VYPR

CWE-703

Improper Check or Handling of Exceptional Conditions

PillarIncomplete

Description

The product does not properly anticipate or handle exceptional conditions that rarely occur during normal operation of the product.

Hierarchy (View 1000)

CVEs mapped to this weakness (162)

page 6 of 9
  • CVE-2023-21036MedMar 24, 2023
    risk 0.36cvss 5.5epss 0.01

    In BitmapExport.java, there is a possible failure to truncate images due to a logic error in the code.Product: AndroidVersions: Android kernelAndroid ID: A-264261868References: N/A

  • CVE-2023-21026MedMar 24, 2023
    risk 0.36cvss 5.5epss 0.00

    In updateInputChannel of WindowManagerService.java, there is a possible way to set a touchable region beyond its own SurfaceControl due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is…

  • CVE-2026-56818MedAug 7, 2026
    risk 0.35cvss 6.5epss 0.00

    Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the RedisArrayAggregator Redis codec clears retained partial aggregate state when the maxNestedArrayDepth limit is exceeded, but it does not clear the same state when…

  • CVE-2025-65017MedFeb 3, 2026
    risk 0.35cvss 6.5epss 0.00

    Decidim is a participatory democracy framework. In versions from 0.30.0 to before 0.30.4 and from 0.31.0.rc1 to before 0.31.0, the private data exports can lead to data leaks in case the UUID generation, causing collisions for the generated UUIDs. This issue has been patched in…

  • CVE-2025-54134MedJul 21, 2025
    risk 0.35cvss 6.5epss 0.00

    HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.8 and below, the HAX CMS NodeJS application crashes when an authenticated attacker provides an API request lacking required URL parameters. This vulnerability affects the…

  • CVE-2024-26007MedMay 14, 2024
    risk 0.35cvss 5.3epss 0.01

    An improper check or handling of exceptional conditions vulnerability [CWE-703] in Fortinet FortiOS version 7.4.1 allows an unauthenticated attacker to provoke a denial of service on the administrative interface via crafted HTTP requests.

  • CVE-2024-22023MedApr 4, 2024
    risk 0.35cvss 5.3epss 0.03

    An XML entity expansion or XEE vulnerability in SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated attacker to send specially crafted XML requests in-order-to temporarily cause resource exhaustion thereby resulting in a…

  • CVE-2022-31152MedSep 2, 2022
    risk 0.35cvss 6.4epss 0.01

    Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. The Matrix specification specifies a list of [event authorization rules](https://spec.matrix.org/v1.2/rooms/v9/#authorization-rules) which must be checked when determining if an…

  • CVE-2021-25425MedJun 11, 2021
    risk 0.35cvss 5.3epss 0.01

    Improper check vulnerability in Samsung Health prior to version 6.17 allows attacker to read internal cache data via exported component.

  • CVE-2026-1996MedFeb 10, 2026
    risk 0.34cvss 5.3epss 0.00

    Certain HP OfficeJet Pro printers may be vulnerable to potential denial of service when the IPP requests are mishandled, failing to establish a TCP connection.

  • CVE-2025-11594MedOct 11, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been found in ywxbear PHP-Bookstore-Website-Example and PHP Basic BookStore Website up to 0e0b9f542f7a2d90a8d7f8c83caca69294e234e4. This issue affects some unknown processing of the file /index.php of the component Quantity Handler. Such manipulation leads to…

  • CVE-2024-31883MedJun 27, 2024
    risk 0.34cvss 5.3epss 0.01

    IBM Security Verify Access 10.0.0.0 through 10.0.7.1, under certain configurations, could allow an unauthenticated attacker to cause a denial of service due to asymmetric resource consumption. IBM X-Force ID: 287615.

  • CVE-2022-23004MedJul 29, 2022
    risk 0.34cvss 5.3epss 0.01

    When computing a shared secret or point multiplication on the NIST P-256 curve using a public key with an X coordinate of zero, an error is returned from the library, and an invalid unreduced value is written to the output buffer. This may be leveraged by an attacker to cause an…

  • CVE-2022-23003MedJul 29, 2022
    risk 0.34cvss 5.3epss 0.01

    When computing a shared secret or point multiplication on the NIST P-256 curve that results in an X coordinate of zero, the resulting output is not properly reduced modulo the P-256 field prime and is invalid. The resulting output may cause an error when used in other…

  • CVE-2022-23002MedJul 29, 2022
    risk 0.34cvss 5.3epss 0.01

    When compressing or decompressing a point on the NIST P-256 elliptic curve with an X coordinate of zero, the resulting output is not properly reduced modulo the P-256 field prime and is invalid. The resulting output will cause an error when used in other operations. This may be…

  • CVE-2024-37992MedSep 10, 2024
    risk 0.32cvss 4.9epss 0.00

    A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC Reader RF610R FCC (6GT2811-6BC10-1AA0) (All versions < V4.2), SIMATIC Reader RF615R CMIIT…

  • CVE-2024-39945MedJul 31, 2024
    risk 0.32cvss 4.9epss 0.00

    A vulnerability has been found in Dahua products.  After obtaining the administrator's username and password, the attacker can send a carefully crafted data packet to the interface with vulnerabilities, causing the device to crash.

  • CVE-2024-21629MedJan 2, 2024
    risk 0.31cvss 5.9epss 0.01

    Rust EVM is an Ethereum Virtual Machine interpreter. In `rust-evm`, a feature called `record_external_operation` was introduced, allowing library users to record custom gas changes. This feature can have some bogus interactions with the call stack. In particular, during…

  • CVE-2022-39911MedDec 8, 2022
    risk 0.31cvss 4.8epss 0.00

    Improper check or handling of exceptional conditions vulnerability in Samsung Pass prior to version 4.0.06.1 allows attacker to access Samsung Pass.

  • CVE-2021-42205MedNov 7, 2022
    risk 0.31cvss 4.7epss 0.00

    ELAN Miniport touchpad Windows driver before 24.21.51.2, as used in PC hardware from multiple manufacturers, allows local users to cause a system crash by sending a certain IOCTL request, because that request is handled twice.