CWE-477Base

Use of Obsolete Function

Draft in the CWE catalog · 16 CVEs mapped

16
CVEs mapped
9.8
Median CVSS
What it is

The code uses deprecated or obsolete functions, which suggests that the code has not been actively reviewed or maintained.

Recent examples
5.3cvss
CVE-2026-1693

Use of vulnerable Resource Owner Password Credentials flow

The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVue, WebScheduler, TouchVue and Snapvue features of PcVue in version 12.0.0 through 16.3.3 included despite being deprecated. It might allow a remote attacker to steal user credentials.

MEDIUMno explanation yet
0%
epss
9.8cvss
CVE-2025-49217

An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected…

🚨 Hold onto your security gear! A dangerously insecure deserialization flaw in Trend Micro Endpoint Encryption PolicyServer can open the door to pre-authentication remote code execution. 🔥 Think of it like a package delivery system that accepts any unverified shipment—if the courier doesn't check what's inside, they might just deliver a ticking time bomb right to your doorstep! If exploited, attackers could execute arbitrary code on your system without even logging in—essentially giving them the keys to the kingdom. This could lead to data breaches, system manipulation, or even a catastrophic loss of sensitive information. It's a nightmare scenario for any organization!

CRITICAL
1%
epss
9.8cvss
CVE-2025-49216

An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to access key methods as an admin user and…

🚨 An unauthorized user can step right into admin territory with just a few tweaks! This critical authentication bypass in Trend Micro Endpoint Encryption PolicyServer is like giving someone a spare key to your server without realizing it. 🔥 Imagine if your hotel’s front desk accidentally handed out master keys to anyone who asks — every room, every safe, completely unlocked. That’s what this vulnerability does for attackers: they can access key methods and alter configurations at will! An attacker could easily exploit this flaw to gain admin access, allowing them to modify crucial product settings and potentially compromise the entire security framework. The implications are absolutely devastating, as it opens the door for unauthorized control over valuable data and resources!

CRITICAL
1%
epss
The record
Technical detail
CWE ID
CWE-477
Abstraction
Base
Structure
Simple
Status
Draft
References (2)