CWE-242Base

Use of Inherently Dangerous Function

Draft in the CWE catalog · 11 CVEs mapped

11
CVEs mapped
7.8
Median CVSS
What it is

The product calls a function that can never be guaranteed to work safely.

Recent examples
7.3cvss
CVE-2026-11980

CVE-2026-11980 - HIGH Severity Vulnerability

IBM Aspera Desktop App 1.0.5 through 1.0.19 can allow arbitrary code execution by loading DLL files at start-up.

HIGHno explanation yet
0%
epss
8.8cvss
CVE-2026-6477

CVE-2026-6477 - HIGH Severity Vulnerability

Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

HIGHno explanation yet
0%
epss
7.8cvss
CVE-2025-1994

IBM Cognos Command Center code execution

IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a local user to execute arbitrary code on the system due to the use of unsafe use of the BinaryFormatter function.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-242
Abstraction
Base
Structure
Simple
Status
Draft
References (4)