CWE-617
Reachable Assertion
Description
The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (812)
page 8 of 41| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-34144 | Hig | 0.49 | 7.5 | 0.00 | May 2, 2023 | Transient DOS due to reachable assertion in Modem during OSI decode scheduling. | ||
| CVE-2023-27788 | Hig | 0.49 | 7.5 | 0.01 | Mar 16, 2023 | An issue found in TCPrewrite v.4.4.3 allows a remote attacker to cause a denial of service via the ports2PORT function at the portmap.c:69 endpoint. | ||
| CVE-2022-40527 | Hig | 0.49 | 7.5 | 0.00 | Mar 10, 2023 | Transient DOS due to reachable assertion in WLAN while processing PEER ID populated by TQM. | ||
| CVE-2022-33272 | Hig | 0.49 | 7.5 | 0.00 | Mar 10, 2023 | Transient DOS in modem due to reachable assertion. | ||
| CVE-2022-33254 | Hig | 0.49 | 7.5 | 0.00 | Mar 10, 2023 | Transient DOS due to reachable assertion in Modem while processing SIB1 Message. | ||
| CVE-2022-33250 | Hig | 0.49 | 7.5 | 0.00 | Mar 10, 2023 | Transient DOS due to reachable assertion in modem when network repeatedly sent invalid message container for NR to LTE handover. | ||
| CVE-2022-33244 | Hig | 0.49 | 7.5 | 0.00 | Mar 10, 2023 | Transient DOS due to reachable assertion in modem during MIB reception and SIB timeout | ||
| CVE-2022-48363 | Hig | 0.49 | 7.5 | 0.01 | Feb 26, 2023 | In MPD before 0.23.8, as used on Automotive Grade Linux and other platforms, the PipeWire output plugin mishandles a Drain call in certain situations involving truncated files. Eventually there is an assertion failure in libmpdclient because libqtappfw passes in a NULL pointer. | ||
| CVE-2020-36562 | Hig | 0.49 | 7.5 | 0.01 | Dec 28, 2022 | Due to unchecked type assertions, maliciously crafted messages can cause panics, which may be used as a denial of service vector. | ||
| CVE-2022-25702 | Hig | 0.49 | 7.5 | 0.00 | Dec 13, 2022 | Denial of service in modem due to reachable assertion while processing reconfiguration message in Snapdragon Auto, Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables | ||
| CVE-2022-25692 | Hig | 0.49 | 7.5 | 0.00 | Dec 13, 2022 | Denial of service in Modem due to reachable assertion while processing the common config procedure in Snapdragon Auto, Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables | ||
| CVE-2022-25691 | Hig | 0.49 | 7.5 | 0.00 | Dec 13, 2022 | Denial of service in Modem due to reachable assertion while processing SIB1 with invalid SCS and bandwidth settings in Snapdragon Mobile | ||
| CVE-2022-25689 | Hig | 0.49 | 7.5 | 0.00 | Dec 13, 2022 | Denial of service in Modem due to reachable assertion in Snapdragon Mobile | ||
| CVE-2022-25673 | Hig | 0.49 | 7.5 | 0.00 | Dec 13, 2022 | Denial of service in MODEM due to reachable assertion while processing configuration from network in Snapdragon Mobile | ||
| CVE-2022-25672 | Hig | 0.49 | 7.5 | 0.00 | Dec 13, 2022 | Denial of service in MODEM due to reachable assertion while processing SIB1 with invalid Bandwidth in Snapdragon Mobile | ||
| CVE-2022-25671 | Hig | 0.49 | 7.5 | 0.00 | Nov 15, 2022 | Denial of service in MODEM due to reachable assertion in Snapdragon Mobile | ||
| CVE-2022-26446 | Hig | 0.49 | 7.5 | 0.01 | Nov 8, 2022 | In Modem 4G RRC, there is a possible system crash due to improper input validation. This could lead to remote denial of service, when concatenating improper SIB12 (CMAS message), with no additional execution privileges needed. User interaction is not needed for exploitation.… | ||
| CVE-2022-34967 | Hig | 0.49 | 7.5 | 0.01 | Aug 3, 2022 | The assertion `stmt->Dbc->FirstStmt' failed in MonetDB Database Server v11.43.13. | ||
| CVE-2022-32082 | Hig | 0.49 | 7.5 | 0.02 | Jul 1, 2022 | MariaDB v10.5 to v10.7 was discovered to contain an assertion failure at table->get_ref_count() == 0 in dict0dict.cc. | ||
| CVE-2022-33024 | Hig | 0.49 | 7.5 | 0.01 | Jun 23, 2022 | There is an Assertion `int decode_preR13_entities(BITCODE_RL, BITCODE_RL, unsigned int, BITCODE_RL, BITCODE_RL, Bit_Chain *, Dwg_Data *' failed at dwg2dxf: decode.c:5801 in libredwg v0.12.4.4608. |
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to reachable assertion in Modem during OSI decode scheduling.
- risk 0.49cvss 7.5epss 0.01
An issue found in TCPrewrite v.4.4.3 allows a remote attacker to cause a denial of service via the ports2PORT function at the portmap.c:69 endpoint.
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to reachable assertion in WLAN while processing PEER ID populated by TQM.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in modem due to reachable assertion.
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to reachable assertion in Modem while processing SIB1 Message.
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to reachable assertion in modem when network repeatedly sent invalid message container for NR to LTE handover.
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to reachable assertion in modem during MIB reception and SIB timeout
- risk 0.49cvss 7.5epss 0.01
In MPD before 0.23.8, as used on Automotive Grade Linux and other platforms, the PipeWire output plugin mishandles a Drain call in certain situations involving truncated files. Eventually there is an assertion failure in libmpdclient because libqtappfw passes in a NULL pointer.
- risk 0.49cvss 7.5epss 0.01
Due to unchecked type assertions, maliciously crafted messages can cause panics, which may be used as a denial of service vector.
- risk 0.49cvss 7.5epss 0.00
Denial of service in modem due to reachable assertion while processing reconfiguration message in Snapdragon Auto, Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
- risk 0.49cvss 7.5epss 0.00
Denial of service in Modem due to reachable assertion while processing the common config procedure in Snapdragon Auto, Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
- risk 0.49cvss 7.5epss 0.00
Denial of service in Modem due to reachable assertion while processing SIB1 with invalid SCS and bandwidth settings in Snapdragon Mobile
- risk 0.49cvss 7.5epss 0.00
Denial of service in Modem due to reachable assertion in Snapdragon Mobile
- risk 0.49cvss 7.5epss 0.00
Denial of service in MODEM due to reachable assertion while processing configuration from network in Snapdragon Mobile
- risk 0.49cvss 7.5epss 0.00
Denial of service in MODEM due to reachable assertion while processing SIB1 with invalid Bandwidth in Snapdragon Mobile
- risk 0.49cvss 7.5epss 0.00
Denial of service in MODEM due to reachable assertion in Snapdragon Mobile
- risk 0.49cvss 7.5epss 0.01
In Modem 4G RRC, there is a possible system crash due to improper input validation. This could lead to remote denial of service, when concatenating improper SIB12 (CMAS message), with no additional execution privileges needed. User interaction is not needed for exploitation.…
- risk 0.49cvss 7.5epss 0.01
The assertion `stmt->Dbc->FirstStmt' failed in MonetDB Database Server v11.43.13.
- risk 0.49cvss 7.5epss 0.02
MariaDB v10.5 to v10.7 was discovered to contain an assertion failure at table->get_ref_count() == 0 in dict0dict.cc.
- risk 0.49cvss 7.5epss 0.01
There is an Assertion `int decode_preR13_entities(BITCODE_RL, BITCODE_RL, unsigned int, BITCODE_RL, BITCODE_RL, Bit_Chain *, Dwg_Data *' failed at dwg2dxf: decode.c:5801 in libredwg v0.12.4.4608.