703 on MITRE CWE →
Monitor CWE-703 Vulnerabilities
Get alerted when new CWE-703 CVEs affect your infrastructure.
Start Monitoring Free