VYPR

CWE-617

Reachable Assertion

BaseDraft

Description

The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (863)

page 8 of 44
  • CVE-2023-39534HigAug 11, 2023
    risk 0.49cvss 7.5epss 0.01

    eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.10.0, 2.9.2, and 2.6.5, a malformed GAP submessage can trigger assertion failure, crashing FastDDS. Version 2.10.0, 2.9.2, and 2.6.5 contain a…

  • CVE-2023-34868HigJun 14, 2023
    risk 0.49cvss 7.5epss 0.01

    Jerryscript 3.0 (commit 05dbbd1) was discovered to contain an Assertion Failure via the parser_parse_for_statement_start at jerry-core/parser/js/js-parser-statm.c.

  • CVE-2023-34867HigJun 14, 2023
    risk 0.49cvss 7.5epss 0.01

    Jerryscript 3.0 (commit 05dbbd1) was discovered to contain an Assertion Failure via the ecma_property_hashmap_create at jerry-core/ecma/base/ecma-property-hashmap.c.

  • CVE-2022-40538HigJun 6, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS due to reachable assertion in modem while processing sib with incorrect values from network.

  • CVE-2022-33251HigJun 6, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS due to reachable assertion in Modem because of invalid network configuration.

  • CVE-2022-22060HigJun 6, 2023
    risk 0.49cvss 7.5epss 0.00

    Assertion occurs while processing Reconfiguration message due to improper validation

  • CVE-2023-2156HigMay 9, 2023
    risk 0.49cvss 7.5epss 0.06

    A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL protocol. This issue results from the lack of proper handling of user-supplied data, which can lead to an assertion failure. This may allow an unauthenticated remote attacker to…

  • CVE-2022-40504HigMay 2, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network.

  • CVE-2022-40508HigMay 2, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS due to reachable assertion in Modem while processing config related to cross carrier scheduling, which is not supported.

  • CVE-2022-34144HigMay 2, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS due to reachable assertion in Modem during OSI decode scheduling.

  • CVE-2023-27788HigMar 16, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue found in TCPrewrite v.4.4.3 allows a remote attacker to cause a denial of service via the ports2PORT function at the portmap.c:69 endpoint.

  • CVE-2022-40527HigMar 10, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS due to reachable assertion in WLAN while processing PEER ID populated by TQM.

  • CVE-2022-33272HigMar 10, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in modem due to reachable assertion.

  • CVE-2022-33254HigMar 10, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS due to reachable assertion in Modem while processing SIB1 Message.

  • CVE-2022-33250HigMar 10, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS due to reachable assertion in modem when network repeatedly sent invalid message container for NR to LTE handover.

  • CVE-2022-33244HigMar 10, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS due to reachable assertion in modem during MIB reception and SIB timeout

  • CVE-2022-48363HigFeb 26, 2023
    risk 0.49cvss 7.5epss 0.01

    In MPD before 0.23.8, as used on Automotive Grade Linux and other platforms, the PipeWire output plugin mishandles a Drain call in certain situations involving truncated files. Eventually there is an assertion failure in libmpdclient because libqtappfw passes in a NULL pointer.

  • CVE-2020-36562HigDec 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Due to unchecked type assertions, maliciously crafted messages can cause panics, which may be used as a denial of service vector.

  • CVE-2022-25702HigDec 13, 2022
    risk 0.49cvss 7.5epss 0.00

    Denial of service in modem due to reachable assertion while processing reconfiguration message in Snapdragon Auto, Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

  • CVE-2022-25692HigDec 13, 2022
    risk 0.49cvss 7.5epss 0.00

    Denial of service in Modem due to reachable assertion while processing the common config procedure in Snapdragon Auto, Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables