CWE-561
Dead Code
Description
The product contains dead code, which can never be executed.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (9)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-34205 | Cri | 0.64 | 9.8 | 0.01 | Sep 19, 2025 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.843 and Application prior to 20.0.1923 (VA and SaaS deployments) contains dangerous PHP dead code present in multiple Docker-hosted PHP instances. A script named /var/www/app/resetroot.php (found… | ||
| CVE-2024-8300 | Hig | 0.46 | 7.0 | 0.00 | Nov 28, 2024 | Dead Code vulnerability in Mitsubishi Electric GENESIS64 Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3, Mitsubishi Electric Iconics Digital Solutions GENESIS64 Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3, Mitsubishi Electric ICONICS Suite Version 10.97.2,… | ||
| CVE-2018-0039 | Med | 0.42 | 6.5 | 0.01 | Jul 11, 2018 | Juniper Networks Contrail Service Orchestration releases prior to 4.0.0 have Grafana service enabled by default with hardcoded credentials. These credentials allow network based attackers unauthorized access to information stored in Grafana or exploit other weaknesses or… | ||
| CVE-2024-32634 | Med | 0.40 | 6.1 | 0.00 | Apr 16, 2024 | In huge memory get unmapped area check, code can never be reached because of a logical contradiction. | ||
| CVE-2022-33685 | Med | 0.26 | 4.0 | 0.00 | Jul 12, 2022 | Unprotected dynamic receiver in Wearable Manager Service prior to SMR Jul-2022 Release 1 allows attacker to launch arbitray activity and access senstive information. | ||
| CVE-2022-30748 | Med | 0.26 | 4.0 | 0.00 | Jun 7, 2022 | Unprotected dynamic receiver in Samsung Members prior to version 4.2.005 allows attacker to launch arbitrary activity. | ||
| CVE-2022-33726 | Low | 0.21 | 3.3 | 0.00 | Aug 5, 2022 | Unprotected dynamic receiver in Samsung Galaxy Friends prior to SMR Aug-2022 Release 1 allows attacker to launch activity. | ||
| CVE-2021-25398 | Low | 0.21 | 3.3 | 0.00 | Jun 11, 2021 | Intent redirection vulnerability in Bixby Voice prior to version 3.1.12 allows attacker to access contacts. | ||
| CVE-2026-44057 | Low | 0.13 | 3.1 | 0.00 | May 21, 2026 | A dead bounds check in the Spotlight RPC unmarshaller in Netatalk 3.0.0 through 4.4.2 results in an unreachable code path that provides no effective bounds protection, which may allow a remote authenticated attacker to obtain limited information via crafted Spotlight RPC… |
- risk 0.64cvss 9.8epss 0.01
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.843 and Application prior to 20.0.1923 (VA and SaaS deployments) contains dangerous PHP dead code present in multiple Docker-hosted PHP instances. A script named /var/www/app/resetroot.php (found…
- risk 0.46cvss 7.0epss 0.00
Dead Code vulnerability in Mitsubishi Electric GENESIS64 Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3, Mitsubishi Electric Iconics Digital Solutions GENESIS64 Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3, Mitsubishi Electric ICONICS Suite Version 10.97.2,…
- risk 0.42cvss 6.5epss 0.01
Juniper Networks Contrail Service Orchestration releases prior to 4.0.0 have Grafana service enabled by default with hardcoded credentials. These credentials allow network based attackers unauthorized access to information stored in Grafana or exploit other weaknesses or…
- risk 0.40cvss 6.1epss 0.00
In huge memory get unmapped area check, code can never be reached because of a logical contradiction.
- risk 0.26cvss 4.0epss 0.00
Unprotected dynamic receiver in Wearable Manager Service prior to SMR Jul-2022 Release 1 allows attacker to launch arbitray activity and access senstive information.
- risk 0.26cvss 4.0epss 0.00
Unprotected dynamic receiver in Samsung Members prior to version 4.2.005 allows attacker to launch arbitrary activity.
- risk 0.21cvss 3.3epss 0.00
Unprotected dynamic receiver in Samsung Galaxy Friends prior to SMR Aug-2022 Release 1 allows attacker to launch activity.
- risk 0.21cvss 3.3epss 0.00
Intent redirection vulnerability in Bixby Voice prior to version 3.1.12 allows attacker to access contacts.
- risk 0.13cvss 3.1epss 0.00
A dead bounds check in the Spotlight RPC unmarshaller in Netatalk 3.0.0 through 4.4.2 results in an unreachable code path that provides no effective bounds protection, which may allow a remote authenticated attacker to obtain limited information via crafted Spotlight RPC…