CWE-691
Insufficient Control Flow Management
Description
The code does not sufficiently manage its control flow during execution, creating conditions in which the control flow can be modified in unexpected ways.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-29
CVEs mapped to this weakness (33)
page 2 of 2| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-5102 | Med | 0.34 | 5.3 | 0.01 | Oct 9, 2023 | Insufficient Control Flow Management in RDT400 in SICK APU allows an unprivileged remote attacker to potentially enable hidden functionality via HTTP requests. | ||
| CVE-2022-48481 | Med | 0.34 | 5.2 | 0.00 | Apr 28, 2023 | In JetBrains Toolbox App before 1.28 a DYLIB injection on macOS was possible | ||
| CVE-2022-46828 | Med | 0.34 | 5.2 | 0.00 | Dec 8, 2022 | In JetBrains IntelliJ IDEA before 2022.3 a DYLIB injection on macOS was possible. | ||
| CVE-2022-41646 | Med | 0.31 | 4.7 | 0.00 | May 10, 2023 | Insufficient control flow management in the Intel(R) IPP Cryptography software before version 2021.6 may allow an unauthenticated user to potentially enable information disclosure via local access. | ||
| CVE-2022-37409 | Med | 0.31 | 4.7 | 0.00 | May 10, 2023 | Insufficient control flow management for the Intel(R) IPP Cryptography software before version 2021.6 may allow an authenticated user to potentially enable information disclosure via local access. | ||
| CVE-2022-43505 | Med | 0.27 | 4.1 | 0.00 | Aug 11, 2023 | Insufficient control flow management in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable denial of service via local access. | ||
| CVE-2024-25565 | Low | 0.25 | 3.8 | 0.00 | Nov 13, 2024 | Insufficient control flow management in UEFI firmware for some Intel(R) Xeon(R) Processors may allow an authenticated user to enable denial of service via local access. | ||
| CVE-2022-46299 | Low | 0.21 | 3.3 | 0.00 | Nov 14, 2023 | Insufficient control flow management for some Intel Unison software may allow an authenticated user to potentially enable information disclosure via local access. | ||
| CVE-2025-47774 | Low | 0.12 | — | 0.00 | May 15, 2025 | Vyper is the Pythonic Programming Language for the Ethereum Virtual Machine. In versions up to and including 0.4.2rc1, the `slice()` builtin can elide side effects when the output length is 0, and the source bytestring is a builtin (`msg.data` or `.code`). The reason is… | ||
| CVE-2025-47285 | Low | 0.12 | — | 0.00 | May 15, 2025 | Vyper is the Pythonic Programming Language for the Ethereum Virtual Machine. In versions up to and including 0.4.2rc1, `concat()` may skip evaluation of side effects when the length of an argument is zero. This is due to a fastpath in the implementation which skips evaluation of… | ||
| CVE-2025-25774 | Med | 0.00 | 6.5 | 0.00 | Mar 12, 2025 | An issue was discovered in Open5GS v2.7.2. When a UE switches between two gNBs and sends a handover request at a specific time, it may cause an exception in the AMF's internal state machine, leading to an AMF crash and resulting in a Denial of Service (DoS). | ||
| CVE-2024-37158 | Low | 0.00 | 3.5 | 0.00 | Jun 17, 2024 | Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. Preliminary checks on actions computed by the clawback vesting accounts are performed in the ante handler. Evmos core, implements two different ante handlers: one for Cosmos transactions and one for Ethereum… | ||
| CVE-2023-44384 | Med | 0.00 | 4.1 | 0.00 | Oct 6, 2023 | Discourse-jira is a Discourse plugin allows Jira projects, issue types, fields and field options will be synced automatically. An administrator user can make an SSRF attack by setting the Jira URL to an arbitrary location and enabling the `discourse_jira_verbose_log` site… |
- risk 0.34cvss 5.3epss 0.01
Insufficient Control Flow Management in RDT400 in SICK APU allows an unprivileged remote attacker to potentially enable hidden functionality via HTTP requests.
- risk 0.34cvss 5.2epss 0.00
In JetBrains Toolbox App before 1.28 a DYLIB injection on macOS was possible
- risk 0.34cvss 5.2epss 0.00
In JetBrains IntelliJ IDEA before 2022.3 a DYLIB injection on macOS was possible.
- risk 0.31cvss 4.7epss 0.00
Insufficient control flow management in the Intel(R) IPP Cryptography software before version 2021.6 may allow an unauthenticated user to potentially enable information disclosure via local access.
- risk 0.31cvss 4.7epss 0.00
Insufficient control flow management for the Intel(R) IPP Cryptography software before version 2021.6 may allow an authenticated user to potentially enable information disclosure via local access.
- risk 0.27cvss 4.1epss 0.00
Insufficient control flow management in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable denial of service via local access.
- risk 0.25cvss 3.8epss 0.00
Insufficient control flow management in UEFI firmware for some Intel(R) Xeon(R) Processors may allow an authenticated user to enable denial of service via local access.
- risk 0.21cvss 3.3epss 0.00
Insufficient control flow management for some Intel Unison software may allow an authenticated user to potentially enable information disclosure via local access.
- risk 0.12cvss —epss 0.00
Vyper is the Pythonic Programming Language for the Ethereum Virtual Machine. In versions up to and including 0.4.2rc1, the `slice()` builtin can elide side effects when the output length is 0, and the source bytestring is a builtin (`msg.data` or `.code`). The reason is…
- risk 0.12cvss —epss 0.00
Vyper is the Pythonic Programming Language for the Ethereum Virtual Machine. In versions up to and including 0.4.2rc1, `concat()` may skip evaluation of side effects when the length of an argument is zero. This is due to a fastpath in the implementation which skips evaluation of…
- risk 0.00cvss 6.5epss 0.00
An issue was discovered in Open5GS v2.7.2. When a UE switches between two gNBs and sends a handover request at a specific time, it may cause an exception in the AMF's internal state machine, leading to an AMF crash and resulting in a Denial of Service (DoS).
- risk 0.00cvss 3.5epss 0.00
Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. Preliminary checks on actions computed by the clawback vesting accounts are performed in the ante handler. Evmos core, implements two different ante handlers: one for Cosmos transactions and one for Ethereum…
- risk 0.00cvss 4.1epss 0.00
Discourse-jira is a Discourse plugin allows Jira projects, issue types, fields and field options will be synced automatically. An administrator user can make an SSRF attack by setting the Jira URL to an arbitrary location and enabling the `discourse_jira_verbose_log` site…