VYPR

CWE-754

Improper Check for Unusual or Exceptional Conditions

ClassIncompleteLikelihood: Medium

Description

The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.

Hierarchy (View 1000)

CVEs mapped to this weakness (651)

page 18 of 33
  • CVE-2019-5673MedApr 11, 2019
    risk 0.40cvss 6.1epss 0.00

    NVIDIA Jetson TX2 contains a vulnerability in the kernel driver (on all versions prior to R28.3) where the ARM System Memory Management Unit (SMMU) improperly checks for a fault condition, causing transactions to be discarded, which may lead to denial of service.

  • CVE-2025-9998MedSep 5, 2025
    risk 0.39cvss —epss 0.00

    The sequence of packets received by a Networking server are not correctly checked. An attacker could exploit this vulnerability to send specially crafted messages to force the application to stop.

  • CVE-2024-25122HigFeb 13, 2024
    risk 0.39cvss 7.1epss 0.01

    sidekiq-unique-jobs is an open source project which prevents simultaneous Sidekiq jobs with the same unique arguments to run. Specially crafted GET request parameters handled by any of the following endpoints of sidekiq-unique-jobs' "admin" web UI, allow a super-user attacker,…

  • CVE-2023-29198MedSep 6, 2023
    risk 0.39cvss 6.0epss 0.01

    Electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Electron apps using `contextIsolation` and `contextBridge` are affected. This is a context isolation bypass, meaning that code running in the main world context in…

  • CVE-2022-36794MedFeb 16, 2023
    risk 0.39cvss 6.0epss 0.00

    Improper condition check in some Intel(R) SPS firmware before version SPS_E3_06.00.03.300.0 may allow a privileged user to potentially enable denial of service via local access.

  • CVE-2022-26079MedNov 11, 2022
    risk 0.39cvss 6.0epss 0.00

    Improper conditions check in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2020-7453MedApr 29, 2020
    risk 0.39cvss 6.0epss 0.00

    In FreeBSD 12.1-STABLE before r359021, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r359020, and 11.3-RELEASE before 11.3-RELEASE-p7, a missing null termination check in the jail_set configuration option "osrelease" may return more bytes with a subsequent jail_get…

  • CVE-2019-11139MedNov 14, 2019
    risk 0.39cvss 6.0epss 0.00

    Improper conditions check in the voltage modulation interface for some Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potentially enable denial of service via local access.

  • CVE-2018-7287MedFeb 22, 2018
    risk 0.39cvss 5.9epss 0.11

    An issue was discovered in res_http_websocket.c in Asterisk 15.x through 15.2.1. If the HTTP server is enabled (default is disabled), WebSocket payloads of size 0 are mishandled (with a busy loop).

  • CVE-2025-60011MedJan 15, 2026
    risk 0.38cvss 5.8epss 0.00

    An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause an availability impact for downstream devices. When an…

  • CVE-2025-58289MedOct 11, 2025
    risk 0.38cvss 5.9epss 0.00

    Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-58354MedSep 23, 2025
    risk 0.38cvss —epss 0.00

    Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. In Kata Containers versions from 3.20.0 and before, a malicious host can circumvent initdata verification. On TDX systems running…

  • CVE-2025-8716MedSep 11, 2025
    risk 0.38cvss —epss 0.00

    In Content Management versions 20.4- 25.3 authenticated attackers may exploit a complex cache poisoning technique to download unprotected files from the server if the filenames are known.

  • CVE-2025-54463MedAug 11, 2025
    risk 0.38cvss 5.9epss 0.00

    Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to server webhook endpoint with an invalid request body.

  • CVE-2025-53514MedAug 11, 2025
    risk 0.38cvss 5.9epss 0.00

    Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to server webhook endpoint with an invalid request body.

  • CVE-2025-54427MedJul 28, 2025
    risk 0.38cvss —epss 0.01

    Polkadot Frontier is an Ethereum and EVM compatibility layer for Polkadot and Substrate. The extrinsic note_min_gas_price_target is an inherent extrinsic, meaning only the block producer can call it. To ensure correctness, the ProvideInherent trait should be implemented for each…

  • CVE-2025-53638MedJul 17, 2025
    risk 0.38cvss —epss 0.00

    Solady is software that provides Solidity snippets with APIs. Starting in version 0.0.125 and prior to version 0.1.24, when an account is deployed via a proxy, using regular Solidity to call its initialization function may result in a silent failure, if the initialization…

  • CVE-2025-53359MedJul 2, 2025
    risk 0.38cvss —epss 0.00

    ethereum is a common ethereum structs for Rust. Prior to ethereum crate v0.18.0, signature malleability (according to EIP-2) was only checked for "legacy" transactions, but not for EIP-2930, EIP-1559 and EIP-7702 transactions. This is a specification deviation. The signature…

  • CVE-2025-32051MedApr 3, 2025
    risk 0.38cvss 5.9epss 0.01

    A flaw was found in libsoup. The libsoup soup_uri_decode_data_uri() function may crash when processing malformed data URI. This flaw allows an attacker to cause a denial of service (DoS).

  • CVE-2024-45085MedOct 15, 2024
    risk 0.38cvss 5.9epss 0.01

    IBM WebSphere Application Server 8.5 is vulnerable to a denial of service, under certain configurations, caused by an unexpected specially crafted request. A remote attacker could exploit this vulnerability to cause an error resulting in a denial of service.