VYPR

CWE-754

Improper Check for Unusual or Exceptional Conditions

ClassIncompleteLikelihood: Medium

Description

The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.

Hierarchy (View 1000)

CVEs mapped to this weakness (632)

page 17 of 32
  • CVE-2023-32695HigMay 27, 2023
    risk 0.41cvss 7.3epss 0.01

    socket.io parser is a socket.io encoder and decoder written in JavaScript complying with version 5 of socket.io-protocol. A specially crafted Socket.IO packet can trigger an uncaught exception on the Socket.IO server, thus killing the Node.js process. A patch has been released…

  • CVE-2025-11925MedOct 17, 2025
    risk 0.40cvss 6.1epss 0.00

    Incorrect Content-Type header in one of the APIs (`text/html` instead of `application/json`) replies may potentially allow injection of HTML/JavaScript into reply.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

  • CVE-2025-55035MedOct 16, 2025
    risk 0.40cvss 6.1epss 0.00

    Mattermost Desktop App versions <=5.13.0 fail to manage modals in the Mattermost Desktop App that stops a user with a server that uses basic authentication from accessing their server which allows an attacker that provides a malicious server to the user to deny use of the…

  • CVE-2024-10635MedApr 28, 2025
    risk 0.40cvss 6.1epss 0.00

    Enterprise Protection contains an improper input validation vulnerability in attachment defense that allows an unauthenticated remote attacker to bypass attachment scanning security policy by sending a malicious S/MIME attachment with an opaque signature. When opened by a…

  • CVE-2025-3359MedApr 7, 2025
    risk 0.40cvss 6.2epss 0.00

    A flaw was found in GNUPlot. A segmentation fault via IO_str_init_static_internal may jeopardize the environment.

  • CVE-2024-20506MedSep 4, 2024
    risk 0.40cvss 6.1epss 0.00

    A vulnerability in the ClamD service module of Clam AntiVirus (ClamAV) versions 1.4.0, 1.3.2 and prior versions, all 1.2.x versions, 1.0.6 and prior versions, all 0.105.x versions, all 0.104.x versions, and 0.103.11 and all prior versions could allow an authenticated, local…

  • CVE-2024-35313HigMay 17, 2024
    risk 0.40cvss 7.3epss 0.00

    In Tor Arti before 1.2.3, circuits sometimes incorrectly have a length of 3 (with full vanguards), aka TROVE-2024-004.

  • CVE-2022-22217MedJul 20, 2022
    risk 0.40cvss 6.1epss 0.00

    An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an adjacent unauthenticated attacker to cause a Denial of Service (DoS). The issue is caused by malformed MLD packets looping on a…

  • CVE-2020-8334MedJun 9, 2020
    risk 0.40cvss 6.1epss 0.00

    The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T495s, X395, T495, A485, A285, A475, A275 which may allow for unauthorized access.

  • CVE-2019-5673MedApr 11, 2019
    risk 0.40cvss 6.1epss 0.00

    NVIDIA Jetson TX2 contains a vulnerability in the kernel driver (on all versions prior to R28.3) where the ARM System Memory Management Unit (SMMU) improperly checks for a fault condition, causing transactions to be discarded, which may lead to denial of service.

  • CVE-2025-9998MedSep 5, 2025
    risk 0.39cvss epss 0.00

    The sequence of packets received by a Networking server are not correctly checked. An attacker could exploit this vulnerability to send specially crafted messages to force the application to stop.

  • CVE-2024-25122HigFeb 13, 2024
    risk 0.39cvss 7.1epss 0.01

    sidekiq-unique-jobs is an open source project which prevents simultaneous Sidekiq jobs with the same unique arguments to run. Specially crafted GET request parameters handled by any of the following endpoints of sidekiq-unique-jobs' "admin" web UI, allow a super-user attacker,…

  • CVE-2023-29198MedSep 6, 2023
    risk 0.39cvss 6.0epss 0.00

    Electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Electron apps using `contextIsolation` and `contextBridge` are affected. This is a context isolation bypass, meaning that code running in the main world context in…

  • CVE-2022-36794MedFeb 16, 2023
    risk 0.39cvss 6.0epss 0.00

    Improper condition check in some Intel(R) SPS firmware before version SPS_E3_06.00.03.300.0 may allow a privileged user to potentially enable denial of service via local access.

  • CVE-2022-26079MedNov 11, 2022
    risk 0.39cvss 6.0epss 0.00

    Improper conditions check in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2020-7453MedApr 29, 2020
    risk 0.39cvss 6.0epss 0.00

    In FreeBSD 12.1-STABLE before r359021, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r359020, and 11.3-RELEASE before 11.3-RELEASE-p7, a missing null termination check in the jail_set configuration option "osrelease" may return more bytes with a subsequent jail_get…

  • CVE-2019-11139MedNov 14, 2019
    risk 0.39cvss 6.0epss 0.00

    Improper conditions check in the voltage modulation interface for some Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potentially enable denial of service via local access.

  • CVE-2018-7287MedFeb 22, 2018
    risk 0.39cvss 5.9epss 0.11

    An issue was discovered in res_http_websocket.c in Asterisk 15.x through 15.2.1. If the HTTP server is enabled (default is disabled), WebSocket payloads of size 0 are mishandled (with a busy loop).

  • CVE-2025-60011MedJan 15, 2026
    risk 0.38cvss 5.8epss 0.00

    An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause an availability impact for downstream devices. When an…

  • CVE-2025-58289MedOct 11, 2025
    risk 0.38cvss 5.9epss 0.00

    Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affect availability.