VYPR

CWE-754

Improper Check for Unusual or Exceptional Conditions

ClassIncompleteLikelihood: Medium

Description

The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.

Hierarchy (View 1000)

CVEs mapped to this weakness (632)

page 15 of 32
  • CVE-2024-21603MedJan 12, 2024
    risk 0.42cvss 6.5epss 0.01

    An Improper Check for Unusual or Exceptional Conditions vulnerability in the kernel of Juniper Network Junos OS on MX Series allows a network based attacker with low privileges to cause a denial of service. If a scaled configuration for Source class usage (SCU) / destination…

  • CVE-2023-22290MedNov 14, 2023
    risk 0.42cvss 6.5epss 0.01

    Uncaught exception for some Intel Unison software may allow an authenticated user to potentially enable denial of service via network access.

  • CVE-2023-45812HigOct 18, 2023
    risk 0.42cvss 7.5epss 0.01

    The Apollo Router is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation. Affected versions are subject to a Denial-of-Service (DoS) type vulnerability which causes the Router to panic and terminate when a…

  • CVE-2023-44196MedOct 13, 2023
    risk 0.42cvss 6.5epss 0.00

    An Improper Check for Unusual or Exceptional Conditions in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS Evolved on PTX10003 Series allows an unauthenticated adjacent attacker to cause an impact to the integrity of the system. When specific transit MPLS…

  • CVE-2023-4828MedSep 13, 2023
    risk 0.42cvss 6.4epss 0.00

    An improper check for an exceptional condition in the Insider Threat Management (ITM) Server could be used by an attacker to change the server's configuration of any already-registered agent so that the agent sends all future communications to an attacker-chosen URL. This could…

  • CVE-2022-25024HigAug 22, 2023
    risk 0.42cvss 7.5epss 0.01

    The json2xml package through 3.12.0 for Python allows an error in typecode decoding enabling a remote attack that can lead to an exception, causing a denial of service.

  • CVE-2023-21405MedJul 25, 2023
    risk 0.42cvss 6.5epss 0.00

    Knud from Fraktal.fi has found a flaw in some Axis Network Door Controllers and Axis Network Intercoms when communicating over OSDP, highlighting that the OSDP message parser crashes the pacsiod process, causing a temporary unavailability of the door-controlling functionalities…

  • CVE-2023-37899HigJul 19, 2023
    risk 0.42cvss 7.5epss 0.01

    Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. Feathers socket handler did not catch invalid string conversion errors like `const message = ${{ toString: '' }}` which would cause the NodeJS process to crash when sending…

  • CVE-2023-23602MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.01

    A mishandled security check when creating a WebSocket in a WebWorker caused the Content Security Policy connect-src header to be ignored. This could lead to connections to restricted origins from inside WebWorkers. This vulnerability affects Firefox < 109, Firefox ESR < 102.7,…

  • CVE-2023-32716MedJun 1, 2023
    risk 0.42cvss 6.5epss 0.01

    In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform versions below 9.0.2303.100, an attacker can exploit a vulnerability in the {{dump}} SPL command to cause a denial of service by crashing the Splunk daemon.

  • CVE-2023-25620MedApr 19, 2023
    risk 0.42cvss 6.5epss 0.01

    A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause denial of service of the controller when a malicious project file is loaded onto the controller by an authenticated user.

  • CVE-2023-28965MedApr 17, 2023
    risk 0.42cvss 6.5epss 0.01

    An Improper Check or Handling of Exceptional Conditions within the storm control feature of Juniper Networks Junos OS allows an attacker sending a high rate of traffic to cause a Denial of Service. Continued receipt and processing of these packets will create a sustained Denial…

  • CVE-2022-32749HigDec 19, 2022
    risk 0.42cvss 7.5epss 0.01

    Improper Check for Unusual or Exceptional Conditions vulnerability handling requests in Apache Traffic Server allows an attacker to crash the server under certain conditions. This issue affects Apache Traffic Server: from 8.0.0 through 9.1.3.

  • CVE-2022-35473MedAug 16, 2022
    risk 0.42cvss 6.5epss 0.01

    OTFCC v0.10.4 was discovered to contain a segmentation violation via /release-x64/otfccdump+0x4fe9a7.

  • CVE-2022-35469MedAug 16, 2022
    risk 0.42cvss 6.5epss 0.01

    OTFCC v0.10.4 was discovered to contain a segmentation violation via /x86_64-linux-gnu/libc.so.6+0xbb384.

  • CVE-2022-31103HigJun 27, 2022
    risk 0.42cvss 7.5epss 0.01

    lettersanitizer is a DOM-based HTML email sanitizer for in-browser email rendering. All versions of lettersanitizer below 1.0.2 are affected by a denial of service issue when processing a CSS at-rule `@keyframes`. This package is depended on by…

  • CVE-2022-31093HigJun 27, 2022
    risk 0.42cvss 7.5epss 0.02

    NextAuth.js is a complete open source authentication solution for Next.js applications. In affected versions an attacker can send a request to an app using NextAuth.js with an invalid `callbackUrl` query parameter, which internally is converted to a `URL` object. The URL…

  • CVE-2022-22196MedApr 14, 2022
    risk 0.42cvss 6.5epss 0.00

    An Improper Check for Unusual or Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker with an established ISIS adjacency to cause a Denial of Service (DoS). The…

  • CVE-2022-21676HigJan 12, 2022
    risk 0.42cvss 7.5epss 0.03

    Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Socket.IO. A specially crafted HTTP request can trigger an uncaught exception on the Engine.IO server, thus killing the Node.js process. This impacts all the…

  • CVE-2021-25481MedOct 6, 2021
    risk 0.42cvss 6.4epss 0.00

    An improper error handling in Exynos CP booting driver prior to SMR Oct-2021 Release 1 allows local attackers to bypass a Secure Memory Protector of Exynos CP Memory.