CWE-693
Protection Mechanism Failure
Description
The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-1 · CAPEC-107 · CAPEC-127 · CAPEC-17 · CAPEC-20 · CAPEC-22 · CAPEC-237 · CAPEC-36 · CAPEC-477 · CAPEC-480 · CAPEC-51 · CAPEC-57 · CAPEC-59 · CAPEC-65 · CAPEC-668 · CAPEC-74 · CAPEC-87
CVEs mapped to this weakness (896)
page 20 of 45| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-40158 | Hig | 0.49 | 8.6 | 0.00 | Apr 10, 2026 | PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI's AST-based Python sandbox can be bypassed using type.__getattribute__ trampoline, allowing arbitrary code execution when running untrusted agent code. The _execute_code_direct function in… | ||
| CVE-2026-20701 | Hig | 0.49 | 7.5 | 0.00 | Mar 25, 2026 | An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to connect to a network share without user consent. | ||
| CVE-2026-2803 | Hig | 0.49 | 7.5 | 0.00 | Feb 24, 2026 | Information disclosure, mitigation bypass in the Settings UI component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. | ||
| CVE-2025-46290 | Hig | 0.49 | 7.5 | 0.01 | Feb 11, 2026 | A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2, visionOS 26.2, watchOS 26.2. A remote attacker may be able to cause a denial-of-service. | ||
| CVE-2025-43413 | Hig | 0.49 | 7.5 | 0.01 | Nov 4, 2025 | An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A sandboxed app may be able to observe system-wide network… | ||
| CVE-2025-33050 | Hig | 0.49 | 7.5 | 0.02 | Jun 10, 2025 | Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | ||
| CVE-2025-32725 | Hig | 0.49 | 7.5 | 0.02 | Jun 10, 2025 | Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | ||
| CVE-2025-21276 | Hig | 0.49 | 7.5 | 0.02 | Jan 14, 2025 | Windows MapUrlToZone Denial of Service Vulnerability | ||
| CVE-2024-0101 | Hig | 0.49 | 7.5 | 0.01 | Aug 8, 2024 | NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in ipfilter, where improper ipfilter definitions could enable an attacker to cause a failure by attacking the switch. A successful exploit of this vulnerability might lead to denial of service. | ||
| CVE-2024-0804 | Hig | 0.49 | 7.5 | 0.00 | Jan 24, 2024 | Insufficient policy enforcement in iOS Security UI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | ||
| CVE-2023-5557 | Hig | 0.49 | 7.5 | 0.01 | Oct 13, 2023 | A flaw was found in the tracker-miners package. A weakness in the sandbox allows a maliciously-crafted file to execute code outside the sandbox if the tracker-extract process has first been compromised by a separate vulnerability. | ||
| CVE-2023-34984 | Hig | 0.49 | 7.5 | 0.01 | Sep 13, 2023 | A protection mechanism failure in Fortinet FortiWeb 7.2.0 through 7.2.1, 7.0.0 through 7.0.6, 6.4.0 through 6.4.3, 6.3.6 through 6.3.23 allows attacker to execute unauthorized code or commands via specially crafted HTTP requests. | ||
| CVE-2023-35352 | Hig | 0.49 | 7.5 | 0.01 | Jul 11, 2023 | Windows Remote Desktop Security Feature Bypass Vulnerability | ||
| CVE-2022-48287 | Hig | 0.49 | 7.5 | 0.00 | Feb 9, 2023 | The HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect data integrity. | ||
| CVE-2022-46762 | Hig | 0.49 | 7.5 | 0.00 | Jan 6, 2023 | The memory management module has a logic bypass vulnerability.Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-32910 | Hig | 0.49 | 7.5 | 0.01 | Nov 1, 2022 | A logic issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6.8, macOS Monterey 12.5, Security Update 2022-005 Catalina. An archive may be able to bypass Gatekeeper. | ||
| CVE-2022-43429 | Hig | 0.49 | 7.5 | 0.01 | Oct 19, 2022 | Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to read arbitrary files on the Jenkins controller file system. | ||
| CVE-2022-39011 | Hig | 0.49 | 7.5 | 0.00 | Oct 14, 2022 | The HISP module has a vulnerability of bypassing the check of the data transferred in the kernel space.Successful exploitation of this vulnerability may cause unauthorized access to the HISP module. | ||
| CVE-2021-1223 | Hig | 0.49 | 7.5 | 0.02 | Jan 13, 2021 | Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect handling of an HTTP range header. An attacker could… | ||
| CVE-2019-12697 | Hig | 0.49 | 7.5 | 0.01 | Oct 2, 2019 | Multiple vulnerabilities in the Cisco Firepower System Software Detection Engine could allow an unauthenticated, remote attacker to bypass configured Malware and File Policies for RTF and RAR file types. For more information about these vulnerabilities, see the Details section… |
- risk 0.49cvss 8.6epss 0.00
PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI's AST-based Python sandbox can be bypassed using type.__getattribute__ trampoline, allowing arbitrary code execution when running untrusted agent code. The _execute_code_direct function in…
- risk 0.49cvss 7.5epss 0.00
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to connect to a network share without user consent.
- risk 0.49cvss 7.5epss 0.00
Information disclosure, mitigation bypass in the Settings UI component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
- risk 0.49cvss 7.5epss 0.01
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2, visionOS 26.2, watchOS 26.2. A remote attacker may be able to cause a denial-of-service.
- risk 0.49cvss 7.5epss 0.01
An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A sandboxed app may be able to observe system-wide network…
- risk 0.49cvss 7.5epss 0.02
Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
- risk 0.49cvss 7.5epss 0.02
Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
- risk 0.49cvss 7.5epss 0.02
Windows MapUrlToZone Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.01
NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in ipfilter, where improper ipfilter definitions could enable an attacker to cause a failure by attacking the switch. A successful exploit of this vulnerability might lead to denial of service.
- risk 0.49cvss 7.5epss 0.00
Insufficient policy enforcement in iOS Security UI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
- risk 0.49cvss 7.5epss 0.01
A flaw was found in the tracker-miners package. A weakness in the sandbox allows a maliciously-crafted file to execute code outside the sandbox if the tracker-extract process has first been compromised by a separate vulnerability.
- risk 0.49cvss 7.5epss 0.01
A protection mechanism failure in Fortinet FortiWeb 7.2.0 through 7.2.1, 7.0.0 through 7.0.6, 6.4.0 through 6.4.3, 6.3.6 through 6.3.23 allows attacker to execute unauthorized code or commands via specially crafted HTTP requests.
- risk 0.49cvss 7.5epss 0.01
Windows Remote Desktop Security Feature Bypass Vulnerability
- risk 0.49cvss 7.5epss 0.00
The HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect data integrity.
- risk 0.49cvss 7.5epss 0.00
The memory management module has a logic bypass vulnerability.Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.01
A logic issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6.8, macOS Monterey 12.5, Security Update 2022-005 Catalina. An archive may be able to bypass Gatekeeper.
- risk 0.49cvss 7.5epss 0.01
Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to read arbitrary files on the Jenkins controller file system.
- risk 0.49cvss 7.5epss 0.00
The HISP module has a vulnerability of bypassing the check of the data transferred in the kernel space.Successful exploitation of this vulnerability may cause unauthorized access to the HISP module.
- risk 0.49cvss 7.5epss 0.02
Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect handling of an HTTP range header. An attacker could…
- risk 0.49cvss 7.5epss 0.01
Multiple vulnerabilities in the Cisco Firepower System Software Detection Engine could allow an unauthenticated, remote attacker to bypass configured Malware and File Policies for RTF and RAR file types. For more information about these vulnerabilities, see the Details section…