CWE-687: Function Call With Incorrectly Specified Argument Value
The product calls a function, procedure, or routine, but the caller specifies an argument that contains the wrong value, which may lead to resultant weaknesses.
3 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-36985 — Remote Code Execution (RCE) through an external lookup due to “copybuckets.py“ script in the “splunk_archiver“ application in Splunk Enterprise
- CVE-2025-22620 — gix-worktree-state nonexclusive checkout sets executable files world-writable
- CVE-2024-49603 — Dell PowerScale OneFS Versions 8.2.2.x through 9.9.0.x contain an incorrect specified argument vulnerability. A remote l
Recently published
- CVE-2025-22620 — gix-worktree-state nonexclusive checkout sets executable files world-writable
- CVE-2024-49603 — Dell PowerScale OneFS Versions 8.2.2.x through 9.9.0.x contain an incorrect specified argument vulnerability. A remote l
- CVE-2024-36985 — Remote Code Execution (RCE) through an external lookup due to “copybuckets.py“ script in the “splunk_archiver“ application in Splunk Enterprise
More specific weaknesses
- CWE-560 — Use of umask() with chmod-style Argument