CWE-617 · 791 записей
Reachable Assertion
CVE этого класса
791 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
53В плане | CVE-2020-36222Эксплойта нет | A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial openldap · openldap · CWE-617 | Высокая7,5 | — | 77,2 % | 26 янв. 2021 г. |
53В плане | CVE-2006-5779Эксплойта нет | OpenLDAP before 2.3.29 allows remote attackers to cause a denial of service (daemon crash) via LDAP BIND requests with long authcid names, wopenldap · openldap · CWE-617 | Высокая7,5 | — | 76,3 % | 7 нояб. 2006 г. |
51В плане | CVE-2020-8617Готовый эксплойт | A logic error in code which checks TSIG validity can be used to trigger an assertion failure in tsig.cisc · bind · CWE-617 | Средняя5,9 | — | 93,4 % | 19 мая 2020 г. |
49В плане | CVE-2021-27212Эксплойта нет | In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function viopenldap · openldap · CWE-617 | Высокая7,5 | — | 64,1 % | 13 февр. 2021 г. |
48В плане | CVE-2018-5740Proof of concept | A flaw in the "deny-answer-aliases" feature can cause an assertion failure in namedisc · bind · CWE-617 | Высокая7,5 | — | 59,6 % | 16 янв. 2019 г. |
42В плане | CVE-2016-8864Эксплойта нет | named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9.11.x before 9.11.0-P1 allows remote attackers to cause a denial of serisc · bind · CWE-617 | Высокая7,5 | — | 38,7 % | 2 нояб. 2016 г. |
41В плане | CVE-2018-12543Эксплойта нет | In Eclipse Mosquitto versions 1.5 to 1.5.2 inclusive, if a message is published to Mosquitto that has a topic starting with $, but that is neclipse · mosquitto · CWE-617 | Высокая7,5 | — | 36,0 % | 15 нояб. 2018 г. |
40В плане | CVE-2019-9795Эксплойта нет | A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially be used by malicious JavaScript to triggmozilla · firefox · CWE-617 | Критическая9,8 | — | 1,7 % | 26 апр. 2019 г. |
39Наблюдать | CVE-2020-3615Эксплойта нет | Valid deauth/disassoc frames is dropped in case if RMF is enabled and some rouge peer keep on sending rogue deauth/disassoc frames due to imqualcomm · apq8009 firmware · CWE-617 | Критическая9,8 | — | 0,8 % | 2 июн. 2020 г. |
36Наблюдать | CVE-2022-3488Эксплойта нет | named may terminate unexpectedly when processing ECS options in repeated responses to iterative queriesisc · bind · CWE-617 | Высокая7,5 | — | 19,2 % | 26 янв. 2023 г. |
36Наблюдать | CVE-2020-12417Эксплойта нет | Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory corruption and a pomozilla · firefox · CWE-617 | Высокая8,8 | — | 2,7 % | 9 июл. 2020 г. |
36Наблюдать | CVE-2026-41584Эксплойта нет | ZEBRA: rk Identity Point Panic in Transaction Verificationzfnd · zebra-chain · CWE-617 | Критическая9,2 | — | 0,5 % | 8 мая 2026 г. |
35Наблюдать | CVE-2022-3924Эксплойта нет | named configured to answer from stale cache may terminate unexpectedly at recursive-clients soft quotaisc · bind · CWE-617 | Высокая7,5 | — | 16,1 % | 26 янв. 2023 г. |
35Наблюдать | CVE-2020-6623Эксплойта нет | stb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_get_index.nothings · stb truetype.h · CWE-617 | Высокая8,8 | — | 1,5 % | 8 янв. 2020 г. |
35Наблюдать | CVE-2020-6619Эксплойта нет | stb stb_truetype.h through 1.22 has an assertion failure in stbtt__buf_seek.nothings · stb truetype.h · CWE-617 | Высокая8,8 | — | 1,1 % | 8 янв. 2020 г. |
35Наблюдать | CVE-2020-6617Эксплойта нет | stb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_int.nothings · stb truetype.h · CWE-617 | Высокая8,8 | — | 1,1 % | 8 янв. 2020 г. |
35Наблюдать | CVE-2026-31739Эксплойта нет | crypto: tegra - Add missing CRYPTO_ALG_ASYNClinux · linux kernel · CWE-617 | Высокая8,8 | — | 0,6 % | 1 мая 2026 г. |
35Наблюдать | CVE-2026-52952Эксплойта нет | iommu: Fix WARN_ON in __iommu_group_set_domain_nofail() due to resetlinux · linux kernel · CWE-617 | Высокая8,8 | — | 0,2 % | 24 июн. 2026 г. |
34Наблюдать | CVE-2017-7478Proof of concept | OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet.openvpn · openvpn · CWE-617 | Высокая7,5 | — | 13,8 % | 15 мая 2017 г. |
34Наблюдать | CVE-2020-36230Эксплойта нет | A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_elemenopenldap · openldap · CWE-617 | Высокая7,5 | — | 12,3 % | 26 янв. 2021 г. |
34Наблюдать | CVE-2006-4095Эксплойта нет | BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via certain SIG queries, which cisc · bind · CWE-617 | Высокая7,5 | — | 11,8 % | 5 сент. 2006 г. |
34Наблюдать | CVE-2024-34235Эксплойта нет | Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.open5gs · open5gs · CWE-617 | Высокая8,6 | — | 0,8 % | 22 янв. 2025 г. |
34Наблюдать | CVE-2023-37017Эксплойта нет | Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.open5gs · open5gs · CWE-617 | Высокая8,6 | — | 0,8 % | 22 янв. 2025 г. |
34Наблюдать | CVE-2023-37015Эксплойта нет | Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.open5gs · open5gs · CWE-617 | Высокая8,6 | — | 0,8 % | 22 янв. 2025 г. |
34Наблюдать | CVE-2023-37016Эксплойта нет | Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.open5gs · open5gs · CWE-617 | Высокая8,6 | — | 0,8 % | 22 янв. 2025 г. |
- CVE-2020-3622253В плане
A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial
ВысокаяCVSS 7,5Эксплойта нетEPSS 77 %openldap · openldap26 янв. 2021 г.
- CVE-2006-577953В плане
OpenLDAP before 2.3.29 allows remote attackers to cause a denial of service (daemon crash) via LDAP BIND requests with long authcid names, w
ВысокаяCVSS 7,5Эксплойта нетEPSS 76 %openldap · openldap7 нояб. 2006 г.
- CVE-2020-861751В плане
A logic error in code which checks TSIG validity can be used to trigger an assertion failure in tsig.c
СредняяCVSS 5,9Готовый эксплойтEPSS 93 %isc · bind19 мая 2020 г.
- CVE-2021-2721249В плане
In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function vi
ВысокаяCVSS 7,5Эксплойта нетEPSS 64 %openldap · openldap13 февр. 2021 г.
- CVE-2018-574048В плане
A flaw in the "deny-answer-aliases" feature can cause an assertion failure in named
ВысокаяCVSS 7,5Proof of conceptEPSS 60 %isc · bind16 янв. 2019 г.
- CVE-2016-886442В плане
named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9.11.x before 9.11.0-P1 allows remote attackers to cause a denial of ser
ВысокаяCVSS 7,5Эксплойта нетEPSS 39 %isc · bind2 нояб. 2016 г.
- CVE-2018-1254341В плане
In Eclipse Mosquitto versions 1.5 to 1.5.2 inclusive, if a message is published to Mosquitto that has a topic starting with $, but that is n
ВысокаяCVSS 7,5Эксплойта нетEPSS 36 %eclipse · mosquitto15 нояб. 2018 г.
- CVE-2019-979540В плане
A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially be used by malicious JavaScript to trigg
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %mozilla · firefox26 апр. 2019 г.
- CVE-2020-361539Наблюдать
Valid deauth/disassoc frames is dropped in case if RMF is enabled and some rouge peer keep on sending rogue deauth/disassoc frames due to im
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %qualcomm · apq8009 firmware2 июн. 2020 г.
- CVE-2022-348836Наблюдать
named may terminate unexpectedly when processing ECS options in repeated responses to iterative queries
ВысокаяCVSS 7,5Эксплойта нетEPSS 19 %isc · bind26 янв. 2023 г.
- CVE-2020-1241736Наблюдать
Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory corruption and a po
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %mozilla · firefox9 июл. 2020 г.
- CVE-2026-4158436Наблюдать
ZEBRA: rk Identity Point Panic in Transaction Verification
КритическаяCVSS 9,2Эксплойта нетEPSS 0 %zfnd · zebra-chain8 мая 2026 г.
- CVE-2022-392435Наблюдать
named configured to answer from stale cache may terminate unexpectedly at recursive-clients soft quota
ВысокаяCVSS 7,5Эксплойта нетEPSS 16 %isc · bind26 янв. 2023 г.
- CVE-2020-662335Наблюдать
stb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_get_index.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %nothings · stb truetype.h8 янв. 2020 г.
- CVE-2020-661935Наблюдать
stb stb_truetype.h through 1.22 has an assertion failure in stbtt__buf_seek.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %nothings · stb truetype.h8 янв. 2020 г.
- CVE-2020-661735Наблюдать
stb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_int.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %nothings · stb truetype.h8 янв. 2020 г.
- CVE-2026-3173935Наблюдать
crypto: tegra - Add missing CRYPTO_ALG_ASYNC
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %linux · linux kernel1 мая 2026 г.
- CVE-2026-5295235Наблюдать
iommu: Fix WARN_ON in __iommu_group_set_domain_nofail() due to reset
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %linux · linux kernel24 июн. 2026 г.
- CVE-2017-747834Наблюдать
OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet.
ВысокаяCVSS 7,5Proof of conceptEPSS 14 %openvpn · openvpn15 мая 2017 г.
- CVE-2020-3623034Наблюдать
A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_elemen
ВысокаяCVSS 7,5Эксплойта нетEPSS 12 %openldap · openldap26 янв. 2021 г.
- CVE-2006-409534Наблюдать
BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via certain SIG queries, which c
ВысокаяCVSS 7,5Эксплойта нетEPSS 12 %isc · bind5 сент. 2006 г.
- CVE-2024-3423534Наблюдать
Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %open5gs · open5gs22 янв. 2025 г.
- CVE-2023-3701734Наблюдать
Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %open5gs · open5gs22 янв. 2025 г.
- CVE-2023-3701534Наблюдать
Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %open5gs · open5gs22 янв. 2025 г.
- CVE-2023-3701634Наблюдать
Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %open5gs · open5gs22 янв. 2025 г.