VYPR

CWE-617

Reachable Assertion

BaseDraft

Description

The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (812)

page 18 of 41
  • CVE-2024-50615MedOct 27, 2024
    risk 0.42cvss 6.5epss 0.00

    TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/digit, that may lead to application exit, in tinyxml2.cpp XMLUtil::GetCharacterRef.

  • CVE-2024-50614MedOct 27, 2024
    risk 0.42cvss 6.5epss 0.00

    TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/16, that may lead to application exit, in tinyxml2.cpp XMLUtil::GetCharacterRef.

  • CVE-2024-50613MedOct 27, 2024
    risk 0.42cvss 6.5epss 0.01

    libsndfile through 1.2.2 has a reachable assertion, that may lead to application exit, in mpeg_l3_encode.c mpeg_l3_encoder_close.

  • CVE-2024-47522HigOct 16, 2024
    risk 0.42cvss 7.5epss 0.01

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.7, invalid ALPN in TLS/QUIC traffic when JA4 matching/logging is enabled can lead to Suricata aborting with a panic. This issue has been…

  • CVE-2024-8768HigSep 17, 2024
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in the vLLM library. A completions API request with an empty prompt will crash the vLLM API server, resulting in a denial of service.

  • CVE-2024-23350MedAug 5, 2024
    risk 0.42cvss 6.5epss 0.00

    Permanent DOS when DL NAS transport receives multiple payloads such that one payload contains SOR container whose integrity check has failed, and the other is LPP where UE needs to send status message to network.

  • CVE-2024-31744HigApr 19, 2024
    risk 0.42cvss 7.5epss 0.01

    In Jasper 4.2.2, the jpc_streamlist_remove function in src/libjasper/jpc/jpc_dec.c:2407 has an assertion failure vulnerability, allowing attackers to cause a denial of service attack through a specific image file.

  • CVE-2023-44175MedOct 12, 2023
    risk 0.42cvss 6.5epss 0.01

    A Reachable Assertion vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows to send specific genuine PIM packets to the device resulting in rpd to crash causing a Denial of Service (DoS). Continued receipt and processing of…

  • CVE-2021-46179MedAug 22, 2023
    risk 0.42cvss 6.5epss 0.00

    Reachable Assertion vulnerability in upx before 4.0.0 allows attackers to cause a denial of service via crafted file passed to the the readx function.

  • CVE-2023-38976HigAug 21, 2023
    risk 0.42cvss 7.5epss 0.02

    An issue in weaviate v.1.20.0 allows a remote attacker to cause a denial of service via the handleUnbatchedGraphQLRequest function.

  • CVE-2023-37836MedJul 13, 2023
    risk 0.42cvss 6.5epss 0.01

    libjpeg commit db33a6e was discovered to contain a reachable assertion via BitMapHook::BitMapHook at bitmaphook.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.

  • CVE-2023-1428HigJun 9, 2023
    risk 0.42cvss 7.5epss 0.00

    There exists an vulnerability causing an abort() to be called in gRPC.  The following headers cause gRPC's C++ implementation to abort() when called via http2: te: x (x != trailers) :scheme: x (x != http, https) grpclb_client_stats: x (x == anything) On top of sending one…

  • CVE-2023-34411HigJun 5, 2023
    risk 0.42cvss 7.5epss 0.01

    The xml-rs crate before 0.8.14 for Rust and Crab allows a denial of service (panic) via an invalid <! token (such as <!DOCTYPEs/%<!A nesting) in an XML document. The earliest affected version is 0.8.9.

  • CVE-2022-36440HigApr 3, 2023
    risk 0.42cvss 7.5epss 0.02

    A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in the peek_for_as4_capability function. Attackers can maliciously construct BGP open packets and send them to BGP peers running frr-bgpd, resulting in DoS.

  • CVE-2022-3029HigSep 13, 2022
    risk 0.42cvss 7.5epss 0.01

    In NLnet Labs Routinator 0.9.0 up to and including 0.11.2, due to a mistake in error handling, data in RRDP snapshot and delta files that isn’t correctly base 64 encoded is treated as a fatal error and causes Routinator to exit. Worst case impact of this vulnerability is…

  • CVE-2022-2520MedAug 31, 2022
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in libtiff 4.4.0rc1. There is a sysmalloc assertion fail in rotateImage() at tiffcrop.c:8621 that can cause program crash when reading a crafted input.

  • CVE-2022-36522MedAug 26, 2022
    risk 0.42cvss 6.5epss 0.01

    Mikrotik RouterOs through stable v6.48.3 was discovered to contain an assertion failure in the component /advanced-tools/nova/bin/netwatch. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.

  • CVE-2021-3430MedJun 28, 2022
    risk 0.42cvss 6.5epss 0.01

    Assertion reachable with repeated LL_CONNECTION_PARAM_REQ. Zephyr versions >= v1.14 contain Reachable Assertion (CWE-617). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-46h3-hjcq-2jjr

  • CVE-2022-34000MedJun 19, 2022
    risk 0.42cvss 6.5epss 0.01

    libjxl 0.6.1 has an assertion failure in LowMemoryRenderPipeline::Init() in render_pipeline/low_memory_render_pipeline.cc.

  • CVE-2022-29977MedMay 11, 2022
    risk 0.42cvss 6.5epss 0.01

    There is an assertion failure error in stbi__jpeg_huff_decode, stb_image.h:1894 in libsixel img2sixel 1.8.6. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted JPEG file.