VYPR

CWE-703

Improper Check or Handling of Exceptional Conditions

PillarIncomplete

Description

The product does not properly anticipate or handle exceptional conditions that rarely occur during normal operation of the product.

Hierarchy (View 1000)

CVEs mapped to this weakness (162)

page 1 of 9
  • CVE-2024-21894CriApr 4, 2024
    risk 0.65cvss 9.8epss 0.19

    A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service thereby causing a DoS attack. In certain conditions this may…

  • CVE-2025-13026CriNov 11, 2025
    risk 0.64cvss 9.8epss 0.00

    Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145.

  • CVE-2025-13023CriNov 11, 2025
    risk 0.64cvss 9.8epss 0.00

    Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145.

  • CVE-2025-13022CriNov 11, 2025
    risk 0.64cvss 9.8epss 0.00

    Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145.

  • CVE-2025-13021CriNov 11, 2025
    risk 0.64cvss 9.8epss 0.00

    Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145.

  • CVE-2021-3329CriFeb 26, 2023
    risk 0.62cvss 9.6epss 0.01

    Lack of proper validation in HCI Host stack initialization can cause a crash of the bluetooth stack

  • CVE-2023-0397CriJan 19, 2023
    risk 0.62cvss 9.6epss 0.00

    A malicious / defect bluetooth controller can cause a Denial of Service due to unchecked input in le_read_buffer_size_complete.

  • CVE-2024-39815CriAug 12, 2024
    risk 0.59cvss 9.1epss 0.01

    Improper check or handling of exceptional conditions vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior, enable an unauthenticated remote attacker to cause a denial of service. A specially-crafted…

  • CVE-2023-45927CriMar 27, 2024
    risk 0.59cvss 9.1epss 0.01

    S-Lang 2.3.2 was discovered to contain an arithmetic exception via the function tt_sprintf().

  • CVE-2021-23859CriDec 8, 2021
    risk 0.59cvss 9.1epss 0.01

    An unauthenticated attacker is able to send a special HTTP request, that causes a service to crash. In case of a standalone VRM or BVMS with VRM installation this crash also opens the possibility to send further unauthenticated commands to the service. On some products the…

  • CVE-2019-5031HigOct 2, 2019
    risk 0.58cvss 8.8epss 0.06

    An exploitable memory corruption vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader, version 9.4.1.16828. A specially crafted PDF document can trigger an out-of-memory condition which isn't handled properly, resulting in arbitrary code execution.…

  • CVE-2026-0011HigMar 2, 2026
    risk 0.55cvss 8.4epss 0.00

    In enableSystemPackageLPw of Settings.java, there is a possible way to prevent location access from working due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2024-21525HigJul 10, 2024
    risk 0.54cvss 8.3epss 0.01

    All versions of the package node-twain are vulnerable to Improper Check or Handling of Exceptional Conditions due to the length of the source data not being checked. Creating a new twain.TwainSDK with a productName or productFamily, manufacturer, version.info property of length…

  • CVE-2024-22053HigApr 4, 2024
    risk 0.54cvss 8.2epss 0.04

    A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service thereby causing a DoS attack or in certain conditions read…

  • CVE-2018-12551HigMar 27, 2019
    risk 0.53cvss 8.1epss 0.01

    When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use a password file for authentication, any malformed data in the password file will be treated as valid. This typically means that the malformed data becomes a username and no password. If this occurs,…

  • CVE-2021-25372MedKEVMar 26, 2021
    risk 0.52cvss 6.1epss 0.01

    An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access.

  • CVE-2021-25370MedKEVMar 26, 2021
    risk 0.52cvss 6.1epss 0.01

    An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel panic.

  • CVE-2024-27832HigJun 10, 2024
    risk 0.51cvss 7.8epss 0.01

    The issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. An app may be able to elevate privileges.

  • CVE-2018-5463HigApr 9, 2018
    risk 0.51cvss 7.8epss 0.00

    A structured exception handler overflow vulnerability in Leao Consultoria e Desenvolvimento de Sistemas (LCDS) LTDA ME LAquis SCADA 4.1.0.3391 and earlier may allow code execution.

  • CVE-2022-20924HigNov 15, 2022
    risk 0.50cvss 7.7epss 0.01

    A vulnerability in the Simple Network Management Protocol (SNMP) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an…