VYPR

CWE-703

Improper Check or Handling of Exceptional Conditions

PillarIncomplete

Description

The product does not properly anticipate or handle exceptional conditions that rarely occur during normal operation of the product.

Hierarchy (View 1000)

CVEs mapped to this weakness (162)

page 8 of 9
  • CVE-2021-25366LowMar 25, 2021
    risk 0.21cvss 3.2epss 0.00

    Improper access control in Samsung Internet prior to version 13.2.1.70 allows physically proximate attackers to bypass the secret mode's authentication.

  • CVE-2023-29195MedMay 11, 2023
    risk 0.20cvss 4.1epss 0.01

    Vitess is a database clustering system for horizontal scaling of MySQL through generalized sharding. Prior to version 16.0.2, users can either intentionally or inadvertently create a shard containing `/` characters from VTAdmin such that from that point on, anyone who tries to…

  • CVE-2023-29194MedApr 14, 2023
    risk 0.20cvss 4.1epss 0.01

    Vitess is a database clustering system for horizontal scaling of MySQL. Users can either intentionally or inadvertently create a keyspace containing `/` characters such that from that point on, anyone who tries to view keyspaces from VTAdmin will receive an error. Trying to list…

  • CVE-2024-37995LowSep 10, 2024
    risk 0.18cvss 2.7epss 0.00

    A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC Reader RF610R FCC (6GT2811-6BC10-1AA0) (All versions < V4.2), SIMATIC Reader RF615R CMIIT…

  • CVE-2022-21164LowMar 16, 2022
    risk 0.17cvss 3.7epss 0.01

    The package node-lmdb before 0.9.7 are vulnerable to Denial of Service (DoS) when defining a non-invokable ToString value, which will cause a crash during type check.

  • CVE-2021-25409LowJun 11, 2021
    risk 0.16cvss 2.4epss 0.00

    Improper access in Notification setting prior to SMR JUN-2021 Release 1 allows physically proximate attackers to set arbitrary notification via physically configuring device.

  • CVE-2021-25335LowMar 4, 2021
    risk 0.16cvss 2.5epss 0.00

    Improper lockscreen status check in cocktailbar service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows unauthenticated users to access hidden notification contents over the lockscreen in specific condition.

  • CVE-2024-51491LowJan 13, 2025
    risk 0.14cvss 3.3epss 0.00

    notion-go is a collection of libraries for supporting sign and verify OCI artifacts. Based on Notary Project specifications. The issue was identified during Quarkslab's security audit on the Certificate Revocation List (CRL) based revocation check feature. After retrieving the…

  • CVE-2021-25348LowMar 4, 2021
    risk 0.14cvss 2.1epss 0.00

    Improper permission grant check in Samsung Internet prior to version 13.0.1.60 allows access to files in internal storage without authorized STORAGE permission.

  • CVE-2021-25525LowDec 8, 2021
    risk 0.13cvss 2.0epss 0.00

    Improper check or handling of exception conditions vulnerability in Samsung Pay (US only) prior to version 4.0.65 allows attacker to use NFC without user recognition.

  • CVE-2026-38763MedJul 22, 2026
    risk 0.00cvss 5.5epss 0.00

    An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to cause a denial of service via the function sub_13828

  • CVE-2026-16218LowJul 19, 2026
    risk 0.00cvss 2.6epss 0.00

    A vulnerability was detected in hunvreus devpush up to 0.4.6. Affected by this issue is the function reset_storage of the file app/workers/tasks/storage.py of the component Storage Reset Failure Handler. The manipulation results in improper check or handling of exceptional…

  • CVE-2026-51600HigJul 9, 2026
    risk 0.00cvss 7.5epss 0.00

    Tenda CP3 V3.0 firmware V31.1.9.91 does not validate the Content-Length header field in RTSP requests (including DESCRIBE, SETUP, and PLAY methods). When a request carrying a Content-Length header is received without a corresponding message body, the RTSP parser enters a…

  • CVE-2026-31794MedMar 10, 2026
    risk 0.00cvss 5.5epss 0.00

    iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a segmentation fault from invalid/wild pointer read in CIccCLUT::Interp3d() causing a denial of service. This vulnerability is fixed in 2.3.1.5.

  • CVE-2026-31793MedMar 10, 2026
    risk 0.00cvss 5.5epss 0.00

    iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a segmentation fault due to invalid/wild pointer read in CIccCalculatorFunc::ApplySequence() causing denial of service. This vulnerability is fixed in 2.3.1.5.

  • CVE-2026-21493MedJan 6, 2026
    risk 0.00cvss 6.6epss 0.00

    iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below are vulnerable to Type Confusion in its CIccSingleSampledeCurveXml class during XML Curve Serialization. This issue is fixed in version 2.3.1.2.

  • CVE-2025-61602HigOct 9, 2025
    risk 0.00cvss 7.5epss 0.00

    BigBlueButton is an open-source virtual classroom. A denial-of-service (DoS) vulnerability in versions prior to 3.0.13 allows any authenticated user to crash the chat functionality for all participants in a meeting by sending a malformed `reactionEmojiId` in the GraphQL mutation…

  • CVE-2025-61601HigOct 9, 2025
    risk 0.00cvss 7.5epss 0.00

    BigBlueButton is an open-source virtual classroom. A Denial of Service (DoS) vulnerability in versions prior to 3.0.13 allows any authenticated user to freeze or crash the entire server by abusing the polling feature's `Choices` response type. By submitting a malicious payload…

  • CVE-2023-51443HigDec 27, 2023
    risk 0.00cvss 7.5epss 0.01

    FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.10.11, when handling DTLS-SRTP for media setup, FreeSWITCH is susceptible to…

  • CVE-2023-49786HigDec 14, 2023
    risk 0.00cvss 7.5epss 0.05

    Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk prior to versions 18.20.1, 20.5.1, and 21.0.1; as well as certified-asterisk prior to 18.9-cert6; Asterisk is susceptible to a DoS due to a race condition in the hello handshake phase of the…