Skip to content
Noroxi

CWE-617 · 791 records

Reachable Assertion

CVEs in this class

791 records

  • A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial

    HighCVSS 7.5No exploitEPSS 77%

    openldap · openldapJan 26, 2021

  • OpenLDAP before 2.3.29 allows remote attackers to cause a denial of service (daemon crash) via LDAP BIND requests with long authcid names, w

    HighCVSS 7.5No exploitEPSS 76%

    openldap · openldapNov 7, 2006

  • A logic error in code which checks TSIG validity can be used to trigger an assertion failure in tsig.c

    MediumCVSS 5.9WeaponizedEPSS 93%

    isc · bindMay 19, 2020

  • In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function vi

    HighCVSS 7.5No exploitEPSS 64%

    openldap · openldapFeb 13, 2021

  • A flaw in the "deny-answer-aliases" feature can cause an assertion failure in named

    HighCVSS 7.5Proof of conceptEPSS 60%

    isc · bindJan 16, 2019

  • named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9.11.x before 9.11.0-P1 allows remote attackers to cause a denial of ser

    HighCVSS 7.5No exploitEPSS 39%

    isc · bindNov 2, 2016

  • In Eclipse Mosquitto versions 1.5 to 1.5.2 inclusive, if a message is published to Mosquitto that has a topic starting with $, but that is n

    HighCVSS 7.5No exploitEPSS 36%

    eclipse · mosquittoNov 15, 2018

  • A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially be used by malicious JavaScript to trigg

    CriticalCVSS 9.8No exploitEPSS 2%

    mozilla · firefoxApr 26, 2019

  • CVE-2020-3615
    39Monitor

    Valid deauth/disassoc frames is dropped in case if RMF is enabled and some rouge peer keep on sending rogue deauth/disassoc frames due to im

    CriticalCVSS 9.8No exploitEPSS 1%

    qualcomm · apq8009 firmwareJun 2, 2020

  • CVE-2022-3488
    36Monitor

    named may terminate unexpectedly when processing ECS options in repeated responses to iterative queries

    HighCVSS 7.5No exploitEPSS 19%

    isc · bindJan 26, 2023

  • Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory corruption and a po

    HighCVSS 8.8No exploitEPSS 3%

    mozilla · firefoxJul 9, 2020

  • ZEBRA: rk Identity Point Panic in Transaction Verification

    CriticalCVSS 9.2No exploitEPSS 0%

    zfnd · zebra-chainMay 8, 2026

  • CVE-2022-3924
    35Monitor

    named configured to answer from stale cache may terminate unexpectedly at recursive-clients soft quota

    HighCVSS 7.5No exploitEPSS 16%

    isc · bindJan 26, 2023

  • CVE-2020-6623
    35Monitor

    stb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_get_index.

    HighCVSS 8.8No exploitEPSS 1%

    nothings · stb truetype.hJan 8, 2020

  • CVE-2020-6619
    35Monitor

    stb stb_truetype.h through 1.22 has an assertion failure in stbtt__buf_seek.

    HighCVSS 8.8No exploitEPSS 1%

    nothings · stb truetype.hJan 8, 2020

  • CVE-2020-6617
    35Monitor

    stb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_int.

    HighCVSS 8.8No exploitEPSS 1%

    nothings · stb truetype.hJan 8, 2020

  • crypto: tegra - Add missing CRYPTO_ALG_ASYNC

    HighCVSS 8.8No exploitEPSS 1%

    linux · linux kernelMay 1, 2026

  • iommu: Fix WARN_ON in __iommu_group_set_domain_nofail() due to reset

    HighCVSS 8.8No exploitEPSS 0%

    linux · linux kernelJun 24, 2026

  • CVE-2017-7478
    34Monitor

    OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet.

    HighCVSS 7.5Proof of conceptEPSS 14%

    openvpn · openvpnMay 15, 2017

  • A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_elemen

    HighCVSS 7.5No exploitEPSS 12%

    openldap · openldapJan 26, 2021

  • CVE-2006-4095
    34Monitor

    BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via certain SIG queries, which c

    HighCVSS 7.5No exploitEPSS 12%

    isc · bindSep 5, 2006

  • Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.

    HighCVSS 8.6No exploitEPSS 1%

    open5gs · open5gsJan 22, 2025

  • Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.

    HighCVSS 8.6No exploitEPSS 1%

    open5gs · open5gsJan 22, 2025

  • Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.

    HighCVSS 8.6No exploitEPSS 1%

    open5gs · open5gsJan 22, 2025

  • Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.

    HighCVSS 8.6No exploitEPSS 1%

    open5gs · open5gsJan 22, 2025

All vulnerability classes