SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

50 results for “cwe-189” · 0.69 s · cached

Facets · 3 entity types

33 CVE13 CWE4 CAPEC
CAPEC-121CAPEC

Exploit Non-Production Interfaces

Metadata: standard CAPEC pattern, status stable, likelihood low, severity high. Underlying weaknesses: CWE-489, CWE-1209, CWE-1259, CWE-1267, CWE-1270 (and 5 more). Related CAPEC pattern: [object Obj…

Standard
Match for cwe-189
CVE-2025-8189CVE

CVE-2025-8189

A vulnerability classified as critical was found in Campcodes Courier Management System 1.0. This vulnerability affects unknown code of the file /edit_user.php. The manipulation of the argument ID le…

CVSS 8.8EPSS 0.4%
Match for cwe-189
CVE-2025-9185CVE

CVE-2025-9185

Memory safety bugs present in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of these bugs showed evid…

CVSS 8.1EPSS 0.5%mozilla
Match for cwe-189
CVE-2025-56089CVE

CVE-2025-56089

OS Command Injection vulnerability in Ruijie M18 EW_3.0(1)B11P226_M18_10223116 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev…

CVSS 8.8EPSS 2.8%
Match for cwe-189
CVE-2025-15189CVE

CVE-2025-15189

A vulnerability was identified in D-Link DWR-M920 up to 1.1.50. This issue affects the function sub_464794 of the file /boafrm/formDefRoute. The manipulation of the argument submit-url leads to buffe…

CVSS 8.8EPSS 0.8%dlink
Match for cwe-189
CVE-2026-9119CVE

CVE-2026-9119

Heap buffer overflow in WebRTC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: H…

CVSS 8.8EPSS 0.5%google
Match for cwe-189
CAPEC-680CAPEC

Exploitation of Improperly Controlled Registers

Metadata: detailed CAPEC pattern, status draft, likelihood medium, severity high. Underlying weaknesses: CWE-1224, CWE-1231, CWE-1233, CWE-1262, CWE-1283. Related CAPEC patterns: [object Object], [ob…

Detailed
Match for cwe-189
CVE-2026-11196CVE

CVE-2026-11196

Type Confusion in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted XML file. (Chromium security seve…

CVSS 6.5EPSS 0.2%google
Match for cwe-189
CVE-2026-10989CVE

CVE-2026-10989

Inappropriate implementation in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via …

CVSS 8.8EPSS 0.3%google
Match for cwe-189
CVE-2026-8509CVE

CVE-2026-8509

Heap buffer overflow in WebML in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Criti…

CVSS 8.8EPSS 0.5%
Match for cwe-189
CVE-2026-8531CVE

CVE-2026-8531

Heap buffer overflow in WebML in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity…

CVSS 8.8EPSS 0.3%
Match for cwe-189
CVE-2026-11187CVE

CVE-2026-11187

Inappropriate implementation in Glic in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVSS 6.3EPSS 0.2%google
Match for cwe-189
CVE-2025-9187CVE

CVE-2025-9187

Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited t…

CVSS 9.8EPSS 0.5%mozilla
Match for cwe-189
CVE-2025-55055CVE

CVE-2025-55055

CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CVSS 9.8EPSS 0.8%
Match for cwe-189
CVE-2026-11787CVE

CVE-2026-11787

A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a heap buffer over-read in string filter parsing that …

CVSS 5.0EPSS 0.2%redhat
Match for cwe-189
CVE-2025-3589CVE

CVE-2025-3589

A vulnerability, which was classified as critical, was found in SourceCodester Music Class Enrollment System 1.0. Affected is an unknown function of the file /manage_class.php. The manipulation of th…

CVSS 9.8EPSS 0.6%
Match for cwe-189
CVE-2026-41088CVE

CVE-2026-41088

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVSS 7.8EPSS 0.4%microsoft
Match for cwe-189
CVE-2026-11180CVE

CVE-2026-11180

Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVSS 6.5EPSS 0.2%google
Match for cwe-189
CVE-2026-11299CVE

CVE-2026-11299

Integer overflow in Fonts in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security…

CVSS 6.5EPSS 0.2%google
Match for cwe-189
CVE-2025-15089CVE

CVE-2025-15089

A vulnerability has been found in UTT 进取 512W up to 1.7.7-171114. This affects the function strcpy of the file /goform/APSecurity. The manipulation of the argument wepkey1 leads to buffer overflow. T…

CVSS 9.8EPSS 0.8%
Match for cwe-189
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.