CWE-617 · 791 records
Reachable Assertion
CVEs in this class
791 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
53Plan | CVE-2020-36222No exploit | A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial openldap · openldap · CWE-617 | High7.5 | — | 77.2% | Jan 26, 2021 |
53Plan | CVE-2006-5779No exploit | OpenLDAP before 2.3.29 allows remote attackers to cause a denial of service (daemon crash) via LDAP BIND requests with long authcid names, wopenldap · openldap · CWE-617 | High7.5 | — | 76.3% | Nov 7, 2006 |
51Plan | CVE-2020-8617Weaponized | A logic error in code which checks TSIG validity can be used to trigger an assertion failure in tsig.cisc · bind · CWE-617 | Medium5.9 | — | 93.4% | May 19, 2020 |
49Plan | CVE-2021-27212No exploit | In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function viopenldap · openldap · CWE-617 | High7.5 | — | 64.1% | Feb 13, 2021 |
48Plan | CVE-2018-5740Proof of concept | A flaw in the "deny-answer-aliases" feature can cause an assertion failure in namedisc · bind · CWE-617 | High7.5 | — | 59.6% | Jan 16, 2019 |
42Plan | CVE-2016-8864No exploit | named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9.11.x before 9.11.0-P1 allows remote attackers to cause a denial of serisc · bind · CWE-617 | High7.5 | — | 38.7% | Nov 2, 2016 |
41Plan | CVE-2018-12543No exploit | In Eclipse Mosquitto versions 1.5 to 1.5.2 inclusive, if a message is published to Mosquitto that has a topic starting with $, but that is neclipse · mosquitto · CWE-617 | High7.5 | — | 36.0% | Nov 15, 2018 |
40Plan | CVE-2019-9795No exploit | A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially be used by malicious JavaScript to triggmozilla · firefox · CWE-617 | Critical9.8 | — | 1.7% | Apr 26, 2019 |
39Monitor | CVE-2020-3615No exploit | Valid deauth/disassoc frames is dropped in case if RMF is enabled and some rouge peer keep on sending rogue deauth/disassoc frames due to imqualcomm · apq8009 firmware · CWE-617 | Critical9.8 | — | 0.8% | Jun 2, 2020 |
36Monitor | CVE-2022-3488No exploit | named may terminate unexpectedly when processing ECS options in repeated responses to iterative queriesisc · bind · CWE-617 | High7.5 | — | 19.2% | Jan 26, 2023 |
36Monitor | CVE-2020-12417No exploit | Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory corruption and a pomozilla · firefox · CWE-617 | High8.8 | — | 2.7% | Jul 9, 2020 |
36Monitor | CVE-2026-41584No exploit | ZEBRA: rk Identity Point Panic in Transaction Verificationzfnd · zebra-chain · CWE-617 | Critical9.2 | — | 0.5% | May 8, 2026 |
35Monitor | CVE-2022-3924No exploit | named configured to answer from stale cache may terminate unexpectedly at recursive-clients soft quotaisc · bind · CWE-617 | High7.5 | — | 16.1% | Jan 26, 2023 |
35Monitor | CVE-2020-6623No exploit | stb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_get_index.nothings · stb truetype.h · CWE-617 | High8.8 | — | 1.5% | Jan 8, 2020 |
35Monitor | CVE-2020-6619No exploit | stb stb_truetype.h through 1.22 has an assertion failure in stbtt__buf_seek.nothings · stb truetype.h · CWE-617 | High8.8 | — | 1.1% | Jan 8, 2020 |
35Monitor | CVE-2020-6617No exploit | stb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_int.nothings · stb truetype.h · CWE-617 | High8.8 | — | 1.1% | Jan 8, 2020 |
35Monitor | CVE-2026-31739No exploit | crypto: tegra - Add missing CRYPTO_ALG_ASYNClinux · linux kernel · CWE-617 | High8.8 | — | 0.6% | May 1, 2026 |
35Monitor | CVE-2026-52952No exploit | iommu: Fix WARN_ON in __iommu_group_set_domain_nofail() due to resetlinux · linux kernel · CWE-617 | High8.8 | — | 0.2% | Jun 24, 2026 |
34Monitor | CVE-2017-7478Proof of concept | OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet.openvpn · openvpn · CWE-617 | High7.5 | — | 13.8% | May 15, 2017 |
34Monitor | CVE-2020-36230No exploit | A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_elemenopenldap · openldap · CWE-617 | High7.5 | — | 12.3% | Jan 26, 2021 |
34Monitor | CVE-2006-4095No exploit | BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via certain SIG queries, which cisc · bind · CWE-617 | High7.5 | — | 11.8% | Sep 5, 2006 |
34Monitor | CVE-2024-34235No exploit | Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.open5gs · open5gs · CWE-617 | High8.6 | — | 0.8% | Jan 22, 2025 |
34Monitor | CVE-2023-37017No exploit | Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.open5gs · open5gs · CWE-617 | High8.6 | — | 0.8% | Jan 22, 2025 |
34Monitor | CVE-2023-37015No exploit | Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.open5gs · open5gs · CWE-617 | High8.6 | — | 0.8% | Jan 22, 2025 |
34Monitor | CVE-2023-37016No exploit | Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.open5gs · open5gs · CWE-617 | High8.6 | — | 0.8% | Jan 22, 2025 |
- CVE-2020-3622253Plan
A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial
HighCVSS 7.5No exploitEPSS 77%openldap · openldapJan 26, 2021
- CVE-2006-577953Plan
OpenLDAP before 2.3.29 allows remote attackers to cause a denial of service (daemon crash) via LDAP BIND requests with long authcid names, w
HighCVSS 7.5No exploitEPSS 76%openldap · openldapNov 7, 2006
- CVE-2020-861751Plan
A logic error in code which checks TSIG validity can be used to trigger an assertion failure in tsig.c
MediumCVSS 5.9WeaponizedEPSS 93%isc · bindMay 19, 2020
- CVE-2021-2721249Plan
In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function vi
HighCVSS 7.5No exploitEPSS 64%openldap · openldapFeb 13, 2021
- CVE-2018-574048Plan
A flaw in the "deny-answer-aliases" feature can cause an assertion failure in named
HighCVSS 7.5Proof of conceptEPSS 60%isc · bindJan 16, 2019
- CVE-2016-886442Plan
named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9.11.x before 9.11.0-P1 allows remote attackers to cause a denial of ser
HighCVSS 7.5No exploitEPSS 39%isc · bindNov 2, 2016
- CVE-2018-1254341Plan
In Eclipse Mosquitto versions 1.5 to 1.5.2 inclusive, if a message is published to Mosquitto that has a topic starting with $, but that is n
HighCVSS 7.5No exploitEPSS 36%eclipse · mosquittoNov 15, 2018
- CVE-2019-979540Plan
A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially be used by malicious JavaScript to trigg
CriticalCVSS 9.8No exploitEPSS 2%mozilla · firefoxApr 26, 2019
- CVE-2020-361539Monitor
Valid deauth/disassoc frames is dropped in case if RMF is enabled and some rouge peer keep on sending rogue deauth/disassoc frames due to im
CriticalCVSS 9.8No exploitEPSS 1%qualcomm · apq8009 firmwareJun 2, 2020
- CVE-2022-348836Monitor
named may terminate unexpectedly when processing ECS options in repeated responses to iterative queries
HighCVSS 7.5No exploitEPSS 19%isc · bindJan 26, 2023
- CVE-2020-1241736Monitor
Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory corruption and a po
HighCVSS 8.8No exploitEPSS 3%mozilla · firefoxJul 9, 2020
- CVE-2026-4158436Monitor
ZEBRA: rk Identity Point Panic in Transaction Verification
CriticalCVSS 9.2No exploitEPSS 0%zfnd · zebra-chainMay 8, 2026
- CVE-2022-392435Monitor
named configured to answer from stale cache may terminate unexpectedly at recursive-clients soft quota
HighCVSS 7.5No exploitEPSS 16%isc · bindJan 26, 2023
- CVE-2020-662335Monitor
stb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_get_index.
HighCVSS 8.8No exploitEPSS 1%nothings · stb truetype.hJan 8, 2020
- CVE-2020-661935Monitor
stb stb_truetype.h through 1.22 has an assertion failure in stbtt__buf_seek.
HighCVSS 8.8No exploitEPSS 1%nothings · stb truetype.hJan 8, 2020
- CVE-2020-661735Monitor
stb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_int.
HighCVSS 8.8No exploitEPSS 1%nothings · stb truetype.hJan 8, 2020
- CVE-2026-3173935Monitor
crypto: tegra - Add missing CRYPTO_ALG_ASYNC
HighCVSS 8.8No exploitEPSS 1%linux · linux kernelMay 1, 2026
- CVE-2026-5295235Monitor
iommu: Fix WARN_ON in __iommu_group_set_domain_nofail() due to reset
HighCVSS 8.8No exploitEPSS 0%linux · linux kernelJun 24, 2026
- CVE-2017-747834Monitor
OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet.
HighCVSS 7.5Proof of conceptEPSS 14%openvpn · openvpnMay 15, 2017
- CVE-2020-3623034Monitor
A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_elemen
HighCVSS 7.5No exploitEPSS 12%openldap · openldapJan 26, 2021
- CVE-2006-409534Monitor
BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via certain SIG queries, which c
HighCVSS 7.5No exploitEPSS 12%isc · bindSep 5, 2006
- CVE-2024-3423534Monitor
Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.
HighCVSS 8.6No exploitEPSS 1%open5gs · open5gsJan 22, 2025
- CVE-2023-3701734Monitor
Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.
HighCVSS 8.6No exploitEPSS 1%open5gs · open5gsJan 22, 2025
- CVE-2023-3701534Monitor
Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.
HighCVSS 8.6No exploitEPSS 1%open5gs · open5gsJan 22, 2025
- CVE-2023-3701634Monitor
Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.
HighCVSS 8.6No exploitEPSS 1%open5gs · open5gsJan 22, 2025