VYPR

CWE-617

Reachable Assertion

BaseDraft

Description

The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (812)

page 6 of 41
  • CVE-2024-23385HigNov 4, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.

  • CVE-2024-10455HigOct 28, 2024
    risk 0.49cvss 7.5epss 0.00

    Reachable Assertion in BPv7 parser in µD3TN v0.14.0 allows attacker to disrupt service via malformed Extension Block

  • CVE-2024-45795HigOct 16, 2024
    risk 0.49cvss 7.5epss 0.01

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.7, rules using datasets with the non-functional / unimplemented "unset" option can trigger an assertion during traffic parsing, leading to…

  • CVE-2024-20094HigOct 7, 2024
    risk 0.49cvss 7.5epss 0.01

    In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00843282; Issue ID: MSV-1535.

  • CVE-2024-39949HigJul 31, 2024
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing the device to crash.

  • CVE-2023-52887HigJul 29, 2024
    risk 0.49cvss 7.5epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: net: can: j1939: enhanced error handling for tightly received RTS messages in xtp_rx_rts_session_new This patch enhances error handling in scenarios with RTS (Request to Send) messages arriving closely. It…

  • CVE-2024-4076HigJul 23, 2024
    risk 0.49cvss 7.5epss 0.02

    Client queries that trigger serving stale data and that also require lookups in local authoritative zone data may result in an assertion failure. This issue affects BIND 9 versions 9.16.13 through 9.16.50, 9.18.0 through 9.18.27, 9.19.0 through 9.19.24, 9.11.33-S1 through…

  • CVE-2024-39697HigJul 9, 2024
    risk 0.49cvss 8.6epss 0.01

    phonenumber is a library for parsing, formatting and validating international phone numbers. Since 0.3.4, the phonenumber parsing code may panic due to a panic-guarded out-of-bounds access on the phonenumber string. In a typical deployment of rust-phonenumber, this may get…

  • CVE-2023-43529HigMay 6, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while processing IKEv2 Informational request messages, when a malformed fragment packet is received.

  • CVE-2023-33096HigMar 4, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while processing DL NAS Transport message, as specified in 3GPP 24.501 v16.

  • CVE-2023-33095HigMar 4, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while processing multiple payload container type with incorrect container length received in DL NAS transport OTA in NR.

  • CVE-2023-5679HigFeb 13, 2024
    risk 0.49cvss 7.5epss 0.01

    A bad interaction between DNS64 and serve-stale may cause `named` to crash with an assertion failure during recursive resolution, when both of these features are enabled. This issue affects BIND 9 versions 9.16.12 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19,…

  • CVE-2023-5517HigFeb 13, 2024
    risk 0.49cvss 7.5epss 0.01

    A flaw in query-handling code can cause `named` to exit prematurely with an assertion failure when: - `nxdomain-redirect ;` is configured, and - the resolver receives a PTR query for an RFC 1918 address that would normally result in an authoritative NXDOMAIN…

  • CVE-2023-43523HigFeb 6, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while processing 11AZ RTT management action frame received through OTA.

  • CVE-2023-34194HigDec 13, 2023
    risk 0.49cvss 7.5epss 0.01

    StringEqual in TiXmlDeclaration::Parse in tinyxmlparser.cpp in TinyXML through 2.6.2 has a reachable assertion (and application exit) via a crafted XML document with a '\0' located after whitespace.

  • CVE-2023-33044HigDec 5, 2023
    risk 0.49cvss 7.5epss 0.01

    Transient DOS in Data modem while handling TLB control messages from the Network.

  • CVE-2023-33043HigDec 5, 2023
    risk 0.49cvss 7.5epss 0.01

    Transient DOS in Modem when a Beam switch request is made with a non-configured BWP.

  • CVE-2023-33041HigDec 5, 2023
    risk 0.49cvss 7.5epss 0.00

    Under certain scenarios the WLAN Firmware will reach an assertion due to state confusion while looking up peer ids.

  • CVE-2023-40462HigDec 4, 2023
    risk 0.49cvss 7.5epss 0.01

    The ACEManager component of ALEOS 4.16 and earlier does not perform input sanitization during authentication, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other router functions. ACEManager recovers from the…

  • CVE-2023-32846HigDec 4, 2023
    risk 0.49cvss 7.5epss 0.01

    In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…