CWE-617
Reachable Assertion
Description
The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (812)
page 7 of 41| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-32845 | Hig | 0.49 | 7.5 | 0.01 | Dec 4, 2023 | In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:… | ||
| CVE-2023-32844 | Hig | 0.49 | 7.5 | 0.01 | Dec 4, 2023 | In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:… | ||
| CVE-2023-32843 | Hig | 0.49 | 7.5 | 0.01 | Dec 4, 2023 | In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:… | ||
| CVE-2023-32842 | Hig | 0.49 | 7.5 | 0.01 | Dec 4, 2023 | In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:… | ||
| CVE-2023-32841 | Hig | 0.49 | 7.5 | 0.01 | Dec 4, 2023 | In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:… | ||
| CVE-2023-24843 | Hig | 0.49 | 7.5 | 0.00 | Oct 3, 2023 | Transient DOS in Modem while triggering a camping on an 5G cell. | ||
| CVE-2023-32820 | Hig | 0.49 | 7.5 | 0.00 | Oct 2, 2023 | In wlan firmware, there is a possible firmware assertion due to improper input handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07932637; Issue ID: ALPS07932637. | ||
| CVE-2023-4236 | Hig | 0.49 | 7.5 | 0.02 | Sep 20, 2023 | A flaw in the networking code handling DNS-over-TLS queries may cause `named` to terminate unexpectedly due to an assertion failure. This happens when internal data structures are incorrectly reused under significant DNS-over-TLS query load. This issue affects BIND 9 versions… | ||
| CVE-2023-21653 | Hig | 0.49 | 7.5 | 0.00 | Sep 5, 2023 | Transient DOS in Modem while processing RRC reconfiguration message. | ||
| CVE-2023-21646 | Hig | 0.49 | 7.5 | 0.00 | Sep 5, 2023 | Transient DOS in Modem while processing invalid System Information Block 1. | ||
| CVE-2023-39949 | Hig | 0.49 | 7.5 | 0.01 | Aug 11, 2023 | eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.9.1 and 2.6.5, improper validation of sequence numbers may lead to remotely reachable assertion failure. This can remotely crash any Fast-DDS… | ||
| CVE-2023-39534 | Hig | 0.49 | 7.5 | 0.01 | Aug 11, 2023 | eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.10.0, 2.9.2, and 2.6.5, a malformed GAP submessage can trigger assertion failure, crashing FastDDS. Version 2.10.0, 2.9.2, and 2.6.5 contain a… | ||
| CVE-2023-34868 | Hig | 0.49 | 7.5 | 0.01 | Jun 14, 2023 | Jerryscript 3.0 (commit 05dbbd1) was discovered to contain an Assertion Failure via the parser_parse_for_statement_start at jerry-core/parser/js/js-parser-statm.c. | ||
| CVE-2023-34867 | Hig | 0.49 | 7.5 | 0.01 | Jun 14, 2023 | Jerryscript 3.0 (commit 05dbbd1) was discovered to contain an Assertion Failure via the ecma_property_hashmap_create at jerry-core/ecma/base/ecma-property-hashmap.c. | ||
| CVE-2022-40538 | Hig | 0.49 | 7.5 | 0.00 | Jun 6, 2023 | Transient DOS due to reachable assertion in modem while processing sib with incorrect values from network. | ||
| CVE-2022-33251 | Hig | 0.49 | 7.5 | 0.00 | Jun 6, 2023 | Transient DOS due to reachable assertion in Modem because of invalid network configuration. | ||
| CVE-2022-22060 | Hig | 0.49 | 7.5 | 0.00 | Jun 6, 2023 | Assertion occurs while processing Reconfiguration message due to improper validation | ||
| CVE-2023-2156 | Hig | 0.49 | 7.5 | 0.06 | May 9, 2023 | A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL protocol. This issue results from the lack of proper handling of user-supplied data, which can lead to an assertion failure. This may allow an unauthenticated remote attacker to… | ||
| CVE-2022-40504 | Hig | 0.49 | 7.5 | 0.00 | May 2, 2023 | Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network. | ||
| CVE-2022-40508 | Hig | 0.49 | 7.5 | 0.00 | May 2, 2023 | Transient DOS due to reachable assertion in Modem while processing config related to cross carrier scheduling, which is not supported. |
- risk 0.49cvss 7.5epss 0.01
In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…
- risk 0.49cvss 7.5epss 0.01
In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…
- risk 0.49cvss 7.5epss 0.01
In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…
- risk 0.49cvss 7.5epss 0.01
In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…
- risk 0.49cvss 7.5epss 0.01
In 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving malformed RRC messages, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…
- risk 0.49cvss 7.5epss 0.00
Transient DOS in Modem while triggering a camping on an 5G cell.
- risk 0.49cvss 7.5epss 0.00
In wlan firmware, there is a possible firmware assertion due to improper input handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07932637; Issue ID: ALPS07932637.
- risk 0.49cvss 7.5epss 0.02
A flaw in the networking code handling DNS-over-TLS queries may cause `named` to terminate unexpectedly due to an assertion failure. This happens when internal data structures are incorrectly reused under significant DNS-over-TLS query load. This issue affects BIND 9 versions…
- risk 0.49cvss 7.5epss 0.00
Transient DOS in Modem while processing RRC reconfiguration message.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in Modem while processing invalid System Information Block 1.
- risk 0.49cvss 7.5epss 0.01
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.9.1 and 2.6.5, improper validation of sequence numbers may lead to remotely reachable assertion failure. This can remotely crash any Fast-DDS…
- risk 0.49cvss 7.5epss 0.01
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.10.0, 2.9.2, and 2.6.5, a malformed GAP submessage can trigger assertion failure, crashing FastDDS. Version 2.10.0, 2.9.2, and 2.6.5 contain a…
- risk 0.49cvss 7.5epss 0.01
Jerryscript 3.0 (commit 05dbbd1) was discovered to contain an Assertion Failure via the parser_parse_for_statement_start at jerry-core/parser/js/js-parser-statm.c.
- risk 0.49cvss 7.5epss 0.01
Jerryscript 3.0 (commit 05dbbd1) was discovered to contain an Assertion Failure via the ecma_property_hashmap_create at jerry-core/ecma/base/ecma-property-hashmap.c.
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to reachable assertion in modem while processing sib with incorrect values from network.
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to reachable assertion in Modem because of invalid network configuration.
- risk 0.49cvss 7.5epss 0.00
Assertion occurs while processing Reconfiguration message due to improper validation
- risk 0.49cvss 7.5epss 0.06
A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL protocol. This issue results from the lack of proper handling of user-supplied data, which can lead to an assertion failure. This may allow an unauthenticated remote attacker to…
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network.
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to reachable assertion in Modem while processing config related to cross carrier scheduling, which is not supported.