CWE-617
Reachable Assertion
Description
The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (812)
page 26 of 41| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-25675 | Med | 0.36 | 5.5 | 0.00 | Dec 13, 2022 | Denial of service due to reachable assertion in modem while processing filter rule from application client in Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile | ||
| CVE-2022-40755 | Med | 0.36 | 5.5 | 0.00 | Sep 16, 2022 | JasPer 3.0.6 allows denial of service via a reachable assertion in the function inttobits in libjasper/base/jas_image.c. | ||
| CVE-2022-38496 | Med | 0.36 | 5.5 | 0.00 | Sep 13, 2022 | LIEF commit 365a16a was discovered to contain a reachable assertion abort via the component BinaryStream.hpp. | ||
| CVE-2022-2719 | Med | 0.36 | 5.5 | 0.00 | Aug 10, 2022 | In ImageMagick, a crafted file could trigger an assertion failure when a call to WriteImages was made in MagickWand/operation.c, due to a NULL image list. This could potentially cause a denial of service. This was fixed in upstream ImageMagick version 7.1.0-30. | ||
| CVE-2022-33069 | Med | 0.36 | 5.5 | 0.01 | Jun 23, 2022 | Ethereum Solidity v0.8.14 contains an assertion failure via SMTEncoder::indexOrMemberAssignment() at SMTEncoder.cpp. | ||
| CVE-2022-31651 | Med | 0.36 | 5.5 | 0.01 | May 25, 2022 | In SoX 14.4.2, there is an assertion failure in rate_init in rate.c in libsox.a. | ||
| CVE-2022-27939 | Med | 0.36 | 5.5 | 0.01 | Mar 26, 2022 | tcprewrite in Tcpreplay 4.4.1 has a reachable assertion in get_layer4_v6 in common/get.c. | ||
| CVE-2022-27938 | Med | 0.36 | 5.5 | 0.01 | Mar 26, 2022 | stb_image.h (aka the stb image loader) 2.19, as used in libsixel and other products, has a reachable assertion in stbi__create_png_image_raw. | ||
| CVE-2022-25484 | Med | 0.36 | 5.5 | 0.01 | Mar 22, 2022 | tcpprep v4.4.1 has a reachable assertion (assert(l2len > 0)) in packet2tree() at tree.c in tcpprep v4.4.1. | ||
| CVE-2022-0865 | Med | 0.36 | 5.5 | 0.01 | Mar 10, 2022 | Reachable Assertion in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 5e180045. | ||
| CVE-2022-22901 | Med | 0.36 | 5.5 | 0.01 | Feb 17, 2022 | There is an Assertion in 'context_p->next_scanner_info_p->type == SCANNER_TYPE_FUNCTION' failed at parser_parse_function_arguments in /js/js-parser.c of JerryScript commit a6ab5e9. | ||
| CVE-2021-45387 | Med | 0.36 | 5.5 | 0.01 | Feb 11, 2022 | tcpreplay 4.3.4 has a Reachable Assertion in add_tree_ipv4() at tree.c. | ||
| CVE-2021-45386 | Med | 0.36 | 5.5 | 0.01 | Feb 11, 2022 | tcpreplay 4.3.4 has a Reachable Assertion in add_tree_ipv6() at tree.c | ||
| CVE-2021-46666 | Med | 0.36 | 5.5 | 0.00 | Feb 1, 2022 | MariaDB before 10.6.2 allows an application crash because of mishandling of a pushdown from a HAVING clause to a WHERE clause. | ||
| CVE-2021-46517 | Med | 0.36 | 5.5 | 0.01 | Jan 27, 2022 | There is an Assertion `mjs_stack_size(&mjs->scopes) > 0' failed at src/mjs_exec.c in Cesanta MJS v2.20.0. | ||
| CVE-2021-46515 | Med | 0.36 | 5.5 | 0.01 | Jan 27, 2022 | There is an Assertion `mjs_stack_size(&mjs->scopes) >= scopes_len' failed at src/mjs_exec.c in Cesanta MJS v2.20.0. | ||
| CVE-2021-46514 | Med | 0.36 | 5.5 | 0.01 | Jan 27, 2022 | There is an Assertion 'ppos != NULL && mjs_is_number(*ppos)' failed at src/mjs_core.c in Cesanta MJS v2.20.0. | ||
| CVE-2021-46511 | Med | 0.36 | 5.5 | 0.01 | Jan 27, 2022 | There is an Assertion `m->len >= sizeof(v)' failed at src/mjs_core.c in Cesanta MJS v2.20.0. | ||
| CVE-2021-46510 | Med | 0.36 | 5.5 | 0.01 | Jan 27, 2022 | There is an Assertion `s < mjs->owned_strings.buf + mjs->owned_strings.len' failed at src/mjs_gc.c in Cesanta MJS v2.20.0. | ||
| CVE-2021-46508 | Med | 0.36 | 5.5 | 0.01 | Jan 27, 2022 | There is an Assertion `i < parts_cnt' failed at src/mjs_bcode.c in Cesanta MJS v2.20.0. |
- risk 0.36cvss 5.5epss 0.00
Denial of service due to reachable assertion in modem while processing filter rule from application client in Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile
- risk 0.36cvss 5.5epss 0.00
JasPer 3.0.6 allows denial of service via a reachable assertion in the function inttobits in libjasper/base/jas_image.c.
- risk 0.36cvss 5.5epss 0.00
LIEF commit 365a16a was discovered to contain a reachable assertion abort via the component BinaryStream.hpp.
- risk 0.36cvss 5.5epss 0.00
In ImageMagick, a crafted file could trigger an assertion failure when a call to WriteImages was made in MagickWand/operation.c, due to a NULL image list. This could potentially cause a denial of service. This was fixed in upstream ImageMagick version 7.1.0-30.
- risk 0.36cvss 5.5epss 0.01
Ethereum Solidity v0.8.14 contains an assertion failure via SMTEncoder::indexOrMemberAssignment() at SMTEncoder.cpp.
- risk 0.36cvss 5.5epss 0.01
In SoX 14.4.2, there is an assertion failure in rate_init in rate.c in libsox.a.
- risk 0.36cvss 5.5epss 0.01
tcprewrite in Tcpreplay 4.4.1 has a reachable assertion in get_layer4_v6 in common/get.c.
- risk 0.36cvss 5.5epss 0.01
stb_image.h (aka the stb image loader) 2.19, as used in libsixel and other products, has a reachable assertion in stbi__create_png_image_raw.
- risk 0.36cvss 5.5epss 0.01
tcpprep v4.4.1 has a reachable assertion (assert(l2len > 0)) in packet2tree() at tree.c in tcpprep v4.4.1.
- risk 0.36cvss 5.5epss 0.01
Reachable Assertion in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 5e180045.
- risk 0.36cvss 5.5epss 0.01
There is an Assertion in 'context_p->next_scanner_info_p->type == SCANNER_TYPE_FUNCTION' failed at parser_parse_function_arguments in /js/js-parser.c of JerryScript commit a6ab5e9.
- risk 0.36cvss 5.5epss 0.01
tcpreplay 4.3.4 has a Reachable Assertion in add_tree_ipv4() at tree.c.
- risk 0.36cvss 5.5epss 0.01
tcpreplay 4.3.4 has a Reachable Assertion in add_tree_ipv6() at tree.c
- risk 0.36cvss 5.5epss 0.00
MariaDB before 10.6.2 allows an application crash because of mishandling of a pushdown from a HAVING clause to a WHERE clause.
- risk 0.36cvss 5.5epss 0.01
There is an Assertion `mjs_stack_size(&mjs->scopes) > 0' failed at src/mjs_exec.c in Cesanta MJS v2.20.0.
- risk 0.36cvss 5.5epss 0.01
There is an Assertion `mjs_stack_size(&mjs->scopes) >= scopes_len' failed at src/mjs_exec.c in Cesanta MJS v2.20.0.
- risk 0.36cvss 5.5epss 0.01
There is an Assertion 'ppos != NULL && mjs_is_number(*ppos)' failed at src/mjs_core.c in Cesanta MJS v2.20.0.
- risk 0.36cvss 5.5epss 0.01
There is an Assertion `m->len >= sizeof(v)' failed at src/mjs_core.c in Cesanta MJS v2.20.0.
- risk 0.36cvss 5.5epss 0.01
There is an Assertion `s < mjs->owned_strings.buf + mjs->owned_strings.len' failed at src/mjs_gc.c in Cesanta MJS v2.20.0.
- risk 0.36cvss 5.5epss 0.01
There is an Assertion `i < parts_cnt' failed at src/mjs_bcode.c in Cesanta MJS v2.20.0.