Skip to content
Noroxi

CWE-755 · 435 records

Improper Handling of Exceptional Conditions

CVEs in this class

435 records

  • The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mes

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    apache · strutsMar 10, 2017

  • CVE-2021-38003
    77This week

    Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption v

    HighCVSS 8.8KEVWeaponizedEPSS 39%

    google · chromeNov 23, 2021

  • CVE-2024-29748
    61This week

    there is a possible way to bypass due to a logic error in the code.

    HighCVSS 7.8KEVWeaponizedEPSS 1%

    google · androidApr 5, 2024

  • An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure without

    CriticalCVSS 9.8Proof of conceptEPSS 58%

    proftpd · proftpdJul 19, 2019

  • In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, a

    HighCVSS 8.8Proof of conceptEPSS 64%

    sudo project · sudoOct 17, 2019

  • In Progress MOVEit Transfer before 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), it is

    HighCVSS 7.5No exploitEPSS 72%

    progress · moveit transferJul 5, 2023

  • ChakraCore and Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the Chakr

    HighCVSS 7.5Proof of conceptEPSS 66%

    microsoft · edgeMar 14, 2018

  • A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 CPU (BMEx58*) and Modicon M580 communication mod

    HighCVSS 8.6No exploitEPSS 33%

    schneider-electric · modicon m580 firmwareOct 29, 2019

  • Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash

    CriticalCVSS 9.8Proof of conceptEPSS 11%

    connect2id · nimbus jose\+jwtOct 15, 2019

  • This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk.

    CriticalCVSS 9.8No exploitEPSS 9%

    netatalk · netatalkMar 28, 2023

  • An unauthenticated remote attacker can send data to RsvcHost.exe listening on TCP port 5241 to add entries in the FactoryTalk Diagnostics ev

    HighCVSS 7.5No exploitEPSS 34%

    rockwellautomation · factorytalk diagnosticsDec 29, 2020

  • Improper Handling of Exceptional Conditions in Newtonsoft.Json

    HighCVSS 7.5Proof of conceptEPSS 33%

    newtonsoft · json.netJan 3, 2024

  • ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a case involving the firs

    HighCVSS 8.8Proof of conceptEPSS 17%

    libslirp project · libslirpJul 29, 2019

  • An improper handling of exceptional conditions vulnerability exists in Open Design Alliance ODA Viewer sample before 2022.11.

    CriticalCVSS 9.8No exploitEPSS 4%

    opendesign · oda viewerNov 14, 2021

  • In MatrixSSL 3.8.3 Open through 4.2.1 Open, the DTLS server mishandles incoming network messages leading to a heap-based buffer overflow of

    CriticalCVSS 9.8No exploitEPSS 4%

    matrixssl · matrixsslJul 29, 2019

  • A memory corruption vulnerability in Objective Open CBOR Run-time (oocborrt) in versions before 2020-08-12 could allow an attacker to execut

    CriticalCVSS 9.8No exploitEPSS 3%

    objective open cbor run-time project · objective open cbor run-timeSep 17, 2020

  • A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0.93.

    CriticalCVSS 9.8No exploitEPSS 2%

    live555 · live555 media serverJan 14, 2019

  • VeryNginx 0.3.3 allows remote attackers to bypass the Web Application Firewall feature because there is no error handler (for get_uri_args o

    CriticalCVSS 9.8No exploitEPSS 2%

    verynginx project · verynginxDec 9, 2018

  • Bottle before 0.12.20 mishandles errors during early request binding.

    CriticalCVSS 9.8No exploitEPSS 2%

    bottlepy · bottleJun 2, 2022

  • A missing error check exists in the Multi-Camera interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43.

    CriticalCVSS 9.8No exploitEPSS 2%

    foscam · c1 firmwareSep 19, 2018

  • An issue was discovered in the CentralAuth extension in MediaWiki through 1.36.

    CriticalCVSS 9.8No exploitEPSS 1%

    mediawiki · mediawikiJul 2, 2021

  • Serverless Offline 8.0.0 returns a 403 HTTP status code for a route that has a trailing / character, which might cause a developer to implem

    CriticalCVSS 9.8No exploitEPSS 1%

    serverless offline project · serverless offlineAug 10, 2021

  • app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters.

    CriticalCVSS 9.8No exploitEPSS 1%

    misp-project · mispFeb 20, 2023

  • Attacker controlled data in AST nodes is not validated in comrak

    CriticalCVSS 9.8No exploitEPSS 1%

    comrak project · comrakMar 28, 2023

  • CVE-2009-5043
    39Monitor

    burn allows file names to escape via mishandled quotation marks

    CriticalCVSS 9.8No exploitEPSS 1%

    burn project · burnOct 31, 2019

All vulnerability classes