VYPR

CWE-697

Incorrect Comparison

PillarIncomplete

Description

The product compares two entities in a security-relevant context, but the comparison is incorrect.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-120 · CAPEC-14 · CAPEC-15 · CAPEC-182 · CAPEC-24 · CAPEC-267 · CAPEC-3 · CAPEC-41 · CAPEC-43 · CAPEC-44 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-52 · CAPEC-53 · CAPEC-6 · CAPEC-64 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-88 · CAPEC-9 · CAPEC-92

CVEs mapped to this weakness (177)

page 5 of 9
  • CVE-2022-22203MedJul 20, 2022
    risk 0.42cvss 6.5epss 0.01

    An Incorrect Comparison vulnerability in PFE of Juniper Networks Junos OS allows an adjacent unauthenticated attacker to cause a Denial of Service (DoS). On QFX5000 Series, and EX4600 and EX4650 platforms, the fxpc process will crash followed by the FPC reboot upon receipt of a…

  • CVE-2021-41500HigDec 17, 2021
    risk 0.42cvss 7.5epss 0.01

    Incomplete string comparison vulnerability exits in cvxopt.org cvxop <= 1.2.6 in APIs (cvxopt.cholmod.diag, cvxopt.cholmod.getfactor, cvxopt.cholmod.solve, cvxopt.cholmod.spsolve), which allows attackers to conduct Denial of Service attacks by construct fake Capsule objects.

  • CVE-2021-42836HigOct 22, 2021
    risk 0.42cvss 7.5epss 0.02

    GJSON before 1.9.3 allows a ReDoS (regular expression denial of service) attack.

  • CVE-2021-3828HigSep 27, 2021
    risk 0.42cvss 7.5epss 0.02

    nltk is vulnerable to Inefficient Regular Expression Complexity

  • CVE-2021-3822HigSep 27, 2021
    risk 0.42cvss 7.5epss 0.01

    jsoneditor is vulnerable to Inefficient Regular Expression Complexity

  • CVE-2020-23478HigSep 22, 2021
    risk 0.42cvss 7.5epss 0.01

    Leo Editor v6.2.1 was discovered to contain a regular expression denial of service (ReDoS) vulnerability in the component plugins/importers/dart.py.

  • CVE-2021-39514MedSep 20, 2021
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in libjpeg through 2020021. An uncaught floating point exception in the function ACLosslessScan::ParseMCU() located in aclosslessscan.cpp. It allows an attacker to cause Denial of Service.

  • CVE-2021-3807HigSep 17, 2021
    risk 0.42cvss 7.5epss 0.04

    ansi-regex is vulnerable to Inefficient Regular Expression Complexity

  • CVE-2021-3794HigSep 15, 2021
    risk 0.42cvss 7.5epss 0.01

    vuelidate is vulnerable to Inefficient Regular Expression Complexity

  • CVE-2021-27293HigJul 12, 2021
    risk 0.42cvss 7.5epss 0.02

    RestSharp < 106.11.8-alpha.0.13 uses a regular expression which is vulnerable to Regular Expression Denial of Service (ReDoS) when converting strings into DateTimes. If a server responds with a malicious string, the client using RestSharp will be stuck processing it for an…

  • CVE-2020-1920HigJun 1, 2021
    risk 0.42cvss 7.5epss 0.01

    A regular expression denial of service (ReDoS) vulnerability in the validateBaseUrl function can cause the application to use excessive resources, become unresponsive, or crash. This was introduced in react-native version 0.59.0 and fixed in version 0.64.1.

  • CVE-2021-3116HigJan 11, 2021
    risk 0.42cvss 7.5epss 0.02

    before_upstream_connection in AuthPlugin in http/proxy/auth.py in proxy.py before 2.3.1 accepts incorrect Proxy-Authorization header data because of a boolean confusion (and versus or).

  • CVE-2019-20925HigNov 24, 2020
    risk 0.42cvss 7.5epss 0.02

    An unauthenticated client can trigger denial of service by issuing specially crafted wire protocol messages, which cause the message decompressor to incorrectly allocate memory. This issue affects MongoDB Server v4.2 versions prior to 4.2.1; MongoDB Server v4.0 versions prior to…

  • CVE-2020-15131HigJul 30, 2020
    risk 0.42cvss 7.5epss 0.01

    In SLP Validate (npm package slp-validate) before version 1.2.2, there is a vulnerability to false-positive validation outcomes for the NFT1 Child Genesis transaction type. A poorly implemented SLP wallet or opportunistic attacker could create a seemingly valid NFT1 child token…

  • CVE-2020-15130HigJul 30, 2020
    risk 0.42cvss 7.5epss 0.01

    In SLPJS (npm package slpjs) before version 0.27.4, there is a vulnerability to false-positive validation outcomes for the NFT1 Child Genesis transaction type. A poorly implemented SLP wallet or opportunistic attacker could create a seemingly valid NFT1 child token without…

  • CVE-2023-32627MedJul 10, 2023
    risk 0.40cvss 6.2epss 0.00

    A floating point exception vulnerability was found in sox, in the read_samples function at sox/src/voc.c:334:18. This flaw can lead to a denial of service.

  • CVE-2023-26590MedJul 10, 2023
    risk 0.40cvss 6.2epss 0.00

    A floating point exception vulnerability was found in sox, in the lsx_aiffstartwrite function at sox/src/aiff.c:622:58. This flaw can lead to a denial of service.

  • CVE-2021-1904MedSep 8, 2021
    risk 0.40cvss 6.2epss 0.01

    Child process can leak information from parent process due to numeric pids are getting compared and these pid can be reused in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice &…

  • CVE-2021-0295MedJul 15, 2021
    risk 0.40cvss 6.1epss 0.01

    A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) of Juniper Networks Junos OS on the QFX10K Series switches allows an attacker to trigger a packet forwarding loop, leading to a partial Denial of Service (DoS). The issue is caused by DVMRP packets looping…

  • CVE-2023-44378HigOct 9, 2023
    risk 0.39cvss 7.1epss 0.00

    gnark is a zk-SNARK library that offers a high-level API to design circuits. Prior to version 0.9.0, for some in-circuit values, it is possible to construct two valid decomposition to bits. In addition to the canonical decomposition of `a`, for small values there exists a second…