VYPR

CWE-691

Insufficient Control Flow Management

PillarDraft

Description

The code does not sufficiently manage its control flow during execution, creating conditions in which the control flow can be modified in unexpected ways.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-29

CVEs mapped to this weakness (33)

page 2 of 2
  • CVE-2023-5102MedOct 9, 2023
    risk 0.34cvss 5.3epss 0.01

    Insufficient Control Flow Management in RDT400 in SICK APU allows an unprivileged remote attacker to potentially enable hidden functionality via HTTP requests.

  • CVE-2022-48481MedApr 28, 2023
    risk 0.34cvss 5.2epss 0.00

    In JetBrains Toolbox App before 1.28 a DYLIB injection on macOS was possible

  • CVE-2022-46828MedDec 8, 2022
    risk 0.34cvss 5.2epss 0.00

    In JetBrains IntelliJ IDEA before 2022.3 a DYLIB injection on macOS was possible.

  • CVE-2022-41646MedMay 10, 2023
    risk 0.31cvss 4.7epss 0.00

    Insufficient control flow management in the Intel(R) IPP Cryptography software before version 2021.6 may allow an unauthenticated user to potentially enable information disclosure via local access.

  • CVE-2022-37409MedMay 10, 2023
    risk 0.31cvss 4.7epss 0.00

    Insufficient control flow management for the Intel(R) IPP Cryptography software before version 2021.6 may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2022-43505MedAug 11, 2023
    risk 0.27cvss 4.1epss 0.00

    Insufficient control flow management in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable denial of service via local access.

  • CVE-2024-25565LowNov 13, 2024
    risk 0.25cvss 3.8epss 0.00

    Insufficient control flow management in UEFI firmware for some Intel(R) Xeon(R) Processors may allow an authenticated user to enable denial of service via local access.

  • CVE-2022-46299LowNov 14, 2023
    risk 0.21cvss 3.3epss 0.00

    Insufficient control flow management for some Intel Unison software may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2025-47774LowMay 15, 2025
    risk 0.12cvss epss 0.00

    Vyper is the Pythonic Programming Language for the Ethereum Virtual Machine. In versions up to and including 0.4.2rc1, the `slice()` builtin can elide side effects when the output length is 0, and the source bytestring is a builtin (`msg.data` or `.code`). The reason is…

  • CVE-2025-47285LowMay 15, 2025
    risk 0.12cvss epss 0.00

    Vyper is the Pythonic Programming Language for the Ethereum Virtual Machine. In versions up to and including 0.4.2rc1, `concat()` may skip evaluation of side effects when the length of an argument is zero. This is due to a fastpath in the implementation which skips evaluation of…

  • CVE-2025-25774MedMar 12, 2025
    risk 0.00cvss 6.5epss 0.00

    An issue was discovered in Open5GS v2.7.2. When a UE switches between two gNBs and sends a handover request at a specific time, it may cause an exception in the AMF's internal state machine, leading to an AMF crash and resulting in a Denial of Service (DoS).

  • CVE-2024-37158LowJun 17, 2024
    risk 0.00cvss 3.5epss 0.00

    Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. Preliminary checks on actions computed by the clawback vesting accounts are performed in the ante handler. Evmos core, implements two different ante handlers: one for Cosmos transactions and one for Ethereum…

  • CVE-2023-44384MedOct 6, 2023
    risk 0.00cvss 4.1epss 0.00

    Discourse-jira is a Discourse plugin allows Jira projects, issue types, fields and field options will be synced automatically. An administrator user can make an SSRF attack by setting the Jira URL to an arbitrary location and enabling the `discourse_jira_verbose_log` site…