VYPR

CWE-617

Reachable Assertion

BaseDraft

Description

The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (812)

page 19 of 41
  • CVE-2022-24272MedApr 21, 2022
    risk 0.42cvss 6.5epss 0.01

    An authenticated user may trigger an invariant assertion during command dispatch due to incorrect validation on the $external database. This may result in mongod denial of service or server crash. This issue affects: MongoDB Inc. MongoDB Server v5.0 versions, prior to and…

  • CVE-2022-24777HigMar 25, 2022
    risk 0.42cvss 7.5epss 0.01

    grpc-swift is the Swift language implementation of gRPC, a remote procedure call (RPC) framework. Prior to version 1.7.2, a grpc-swift server is vulnerable to a denial of service attack via a reachable assertion. This is due to incorrect logic when handling GOAWAY frames. The…

  • CVE-2022-23569MedFeb 3, 2022
    risk 0.42cvss 6.5epss 0.00

    Tensorflow is an Open Source Machine Learning Framework. Multiple operations in TensorFlow can be used to trigger a denial of service via `CHECK`-fails (i.e., assertion failures). This is similar to TFSA-2021-198 and has similar fixes. We have patched the reported issues in…

  • CVE-2021-32037MedNov 24, 2021
    risk 0.42cvss 6.5epss 0.01

    An authorized user may trigger an invariant which may result in denial of service or server exit if a relevant aggregation request is sent to a shard. Usually, the requests are sent via mongos and special privileges are required in order to know the address of the shards and to…

  • CVE-2021-31878MedJul 30, 2021
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in PJSIP in Asterisk before 16.19.1 and before 18.5.1. To exploit, a re-INVITE without SDP must be received after Asterisk has sent a BYE request.

  • CVE-2020-20262MedJul 21, 2021
    risk 0.42cvss 6.5epss 0.02

    Mikrotik RouterOs before 6.47 (stable tree) suffers from an assertion failure vulnerability in the /ram/pckg/security/nova/bin/ipsec process. An authenticated remote attacker can cause a Denial of Service due to an assertion failure via a crafted packet.

  • CVE-2020-36420HigJul 15, 2021
    risk 0.42cvss 7.5epss 0.02

    Polipo through 1.1.1, when NDEBUG is omitted, allows denial of service via a reachable assertion during parsing of a malformed Range header. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

  • CVE-2020-20225MedJul 7, 2021
    risk 0.42cvss 6.5epss 0.02

    Mikrotik RouterOs before 6.47 (stable tree) suffers from an assertion failure vulnerability in the /nova/bin/user process. An authenticated remote attacker can cause a Denial of Service due to an assertion failure via a crafted packet.

  • CVE-2020-20211MedJul 7, 2021
    risk 0.42cvss 6.5epss 0.02

    Mikrotik RouterOs 6.44.5 (long-term tree) suffers from an assertion failure vulnerability in the /nova/bin/console process. An authenticated remote attacker can cause a Denial of Service due to an assertion failure via a crafted packet.

  • CVE-2021-29258HigMay 20, 2021
    risk 0.42cvss 7.5epss 0.02

    An issue was discovered in Envoy 1.14.0. There is a remotely exploitable crash for HTTP2 Metadata, because an empty METADATA map triggers a Reachable Assertion.

  • CVE-2020-20214MedMay 18, 2021
    risk 0.42cvss 6.5epss 0.03

    Mikrotik RouterOs 6.44.6 (long-term tree) suffers from an assertion failure vulnerability in the btest process. An authenticated remote attacker can cause a Denial of Service due to an assertion failure via a crafted packet.

  • CVE-2019-25037HigApr 27, 2021
    risk 0.42cvss 7.5epss 0.02

    Unbound before 1.9.5 allows an assertion failure and denial of service in dname_pkt_copy via an invalid packet. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited

  • CVE-2019-25036HigApr 27, 2021
    risk 0.42cvss 7.5epss 0.02

    Unbound before 1.9.5 allows an assertion failure and denial of service in synth_cname. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited

  • CVE-2019-14851MedMar 18, 2021
    risk 0.42cvss 6.5epss 0.01

    A denial of service vulnerability was discovered in nbdkit. A client issuing a certain sequence of commands could possibly trigger an assertion failure, causing nbdkit to exit. This issue only affected nbdkit versions 1.12.7, 1.14.1, and 1.15.1.

  • CVE-2021-23970MedFeb 26, 2021
    risk 0.42cvss 6.5epss 0.01

    Context-specific code was included in a shared jump table; resulting in assertions being triggered in multithreaded wasm code. This vulnerability affects Firefox < 86.

  • CVE-2020-27617MedNov 6, 2020
    risk 0.42cvss 6.5epss 0.03

    eth_get_gso_type in net/eth.c in QEMU 4.2.1 allows guest OS users to trigger an assertion failure. A guest can crash the QEMU process via packet data that lacks a valid Layer 3 protocol.

  • CVE-2020-1681MedOct 16, 2020
    risk 0.42cvss 6.5epss 0.01

    Receipt of a specifically malformed NDP packet sent from the local area network (LAN) to a device running Juniper Networks Junos OS Evolved can cause the ndp process to crash, resulting in a Denial of Service (DoS). The process automatically restarts without intervention, but a…

  • CVE-2020-13595MedAug 31, 2020
    risk 0.42cvss 6.5epss 0.01

    The Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.0 through 4.2 (for ESP32 devices) returns the wrong number of completed BLE packets and triggers a reachable assertion on the host stack when receiving a packet with an MIC failure. An attacker…

  • CVE-2015-8012HigJan 28, 2020
    risk 0.42cvss 7.5epss 0.03

    lldpd before 0.8.0 allows remote attackers to cause a denial of service (assertion failure and daemon crash) via a malformed packet.

  • CVE-2019-20056MedDec 29, 2019
    risk 0.42cvss 6.5epss 0.01

    stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other products, has an assertion failure in stbi__shiftsigned.