CWE-1282: Assumed-Immutable Data is Stored in Writable Memory
Immutable data, such as a first-stage bootloader, device identifiers, and "write-once" configuration settings are stored in writable memory that can be re-programmed or updated in the field.
8 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2019-25590 — Axessh 4.2 Denial of Service via Log File Name
- CVE-2019-25588 — BulletProof FTP Server 2019.0.0.50 Denial of Service via DNS Address
- CVE-2019-25587 — BulletProof FTP Server 2019.0.0.50 Storage-Path Denial of Service
- CVE-2019-25583 — RarmaRadio 2.72.3 Username Field Denial of Service
- CVE-2019-25551 — Sandboxie 5.30 Denial of Service via Program Alerts Buffer Overflow
- CVE-2018-25229 — BulletProof FTP Server 2019.0.0.50 Denial of Service via SMTP
Recently published
- CVE-2018-25229 — BulletProof FTP Server 2019.0.0.50 Denial of Service via SMTP
- CVE-2019-25590 — Axessh 4.2 Denial of Service via Log File Name
- CVE-2019-25588 — BulletProof FTP Server 2019.0.0.50 Denial of Service via DNS Address
- CVE-2019-25587 — BulletProof FTP Server 2019.0.0.50 Storage-Path Denial of Service
- CVE-2019-25583 — RarmaRadio 2.72.3 Username Field Denial of Service
- CVE-2019-25551 — Sandboxie 5.30 Denial of Service via Program Alerts Buffer Overflow