VYPR

CWE-480

Use of Incorrect Operator

BaseDraftLikelihood: Low

Description

The product accidentally uses the wrong operator, which changes the logic in security-relevant ways.

These types of errors are generally the result of a typo by the programmer.

Hierarchy (View 1000)

CVEs mapped to this weakness (9)

  • CVE-2026-15043CriJul 14, 2026
    risk 0.57cvss 9.8epss 0.00

    DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text. DBI::SQL::Nano, DBI's built-in mini-SQL engine, evaluated WHERE predicates incorrectly in some cases. In the non-numeric string branch of the is_matched method, <= was…

  • CVE-2026-43114CriMay 6, 2026
    risk 0.54cvss 9.4epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry New test case fails unexpectedly when avx2 matching functions are used. The test first loads a ranomly generated pipapo set with 'ipv4…

  • CVE-2026-4748HigApr 1, 2026
    risk 0.49cvss 7.5epss 0.00

    A regression in the way hashes were calculated caused rules containing the address range syntax (x.x.x.x - y.y.y.y) that only differ in the address range(s) involved to be silently dropped as duplicates. Only the first of such rules is actually loaded into pf. Ranges expressed…

  • CVE-2021-3116HigJan 11, 2021
    risk 0.42cvss 7.5epss 0.02

    before_upstream_connection in AuthPlugin in http/proxy/auth.py in proxy.py before 2.3.1 accepts incorrect Proxy-Authorization header data because of a boolean confusion (and versus or).

  • CVE-2026-44722MedJul 17, 2026
    risk 0.40cvss 6.2epss 0.00

    pyzipper is a replacement for Python's zipfile that can read and write AES encrypted zip files. Prior to 0.4.0, a Python operator precedence bug in pyzipper/zipfile_aes.py caused the AE-2 format to never be automatically selected during encryption, causing encrypted entries to…

  • CVE-2025-52985MedJul 11, 2025
    risk 0.34cvss 5.3epss 0.00

    A Use of Incorrect Operator vulnerability in the Routing Engine firewall of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to bypass security restrictions. When a firewall filter which is applied to the lo0 or re:mgmt interface references a…

  • CVE-2026-48497MedJun 26, 2026
    risk 0.00cvss 5.9epss 0.00

    Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, in cases where UDP DNS filter is configured with local resolution containing a name with the length of 255 octets or remote resolution for a name…

  • CVE-2024-35190MedMay 17, 2024
    risk 0.00cvss 5.8epss 0.01

    Asterisk is an open source private branch exchange and telephony toolkit. After upgrade to 18.23.0, ALL unauthorized SIP requests are identified as PJSIP Endpoint of local asterisk server. This vulnerability is fixed in 18.23.1, 20.8.1, and 21.3.1.

  • CVE-2022-1947MedMay 31, 2022
    risk 0.00cvss 6.5epss 0.01

    Use of Incorrect Operator in GitHub repository polonel/trudesk prior to 1.2.3.