VYPR

CWE-755

Improper Handling of Exceptional Conditions

ClassIncompleteLikelihood: Medium

Description

The product does not handle or incorrectly handles an exceptional condition.

Hierarchy (View 1000)

CVEs mapped to this weakness (596)

page 29 of 30
  • CVE-2024-8376HigOct 11, 2024
    risk 0.00cvss 7.5epss 0.01

    In Eclipse Mosquitto up to version 2.0.18a, an attacker can achieve memory leaking, segmentation fault or heap-use-after-free by sending specific sequences of "CONNECT", "DISCONNECT", "SUBSCRIBE", "UNSUBSCRIBE" and "PUBLISH" packets.

  • CVE-2024-3150HigJun 6, 2024
    risk 0.00cvss 8.8epss 0.01

    In mintplex-labs/anything-llm, a vulnerability exists in the thread update process that allows users with Default or Manager roles to escalate their privileges to Administrator. The issue arises from improper input validation when handling HTTP POST requests to the endpoint…

  • CVE-2024-3152HigJun 6, 2024
    risk 0.00cvss 8.8epss 0.01

    mintplex-labs/anything-llm is vulnerable to multiple security issues due to improper input validation in several endpoints. An attacker can exploit these vulnerabilities to escalate privileges from a default user role to an admin role, read and delete arbitrary files on the…

  • CVE-2024-23325HigFeb 9, 2024
    risk 0.00cvss 7.5epss 0.01

    Envoy is a high-performance edge/middle/service proxy. Envoy crashes in Proxy protocol when using an address type that isn’t supported by the OS. Envoy is susceptible to crashing on a host with IPv6 disabled and a listener config with proxy protocol enabled when it receives a…

  • CVE-2022-48619MedJan 12, 2024
    risk 0.00cvss 5.5epss 0.00

    An issue was discovered in drivers/input/input.c in the Linux kernel before 5.17.10. An attacker can cause a denial of service (panic) because input_set_capability mishandles the situation in which an event code falls outside of a bitmap.

  • CVE-2023-50019MedJan 2, 2024
    risk 0.00cvss 5.9epss 0.01

    An issue was discovered in open5gs v2.6.6. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handling of Nudm_UECM_Registration response.

  • CVE-2023-38406CriNov 6, 2023
    risk 0.00cvss 9.8epss 0.01

    bgpd/bgp_flowspec.c in FRRouting (FRR) before 8.4.3 mishandles an nlri length of zero, aka a "flowspec overflow."

  • CVE-2023-44488HigSep 30, 2023
    risk 0.00cvss 7.5epss 0.02

    VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding.

  • CVE-2023-4540HigSep 5, 2023
    risk 0.00cvss 7.5epss 0.01

    Improper Handling of Exceptional Conditions vulnerability in Daurnimator lua-http library allows Excessive Allocation and a denial of service (DoS) attack to be executed by sending a properly crafted request to the server. Such a request causes the program to enter an infinite…

  • CVE-2023-40184LowAug 30, 2023
    risk 0.00cvss 2.6epss 0.01

    xrdp is an open source remote desktop protocol (RDP) server. In versions prior to 0.9.23 improper handling of session establishment errors allows bypassing OS-level session restrictions. The `auth_start_session` function can return non-zero (1) value on, e.g., PAM error which…

  • CVE-2022-47933MedDec 24, 2022
    risk 0.00cvss 6.5epss 0.01

    Brave Browser before 1.42.51 allowed a remote attacker to cause a denial of service via a crafted HTML file that references the IPFS scheme. This vulnerability is caused by an uncaught exception in the function ipfs::OnBeforeURLRequest_IPFSRedirectWork() in…

  • CVE-2022-23495HigDec 8, 2022
    risk 0.00cvss 7.5epss 0.01

    go-merkledag implements the 'DAGService' interface and adds two ipld node types, Protobuf and Raw for the ipfs project. A `ProtoNode` may be modified in such a way as to cause various encode errors which will trigger a panic on common method calls that don't allow for error…

  • CVE-2022-41917MedNov 16, 2022
    risk 0.00cvss 4.3epss 0.01

    OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana. OpenSearch allows users to specify a local file when defining text analyzers to process data for text analysis. An issue in the implementation of this feature allows certain specially crafted queries…

  • CVE-2022-32264HigSep 6, 2022
    risk 0.00cvss 7.5epss 0.01

    sys/netinet/tcp_timer.h in FreeBSD before 7.0 contains a denial-of-service (DoS) vulnerability due to improper handling of TSopt on TCP connections. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

  • CVE-2022-34641MedJul 18, 2022
    risk 0.00cvss 5.5epss 0.00

    CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a and RISCV-Boom commit ad64c5419151e5e886daee7084d8399713b46b4b implements the incorrect exception type when a PMP violation occurs during address translation.

  • CVE-2022-34639MedJul 18, 2022
    risk 0.00cvss 5.5epss 0.00

    CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a treats non-standard fence instructions as illegal which can affect the function of the application.

  • CVE-2022-34634MedJul 18, 2022
    risk 0.00cvss 5.5epss 0.00

    CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a executes crafted or incorrectly formatted det instructions rather create an exception.

  • CVE-2022-34633MedJul 18, 2022
    risk 0.00cvss 5.5epss 0.00

    CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a executes crafted or incorrectly formatted sfence.vma instructions rather create an exception.

  • CVE-2022-24448LowFeb 4, 2022
    risk 0.00cvss 3.3epss 0.00

    An issue was discovered in fs/nfs/dir.c in the Linux kernel before 5.16.5. If an application sets the O_DIRECTORY flag, and tries to open a regular file, nfs_atomic_open() performs a regular lookup. If a regular file is found, ENOTDIR should occur, but the server instead returns…

  • CVE-2021-43827MedDec 14, 2021
    risk 0.00cvss 4.3epss 0.01

    discourse-footnote is a library providing footnotes for posts in Discourse. ### Impact When posting an inline footnote wrapped in `` tags (e.g. `^[footnote]`, the resulting rendered HTML would include a nested ``, which is stripped by Nokogiri because it is not…