VYPR

CWE-617

Reachable Assertion

BaseDraft

Description

The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (812)

page 28 of 41
  • CVE-2021-46336MedJan 20, 2022
    risk 0.36cvss 5.5epss 0.01

    There is an Assertion 'opts & PARSER_CLASS_LITERAL_CTOR_PRESENT' failed at /parser/js/js-parser-expr.c(parser_parse_class_body) in JerryScript 3.0.0.

  • CVE-2021-46055MedJan 10, 2022
    risk 0.36cvss 5.5epss 0.01

    A Denial of Service vulnerability exists in Binaryen 104 due to an assertion abort in wasm::WasmBinaryBuilder::visitRethrow(wasm::Rethrow*).

  • CVE-2021-46054MedJan 10, 2022
    risk 0.36cvss 5.5epss 0.01

    A Denial of Service vulnerability exists in Binaryen 104 due to an assertion abort in wasm::WasmBinaryBuilder::visitRethrow(wasm::Rethrow*).

  • CVE-2021-46052MedJan 10, 2022
    risk 0.36cvss 5.5epss 0.01

    A Denial of Service vulnerability exists in Binaryen 104 due to an assertion abort in wasm::Tuple::validate.

  • CVE-2021-46048MedJan 10, 2022
    risk 0.36cvss 5.5epss 0.01

    A Denial of Service vulnerability exists in Binaryen 104 due to an assertion abort in wasm::WasmBinaryBuilder::readFunctions.

  • CVE-2021-44022MedDec 3, 2021
    risk 0.36cvss 5.5epss 0.00

    A reachable assertion vulnerability in Trend Micro Apex One could allow an attacker to crash the program on affected installations, leading to a denial-of-service (DoS). Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in…

  • CVE-2021-39283MedAug 18, 2021
    risk 0.36cvss 5.5epss 0.01

    liveMedia/FramedSource.cpp in Live555 through 1.08 allows an assertion failure and application exit via multiple SETUP and PLAY commands.

  • CVE-2021-3502MedMay 7, 2021
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in avahi 0.8-5. A reachable assertion is present in avahi_s_host_name_resolver_start function allowing a local attacker to crash the avahi service by requesting hostname resolutions through the avahi socket or dbus methods for invalid hostnames. The highest…

  • CVE-2020-3958MedMay 29, 2020
    risk 0.36cvss 5.5epss 0.00

    VMware ESXi (6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), VMware Workstation (15.x before 15.5.2) and VMware Fusion (11.x before 11.5.2) contain a denial-of-service vulnerability in the shader functionality. Successful exploitation of this issue may…

  • CVE-2019-5020MedJul 31, 2019
    risk 0.36cvss 5.5epss 0.01

    An exploitable denial of service vulnerability exists in the object lookup functionality of Yara 3.8.1. A specially crafted binary file can cause a negative value to be read to satisfy an assert, resulting in Denial of Service. An attacker can create a malicious binary to…

  • CVE-2018-5736MedJan 16, 2019
    risk 0.36cvss 5.3epss 0.18

    An error in zone database reference counting can lead to an assertion failure if a server which is running an affected version of BIND attempts several transfers of a slave zone in quick succession. This defect could be deliberately exercised by an attacker who is permitted to…

  • CVE-2017-18169MedJun 15, 2018
    risk 0.36cvss 5.5epss 0.00

    User process can perform the kernel DOS in ashmem when doing cache maintenance operation in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel.

  • CVE-2018-9055MedMar 27, 2018
    risk 0.36cvss 5.5epss 0.02

    JasPer 2.0.14 allows denial of service via a reachable assertion in the function jpc_firstone in libjasper/jpc/jpc_math.c.

  • CVE-2017-15371MedOct 16, 2017
    risk 0.36cvss 5.5epss 0.02

    There is a reachable assertion abort in the function sox_append_comment() in formats.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a denial of service attack during conversion of an audio file.

  • CVE-2017-1000252MedSep 26, 2017
    risk 0.36cvss 5.5epss 0.00

    The KVM subsystem in the Linux kernel through 4.13.3 allows guest OS users to cause a denial of service (assertion failure, and hypervisor hang or crash) via an out-of bounds guest_irq value, related to arch/x86/kvm/vmx.c and virt/kvm/eventfd.c.

  • CVE-2017-14649MedSep 21, 2017
    risk 0.36cvss 5.5epss 0.01

    ReadOneJNGImage in coders/png.c in GraphicsMagick version 1.3.26 does not properly validate JNG data, leading to a denial of service (assertion failure in magick/pixel_cache.c, and application crash).

  • CVE-2016-9388MedMar 23, 2017
    risk 0.36cvss 5.5epss 0.02

    The ras_getcmap function in ras_dec.c in JasPer before 1.900.14 allows remote attackers to cause a denial of service (assertion failure) via a crafted image file.

  • CVE-2017-5981MedMar 1, 2017
    risk 0.36cvss 5.5epss 0.02

    seeko.c in zziplib 0.13.62 allows remote attackers to cause a denial of service (assertion failure and crash) via a crafted ZIP file.

  • CVE-2017-5986MedFeb 18, 2017
    risk 0.36cvss 5.5epss 0.01

    Race condition in the sctp_wait_for_sndbuf function in net/sctp/socket.c in the Linux kernel before 4.9.11 allows local users to cause a denial of service (assertion failure and panic) via a multithreaded application that peels off an association in a certain buffer-full state.

  • CVE-2015-8745MedDec 29, 2016
    risk 0.36cvss 5.5epss 0.00

    QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue. It could occur while reading Interrupt Mask Registers (IMR). A privileged (CAP_SYS_RAWIO) guest user could use this flaw to crash the QEMU process instance…