VYPR

CWE-617

Reachable Assertion

BaseDraft

Description

The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (812)

page 20 of 41
  • CVE-2012-5521MedNov 25, 2019
    risk 0.42cvss 6.5epss 0.01

    quagga (ospf6d) 0.99.21 has a DoS flaw in the way the ospf6d daemon performs routes removal

  • CVE-2019-18844HigNov 13, 2019
    risk 0.42cvss 7.5epss 0.02

    The Device Model in ACRN before 2019w25.5-140000p relies on assert calls in devicemodel/hw/pci/core.c and devicemodel/include/pci_core.h (instead of other mechanisms for propagating error information or diagnostic information), which might allow attackers to cause a denial of…

  • CVE-2019-6473MedOct 16, 2019
    risk 0.42cvss 6.5epss 0.01

    An invalid hostname option can trigger an assertion failure in the Kea DHCPv4 server process (kea-dhcp4), causing the server process to exit. Versions affected: 1.4.0 to 1.5.0, 1.6.0-beta1, and 1.6.0-beta2.

  • CVE-2019-6472MedOct 16, 2019
    risk 0.42cvss 6.5epss 0.01

    A packet containing a malformed DUID can cause the Kea DHCPv6 server process (kea-dhcp6) to exit due to an assertion failure. Versions affected: 1.4.0 to 1.5.0, 1.6.0-beta1, and 1.6.0-beta2.

  • CVE-2019-14383MedJul 30, 2019
    risk 0.42cvss 6.5epss 0.01

    J2B in libopenmpt before 0.4.2 allows an assertion failure during file parsing with debug STLs.

  • CVE-2019-14382MedJul 30, 2019
    risk 0.42cvss 6.5epss 0.01

    DSM in libopenmpt before 0.4.2 allows an assertion failure during file parsing with debug STLs.

  • CVE-2019-9211MedFeb 27, 2019
    risk 0.42cvss 6.5epss 0.02

    There is a reachable assertion abort in the function write_long_string_missing_values() in data/sys-file-writer.c in libdata.a in GNU PSPP 1.2.0 that will lead to denial of service.

  • CVE-2019-7697MedFeb 10, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Bento4 v1.5.1-627. There is an assertion failure in AP4_AtomListWriter::Action in Core/Ap4Atom.cpp, leading to a denial of service (program crash), as demonstrated by mp42hls.

  • CVE-2019-6461MedJan 16, 2019
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in cairo 1.16.0. There is an assertion problem in the function _cairo_arc_in_direction in the file cairo-arc.c.

  • CVE-2018-19539MedNov 26, 2018
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in JasPer 2.0.14. There is an access violation in the function jas_image_readcmpt in libjasper/base/jas_image.c, leading to a denial of service.

  • CVE-2018-17096MedSep 16, 2018
    risk 0.42cvss 6.5epss 0.02

    The BPMDetect class in BPMDetect.cpp in libSoundTouch.a in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (assertion failure and application exit), as demonstrated by SoundStretch.

  • CVE-2018-15822HigAug 23, 2018
    risk 0.42cvss 7.5epss 0.03

    The flv_write_packet function in libavformat/flvenc.c in FFmpeg through 2.8 does not check for an empty audio packet, leading to an assertion failure.

  • CVE-2018-9303MedApr 4, 2018
    risk 0.42cvss 6.5epss 0.01

    In Exiv2 0.26, an assertion failure in BigTiffImage::readData in bigtiffimage.cpp results in an abort.

  • CVE-2018-9252MedApr 4, 2018
    risk 0.42cvss 6.5epss 0.02

    JasPer 2.0.14 allows denial of service via a reachable assertion in the function jpc_abstorelstepsize in libjasper/jpc/jpc_enc.c.

  • CVE-2018-4113MedApr 3, 2018
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves…

  • CVE-2017-18252MedMar 27, 2018
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in ImageMagick 7.0.7. The MogrifyImageList function in MagickWand/mogrify.c allows attackers to cause a denial of service (assertion failure and application exit in ReplaceImageInList) via a crafted file.

  • CVE-2017-17722MedFeb 12, 2018
    risk 0.42cvss 6.5epss 0.01

    In Exiv2 0.26, there is a reachable assertion in the readHeader function in bigtiffimage.cpp, which will lead to a remote denial of service attack via a crafted TIFF file.

  • CVE-2017-16818MedDec 20, 2017
    risk 0.42cvss 6.5epss 0.02

    RADOS Gateway in Ceph 12.1.0 through 12.2.1 allows remote authenticated users to cause a denial of service (assertion failure and application exit) by leveraging "full" (not necessarily admin) privileges to post an invalid profile to the admin API, related to…

  • CVE-2017-13673MedAug 29, 2017
    risk 0.42cvss 6.5epss 0.03

    The vga display update in mis-calculated the region for the dirty bitmap snapshot in case split screen mode is used causing a denial of service (assertion failure) in the cpu_physical_memory_snapshot_get_dirty function.

  • CVE-2017-13727MedAug 29, 2017
    risk 0.42cvss 6.5epss 0.02

    There is a reachable assertion abort in the function TIFFWriteDirectoryTagSubifd() in LibTIFF 4.0.8, related to tif_dirwrite.c and a SubIFD tag. A crafted input will lead to a remote denial of service attack.