CWE-475 - Undefined Behavior for Input to API
- Abstraction:Base
- Structure:Simple
- Status:Incomplete
- Release Date:2006-07-19
- Latest Modification Date:2023-06-29
Weakness Name
Undefined Behavior for Input to API
Description
The behavior of this function is undefined unless its control parameter is set to a specific value.
Common Consequences
Scope: Other
Impact: Quality Degradation, Varies by Context
Related Weaknesses
New Atlantis AIO platform automates credential stuffing on 140 services
New SparrowDoor Backdoor Variants Found in Attacks on U.S. and Mexican Organizations
Claude is testing ChatGPT-like Deep Research feature Compass
Microsoft fixes printing issues caused by January Windows updates
RedCurl cyberspies create ransomware to encrypt Hyper-V servers
EncryptHub Exploits Windows Zero-Day to Deploy Rhadamanthys and StealC Malware
RedCurl Shifts from Espionage to Ransomware with First-Ever QWCrypt Deployment
Microsoft: Recent Windows updates cause Remote Desktop issues
Malicious npm Package Modifies Local 'ethers' Library to Launch Reverse Shell Attacks
CVE-2025-30154 reviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerability
CVE-2025-1316 Edimax IC-7100 IP Camera OS Command Injection Vulnerability
CVE-2024-48248 NAKIVO Backup and Replication Absolute Path Traversal Vulnerability
CVE-2017-12637 SAP NetWeaver Directory Traversal Vulnerability
CVE-2025-24472 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability
CVE-2025-30066 tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability
CVE-2025-24201 Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability
CVE-2025-21590 Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability
CVE-2025-26633 Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability
CVE-2025-24983 Microsoft Windows Win32k Use-After-Free Vulnerability
InformationalInformation Disclosure - Suspicious Comments
InformationalRe-examine Cache-control Directives
CWE-941 Incorrectly Specified Destination in a Communication Channel
HighCWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-1256 Improper Restriction of Software Interfaces to Hardware Features
CWE-349 Acceptance of Extraneous Untrusted Data With Trusted Data
CWE-551 Incorrect Behavior Order: Authorization Before Parsing and Canonicalization
CWE-579 J2EE Bad Practices: Non-serializable Object Stored in Session