CWE-755 · 435 records
Improper Handling of Exceptional Conditions
CVEs in this class
435 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2017-5638Weaponized | The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mesapache · struts · CWE-755 | Critical9.8 | KEV | 100.0% | Mar 10, 2017 |
77This week | CVE-2021-38003Weaponized | Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption vgoogle · chrome · CWE-755 | High8.8 | KEV | 38.6% | Nov 23, 2021 |
61This week | CVE-2024-29748Weaponized | there is a possible way to bypass due to a logic error in the code.google · android · CWE-755 | High7.8 | KEV | 0.7% | Apr 5, 2024 |
56Plan | CVE-2019-12815Proof of concept | An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure withoutproftpd · proftpd · CWE-755 | Critical9.8 | — | 57.6% | Jul 19, 2019 |
54Plan | CVE-2019-14287Proof of concept | In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, asudo project · sudo · CWE-755 | High8.8 | — | 63.8% | Oct 17, 2019 |
52Plan | CVE-2023-36933No exploit | In Progress MOVEit Transfer before 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), it is progress · moveit transfer · CWE-755 | High7.5 | — | 72.2% | Jul 5, 2023 |
50Plan | CVE-2018-0934Proof of concept | ChakraCore and Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the Chakrmicrosoft · edge · CWE-755 | High7.5 | — | 66.2% | Mar 14, 2018 |
44Plan | CVE-2019-6848No exploit | A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 CPU (BMEx58*) and Modicon M580 communication modschneider-electric · modicon m580 firmware · CWE-755 | High8.6 | — | 33.0% | Oct 29, 2019 |
42Plan | CVE-2019-17195Proof of concept | Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crashconnect2id · nimbus jose\+jwt · CWE-755 | Critical9.8 | — | 11.1% | Oct 15, 2019 |
42Plan | CVE-2022-23121No exploit | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk.netatalk · netatalk · CWE-755 | Critical9.8 | — | 8.6% | Mar 28, 2023 |
40Plan | CVE-2020-5807No exploit | An unauthenticated remote attacker can send data to RsvcHost.exe listening on TCP port 5241 to add entries in the FactoryTalk Diagnostics evrockwellautomation · factorytalk diagnostics · CWE-755 | High7.5 | — | 33.8% | Dec 29, 2020 |
40Plan | CVE-2024-21907Proof of concept | Improper Handling of Exceptional Conditions in Newtonsoft.Jsonnewtonsoft · json.net · CWE-755 | High7.5 | — | 32.9% | Jan 3, 2024 |
40Plan | CVE-2019-14378Proof of concept | ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a case involving the firslibslirp project · libslirp · CWE-755 | High8.8 | — | 16.7% | Jul 29, 2019 |
40Plan | CVE-2021-43272No exploit | An improper handling of exceptional conditions vulnerability exists in Open Design Alliance ODA Viewer sample before 2022.11.opendesign · oda viewer · CWE-755 | Critical9.8 | — | 3.6% | Nov 14, 2021 |
40Plan | CVE-2019-14431No exploit | In MatrixSSL 3.8.3 Open through 4.2.1 Open, the DTLS server mishandles incoming network messages leading to a heap-based buffer overflow of matrixssl · matrixssl · CWE-755 | Critical9.8 | — | 3.6% | Jul 29, 2019 |
40Plan | CVE-2020-24753No exploit | A memory corruption vulnerability in Objective Open CBOR Run-time (oocborrt) in versions before 2020-08-12 could allow an attacker to executobjective open cbor run-time project · objective open cbor run-time · CWE-755 | Critical9.8 | — | 2.6% | Sep 17, 2020 |
40Plan | CVE-2019-6256No exploit | A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0.93.live555 · live555 media server · CWE-755 | Critical9.8 | — | 2.4% | Jan 14, 2019 |
40Plan | CVE-2018-19991No exploit | VeryNginx 0.3.3 allows remote attackers to bypass the Web Application Firewall feature because there is no error handler (for get_uri_args overynginx project · verynginx · CWE-755 | Critical9.8 | — | 2.3% | Dec 9, 2018 |
40Plan | CVE-2022-31799No exploit | Bottle before 0.12.20 mishandles errors during early request binding.bottlepy · bottle · CWE-755 | Critical9.8 | — | 2.1% | Jun 2, 2022 |
40Plan | CVE-2017-2877No exploit | A missing error check exists in the Multi-Camera interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43.foscam · c1 firmware · CWE-755 | Critical9.8 | — | 1.9% | Sep 19, 2018 |
39Monitor | CVE-2021-36128No exploit | An issue was discovered in the CentralAuth extension in MediaWiki through 1.36.mediawiki · mediawiki · CWE-755 | Critical9.8 | — | 1.5% | Jul 2, 2021 |
39Monitor | CVE-2021-38384No exploit | Serverless Offline 8.0.0 returns a 403 HTTP status code for a route that has a trailing / character, which might cause a developer to implemserverless offline project · serverless offline · CWE-755 | Critical9.8 | — | 1.5% | Aug 10, 2021 |
39Monitor | CVE-2022-48328No exploit | app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters.misp-project · misp · CWE-755 | Critical9.8 | — | 1.3% | Feb 20, 2023 |
39Monitor | CVE-2023-28631No exploit | Attacker controlled data in AST nodes is not validated in comrakcomrak project · comrak · CWE-755 | Critical9.8 | — | 1.3% | Mar 28, 2023 |
39Monitor | CVE-2009-5043No exploit | burn allows file names to escape via mishandled quotation marksburn project · burn · CWE-755 | Critical9.8 | — | 1.2% | Oct 31, 2019 |
- CVE-2017-563899Now
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mes
CriticalCVSS 9.8KEVWeaponizedEPSS 100%apache · strutsMar 10, 2017
- CVE-2021-3800377This week
Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption v
HighCVSS 8.8KEVWeaponizedEPSS 39%google · chromeNov 23, 2021
- CVE-2024-2974861This week
there is a possible way to bypass due to a logic error in the code.
HighCVSS 7.8KEVWeaponizedEPSS 1%google · androidApr 5, 2024
- CVE-2019-1281556Plan
An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure without
CriticalCVSS 9.8Proof of conceptEPSS 58%proftpd · proftpdJul 19, 2019
- CVE-2019-1428754Plan
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, a
HighCVSS 8.8Proof of conceptEPSS 64%sudo project · sudoOct 17, 2019
- CVE-2023-3693352Plan
In Progress MOVEit Transfer before 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), it is
HighCVSS 7.5No exploitEPSS 72%progress · moveit transferJul 5, 2023
- CVE-2018-093450Plan
ChakraCore and Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the Chakr
HighCVSS 7.5Proof of conceptEPSS 66%microsoft · edgeMar 14, 2018
- CVE-2019-684844Plan
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 CPU (BMEx58*) and Modicon M580 communication mod
HighCVSS 8.6No exploitEPSS 33%schneider-electric · modicon m580 firmwareOct 29, 2019
- CVE-2019-1719542Plan
Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash
CriticalCVSS 9.8Proof of conceptEPSS 11%connect2id · nimbus jose\+jwtOct 15, 2019
- CVE-2022-2312142Plan
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk.
CriticalCVSS 9.8No exploitEPSS 9%netatalk · netatalkMar 28, 2023
- CVE-2020-580740Plan
An unauthenticated remote attacker can send data to RsvcHost.exe listening on TCP port 5241 to add entries in the FactoryTalk Diagnostics ev
HighCVSS 7.5No exploitEPSS 34%rockwellautomation · factorytalk diagnosticsDec 29, 2020
- CVE-2024-2190740Plan
Improper Handling of Exceptional Conditions in Newtonsoft.Json
HighCVSS 7.5Proof of conceptEPSS 33%newtonsoft · json.netJan 3, 2024
- CVE-2019-1437840Plan
ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a case involving the firs
HighCVSS 8.8Proof of conceptEPSS 17%libslirp project · libslirpJul 29, 2019
- CVE-2021-4327240Plan
An improper handling of exceptional conditions vulnerability exists in Open Design Alliance ODA Viewer sample before 2022.11.
CriticalCVSS 9.8No exploitEPSS 4%opendesign · oda viewerNov 14, 2021
- CVE-2019-1443140Plan
In MatrixSSL 3.8.3 Open through 4.2.1 Open, the DTLS server mishandles incoming network messages leading to a heap-based buffer overflow of
CriticalCVSS 9.8No exploitEPSS 4%matrixssl · matrixsslJul 29, 2019
- CVE-2020-2475340Plan
A memory corruption vulnerability in Objective Open CBOR Run-time (oocborrt) in versions before 2020-08-12 could allow an attacker to execut
CriticalCVSS 9.8No exploitEPSS 3%objective open cbor run-time project · objective open cbor run-timeSep 17, 2020
- CVE-2019-625640Plan
A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0.93.
CriticalCVSS 9.8No exploitEPSS 2%live555 · live555 media serverJan 14, 2019
- CVE-2018-1999140Plan
VeryNginx 0.3.3 allows remote attackers to bypass the Web Application Firewall feature because there is no error handler (for get_uri_args o
CriticalCVSS 9.8No exploitEPSS 2%verynginx project · verynginxDec 9, 2018
- CVE-2022-3179940Plan
Bottle before 0.12.20 mishandles errors during early request binding.
CriticalCVSS 9.8No exploitEPSS 2%bottlepy · bottleJun 2, 2022
- CVE-2017-287740Plan
A missing error check exists in the Multi-Camera interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43.
CriticalCVSS 9.8No exploitEPSS 2%foscam · c1 firmwareSep 19, 2018
- CVE-2021-3612839Monitor
An issue was discovered in the CentralAuth extension in MediaWiki through 1.36.
CriticalCVSS 9.8No exploitEPSS 1%mediawiki · mediawikiJul 2, 2021
- CVE-2021-3838439Monitor
Serverless Offline 8.0.0 returns a 403 HTTP status code for a route that has a trailing / character, which might cause a developer to implem
CriticalCVSS 9.8No exploitEPSS 1%serverless offline project · serverless offlineAug 10, 2021
- CVE-2022-4832839Monitor
app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters.
CriticalCVSS 9.8No exploitEPSS 1%misp-project · mispFeb 20, 2023
- CVE-2023-2863139Monitor
Attacker controlled data in AST nodes is not validated in comrak
CriticalCVSS 9.8No exploitEPSS 1%comrak project · comrakMar 28, 2023
- CVE-2009-504339Monitor
burn allows file names to escape via mishandled quotation marks
CriticalCVSS 9.8No exploitEPSS 1%burn project · burnOct 31, 2019