VYPR

CWE-687

Function Call With Incorrectly Specified Argument Value

VariantDraft

Description

The product calls a function, procedure, or routine, but the caller specifies an argument that contains the wrong value, which may lead to resultant weaknesses.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (3)

  • CVE-2024-36985HigJul 1, 2024
    risk 0.61cvss 8.8epss 0.06

    In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10, a low-privileged user that does not hold the admin or power Splunk roles could cause a Remote Code Execution through an external lookup that references the “splunk_archiver“ application.

  • CVE-2024-49603MedDec 9, 2024
    risk 0.28cvss 4.3epss 0.00

    Dell PowerScale OneFS Versions 8.2.2.x through 9.9.0.x contain an incorrect specified argument vulnerability. A remote low privileged legitimate user could potentially exploit this vulnerability, leading to information disclosure.

  • CVE-2025-22620MedJan 20, 2025
    risk 0.26cvss 5.0epss 0.00

    gitoxide is an implementation of git written in Rust. Prior to 0.17.0, gix-worktree-state specifies 0777 permissions when checking out executable files, intending that the umask will restrict them appropriately. But one of the strategies it uses to set permissions is not subject…