VYPR

CWE-755

Improper Handling of Exceptional Conditions

ClassIncompleteLikelihood: Medium

Description

The product does not handle or incorrectly handles an exceptional condition.

Hierarchy (View 1000)

CVEs mapped to this weakness (587)

page 7 of 30
  • CVE-2023-36832HigJul 14, 2023
    risk 0.49cvss 7.5epss 0.01

    An Improper Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS on MX Series allows an unauthenticated network-based attacker to send specific packets to an Aggregated Multiservices (AMS) interface on the device, causing the packet…

  • CVE-2023-1695HigJul 6, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of failures to capture exceptions in the communication framework. Successful exploitation of this vulnerability may cause features to perform abnormally.

  • CVE-2023-20692HigJul 4, 2023
    risk 0.49cvss 7.5epss 0.00

    In wlan firmware, there is possible system crash due to an uncaught exception. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07664720; Issue ID: ALPS07664720.

  • CVE-2023-24510HigJun 5, 2023
    risk 0.49cvss 7.5epss 0.01

    On the affected platforms running EOS, a malformed DHCP packet might cause the DHCP relay agent to restart.

  • CVE-2022-27978HigApr 26, 2023
    risk 0.49cvss 7.5epss 0.01

    Tooljet v1.6 does not properly handle missing values in the API, allowing attackers to arbitrarily reset passwords via a crafted HTTP request.

  • CVE-2023-23837HigApr 25, 2023
    risk 0.49cvss 7.5epss 0.01

    No exception handling vulnerability which revealed sensitive or excessive information to users.

  • CVE-2021-38363HigApr 20, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in ONOS 2.5.1. In IntentManager, the install-requested intent (which causes an exception) remains in pendingMap (in memory) forever. Deletion is possible neither by a user nor by the intermittent Intent Cleanup process.

  • CVE-2023-22391HigJan 13, 2023
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in class-of-service (CoS) queue management in Juniper Networks Junos OS on the ACX2K Series devices allows an unauthenticated network-based attacker to cause a Denial of Service (DoS). Specific packets are being incorrectly routed to a queue used for other…

  • CVE-2022-44030HigDec 6, 2022
    risk 0.49cvss 7.5epss 0.01

    Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks. Depending on the configuration, this may require login as a registered user.

  • CVE-2022-41777HigDec 5, 2022
    risk 0.49cvss 7.5epss 0.01

    Improper check or handling of exceptional conditions vulnerability in Nako3edit, editor component of nadesiko3 (PC Version) v3.3.74 and earlier allows a remote attacker to inject an invalid value to decodeURIComponent of nako3edit, which may lead the server to crash.

  • CVE-2022-20854HigNov 15, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the processing of SSH connections of Cisco Firepower Management Center (FMC) and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This…

  • CVE-2022-35268HigOct 25, 2022
    risk 0.49cvss 7.5epss 0.01

    A denial of service vulnerability exists in the web_server hashFirst functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network request can lead to denial of service. An attacker can send a sequence of requests to trigger this vulnerability.This denial of…

  • CVE-2022-36923HigAug 10, 2022
    risk 0.49cvss 7.5epss 0.07

    Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 2022-07-27 through 2022-07-28 (125657, 126002, 126104, and 126118) allow unauthenticated attackers to obtain a user's API key, and…

  • CVE-2021-46828HigJul 20, 2022
    risk 0.49cvss 7.5epss 0.03

    In libtirpc before 1.3.3rc1, remote attackers could exhaust the file descriptors of a process that uses libtirpc because idle TCP connections are mishandled. This can, in turn, lead to an svc_run infinite loop without accepting new connections.

  • CVE-2021-40402HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.01

    An out-of-bounds read vulnerability exists in the RS-274X aperture macro multiple outline primitives functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.7.1 and 2.8.0. A specially-crafted Gerber file can lead to information disclosure. An attacker can…

  • CVE-2022-23161HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.01

    Dell PowerScale OneFS versions 8.2.x - 9.3.0.x contain a denial-of-service vulnerability in SmartConnect. An unprivileged network attacker may potentially exploit this vulnerability, leading to denial-of-service.

  • CVE-2022-21155HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.01

    A specially crafted packet sent to the Fernhill SCADA Server Version 3.77 and earlier may cause an exception, causing the server process (FHSvrService.exe) to exit.

  • CVE-2020-25691HigApr 1, 2022
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in darkhttpd. Invalid error handling allows remote attackers to cause denial-of-service by accessing a file with a large modification date. The highest threat from this vulnerability is to system availability.

  • CVE-2021-22285HigFeb 4, 2022
    risk 0.49cvss 7.5epss 0.01

    Improper Handling of Exceptional Conditions, Improper Check for Unusual or Exceptional Conditions vulnerability in the ABB SPIET800 and PNI800 module that allows an attacker to cause the denial of service or make the module unresponsive.

  • CVE-2022-23018HigJan 25, 2022
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP AFM version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and 13.1.x beginning in 13.1.3.4, when a virtual server is configured with both HTTP protocol security and HTTP Proxy Connect profiles, undisclosed requests can cause the Traffic…