CWE-242— Use of Inherently Dangerous Function
The product calls a function that can never be guaranteed to work safely.— MITRE CWE catalog
11 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-242page 1 of 1
- CVE-2017-0904HIGHCVSS 8.1EG 8.12017-11-13
The private_address_check ruby gem before 0.4.0 is vulnerable to a bypass due to use of Ruby's Resolv.getaddresses method, which is OS-dependent and should not be relied upon for security measures, such as when used to blacklist private ne…
- CVE-2017-1002157CRITICALCVSS 9.8EG 9.82019-01-10
modulemd 1.3.1 and earlier uses an unsafe function for processing externally provided data, leading to remote code execution.
- CVE-2021-40698HIGHCVSS 7.4EG 7.42023-09-07
ColdFusion version 2021 update 1 (and earlier) and versions 2018.10 (and earlier) are impacted by an Use of Inherently Dangerous Function vulnerability that can lead to a security feature bypass . An authenticated attacker could lever…
- CVE-2021-42543HIGHCVSS 7.8EG 7.82021-11-05
The affected application uses specific functions that could be abused through a crafted project file, which could lead to code execution, system reboot, and system shutdown.
- CVE-2022-36310HIGHCVSS 8.8EG 8.82022-08-16
Airspan AirVelocity 1500 software prior to version 15.18.00.2511 had NET-SNMP-EXTEND-MIB enabled on its snmpd service, enabling an attacker with SNMP write abilities to execute commands as root on the eNodeB. This issue may affect other Ai…
- CVE-2024-52324CRITICALCVSS 9.8EG 9.82024-12-06
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x uses an inherently dangerous function which could allow an attacker to send a malicious MQTT message resulting in devices executing arbitrary OS commands.
- CVE-2025-1331HIGHCVSS 7.8EG 7.82025-05-08
IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1 could allow a local user to execute arbitrary code on the system due to the use of unsafe use of the gets function.
- CVE-2025-1994HIGHCVSS 7.8EG 7.82025-08-26
IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a local user to execute arbitrary code on the system due to the use of unsafe use of the BinaryFormatter function.
- CVE-2025-49215HIGHCVSS 8.8EG 8.82025-06-17
A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low…
- CVE-2026-11980HIGHCVSS 7.3EG 7.32026-07-30
IBM Aspera Desktop App 1.0.5 through 1.0.19 can allow arbitrary code execution by loading DLL files at start-up.
- CVE-2026-6477HIGHCVSS 8.8EG 8.82026-05-14
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-lar…
Map vulnerabilities like CWE-242 to your infrastructure
EchelonGraph correlates every CVE — across CWE-242 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →