CWE-755 · 435 kayıt
Improper Handling of Exceptional Conditions
Bu sınıftaki CVE’ler
435 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2017-5638Silahlaştırılmış | The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mesapache · struts · CWE-755 | Kritik9,8 | KEV | %100,0 | 10 Mar 2017 |
77Bu hafta | CVE-2021-38003Silahlaştırılmış | Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption vgoogle · chrome · CWE-755 | Yüksek8,8 | KEV | %38,6 | 23 Kas 2021 |
61Bu hafta | CVE-2024-29748Silahlaştırılmış | there is a possible way to bypass due to a logic error in the code.google · android · CWE-755 | Yüksek7,8 | KEV | %0,7 | 5 Nis 2024 |
56Planlayın | CVE-2019-12815Kavram kanıtı | An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure withoutproftpd · proftpd · CWE-755 | Kritik9,8 | — | %57,6 | 19 Tem 2019 |
54Planlayın | CVE-2019-14287Kavram kanıtı | In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, asudo project · sudo · CWE-755 | Yüksek8,8 | — | %63,8 | 17 Eki 2019 |
52Planlayın | CVE-2023-36933İstismar yok | In Progress MOVEit Transfer before 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), it is progress · moveit transfer · CWE-755 | Yüksek7,5 | — | %72,2 | 5 Tem 2023 |
50Planlayın | CVE-2018-0934Kavram kanıtı | ChakraCore and Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the Chakrmicrosoft · edge · CWE-755 | Yüksek7,5 | — | %66,2 | 14 Mar 2018 |
44Planlayın | CVE-2019-6848İstismar yok | A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 CPU (BMEx58*) and Modicon M580 communication modschneider-electric · modicon m580 firmware · CWE-755 | Yüksek8,6 | — | %33,0 | 29 Eki 2019 |
42Planlayın | CVE-2019-17195Kavram kanıtı | Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crashconnect2id · nimbus jose\+jwt · CWE-755 | Kritik9,8 | — | %11,1 | 15 Eki 2019 |
42Planlayın | CVE-2022-23121İstismar yok | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk.netatalk · netatalk · CWE-755 | Kritik9,8 | — | %8,6 | 28 Mar 2023 |
40Planlayın | CVE-2020-5807İstismar yok | An unauthenticated remote attacker can send data to RsvcHost.exe listening on TCP port 5241 to add entries in the FactoryTalk Diagnostics evrockwellautomation · factorytalk diagnostics · CWE-755 | Yüksek7,5 | — | %33,8 | 29 Ara 2020 |
40Planlayın | CVE-2024-21907Kavram kanıtı | Improper Handling of Exceptional Conditions in Newtonsoft.Jsonnewtonsoft · json.net · CWE-755 | Yüksek7,5 | — | %32,9 | 3 Oca 2024 |
40Planlayın | CVE-2019-14378Kavram kanıtı | ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a case involving the firslibslirp project · libslirp · CWE-755 | Yüksek8,8 | — | %16,7 | 29 Tem 2019 |
40Planlayın | CVE-2021-43272İstismar yok | An improper handling of exceptional conditions vulnerability exists in Open Design Alliance ODA Viewer sample before 2022.11.opendesign · oda viewer · CWE-755 | Kritik9,8 | — | %3,6 | 14 Kas 2021 |
40Planlayın | CVE-2019-14431İstismar yok | In MatrixSSL 3.8.3 Open through 4.2.1 Open, the DTLS server mishandles incoming network messages leading to a heap-based buffer overflow of matrixssl · matrixssl · CWE-755 | Kritik9,8 | — | %3,6 | 29 Tem 2019 |
40Planlayın | CVE-2020-24753İstismar yok | A memory corruption vulnerability in Objective Open CBOR Run-time (oocborrt) in versions before 2020-08-12 could allow an attacker to executobjective open cbor run-time project · objective open cbor run-time · CWE-755 | Kritik9,8 | — | %2,6 | 17 Eyl 2020 |
40Planlayın | CVE-2019-6256İstismar yok | A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0.93.live555 · live555 media server · CWE-755 | Kritik9,8 | — | %2,4 | 14 Oca 2019 |
40Planlayın | CVE-2018-19991İstismar yok | VeryNginx 0.3.3 allows remote attackers to bypass the Web Application Firewall feature because there is no error handler (for get_uri_args overynginx project · verynginx · CWE-755 | Kritik9,8 | — | %2,3 | 9 Ara 2018 |
40Planlayın | CVE-2022-31799İstismar yok | Bottle before 0.12.20 mishandles errors during early request binding.bottlepy · bottle · CWE-755 | Kritik9,8 | — | %2,1 | 2 Haz 2022 |
40Planlayın | CVE-2017-2877İstismar yok | A missing error check exists in the Multi-Camera interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43.foscam · c1 firmware · CWE-755 | Kritik9,8 | — | %1,9 | 19 Eyl 2018 |
39İzleyin | CVE-2021-36128İstismar yok | An issue was discovered in the CentralAuth extension in MediaWiki through 1.36.mediawiki · mediawiki · CWE-755 | Kritik9,8 | — | %1,5 | 2 Tem 2021 |
39İzleyin | CVE-2021-38384İstismar yok | Serverless Offline 8.0.0 returns a 403 HTTP status code for a route that has a trailing / character, which might cause a developer to implemserverless offline project · serverless offline · CWE-755 | Kritik9,8 | — | %1,5 | 10 Ağu 2021 |
39İzleyin | CVE-2022-48328İstismar yok | app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters.misp-project · misp · CWE-755 | Kritik9,8 | — | %1,3 | 20 Şub 2023 |
39İzleyin | CVE-2023-28631İstismar yok | Attacker controlled data in AST nodes is not validated in comrakcomrak project · comrak · CWE-755 | Kritik9,8 | — | %1,3 | 28 Mar 2023 |
39İzleyin | CVE-2009-5043İstismar yok | burn allows file names to escape via mishandled quotation marksburn project · burn · CWE-755 | Kritik9,8 | — | %1,2 | 31 Eki 2019 |
- CVE-2017-563899Hemen
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mes
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100apache · struts10 Mar 2017
- CVE-2021-3800377Bu hafta
Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption v
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %39google · chrome23 Kas 2021
- CVE-2024-2974861Bu hafta
there is a possible way to bypass due to a logic error in the code.
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %1google · android5 Nis 2024
- CVE-2019-1281556Planlayın
An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure without
KritikCVSS 9,8Kavram kanıtıEPSS %58proftpd · proftpd19 Tem 2019
- CVE-2019-1428754Planlayın
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, a
YüksekCVSS 8,8Kavram kanıtıEPSS %64sudo project · sudo17 Eki 2019
- CVE-2023-3693352Planlayın
In Progress MOVEit Transfer before 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), it is
YüksekCVSS 7,5İstismar yokEPSS %72progress · moveit transfer5 Tem 2023
- CVE-2018-093450Planlayın
ChakraCore and Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the Chakr
YüksekCVSS 7,5Kavram kanıtıEPSS %66microsoft · edge14 Mar 2018
- CVE-2019-684844Planlayın
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 CPU (BMEx58*) and Modicon M580 communication mod
YüksekCVSS 8,6İstismar yokEPSS %33schneider-electric · modicon m580 firmware29 Eki 2019
- CVE-2019-1719542Planlayın
Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash
KritikCVSS 9,8Kavram kanıtıEPSS %11connect2id · nimbus jose\+jwt15 Eki 2019
- CVE-2022-2312142Planlayın
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk.
KritikCVSS 9,8İstismar yokEPSS %9netatalk · netatalk28 Mar 2023
- CVE-2020-580740Planlayın
An unauthenticated remote attacker can send data to RsvcHost.exe listening on TCP port 5241 to add entries in the FactoryTalk Diagnostics ev
YüksekCVSS 7,5İstismar yokEPSS %34rockwellautomation · factorytalk diagnostics29 Ara 2020
- CVE-2024-2190740Planlayın
Improper Handling of Exceptional Conditions in Newtonsoft.Json
YüksekCVSS 7,5Kavram kanıtıEPSS %33newtonsoft · json.net3 Oca 2024
- CVE-2019-1437840Planlayın
ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a case involving the firs
YüksekCVSS 8,8Kavram kanıtıEPSS %17libslirp project · libslirp29 Tem 2019
- CVE-2021-4327240Planlayın
An improper handling of exceptional conditions vulnerability exists in Open Design Alliance ODA Viewer sample before 2022.11.
KritikCVSS 9,8İstismar yokEPSS %4opendesign · oda viewer14 Kas 2021
- CVE-2019-1443140Planlayın
In MatrixSSL 3.8.3 Open through 4.2.1 Open, the DTLS server mishandles incoming network messages leading to a heap-based buffer overflow of
KritikCVSS 9,8İstismar yokEPSS %4matrixssl · matrixssl29 Tem 2019
- CVE-2020-2475340Planlayın
A memory corruption vulnerability in Objective Open CBOR Run-time (oocborrt) in versions before 2020-08-12 could allow an attacker to execut
KritikCVSS 9,8İstismar yokEPSS %3objective open cbor run-time project · objective open cbor run-time17 Eyl 2020
- CVE-2019-625640Planlayın
A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0.93.
KritikCVSS 9,8İstismar yokEPSS %2live555 · live555 media server14 Oca 2019
- CVE-2018-1999140Planlayın
VeryNginx 0.3.3 allows remote attackers to bypass the Web Application Firewall feature because there is no error handler (for get_uri_args o
KritikCVSS 9,8İstismar yokEPSS %2verynginx project · verynginx9 Ara 2018
- CVE-2022-3179940Planlayın
Bottle before 0.12.20 mishandles errors during early request binding.
KritikCVSS 9,8İstismar yokEPSS %2bottlepy · bottle2 Haz 2022
- CVE-2017-287740Planlayın
A missing error check exists in the Multi-Camera interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43.
KritikCVSS 9,8İstismar yokEPSS %2foscam · c1 firmware19 Eyl 2018
- CVE-2021-3612839İzleyin
An issue was discovered in the CentralAuth extension in MediaWiki through 1.36.
KritikCVSS 9,8İstismar yokEPSS %1mediawiki · mediawiki2 Tem 2021
- CVE-2021-3838439İzleyin
Serverless Offline 8.0.0 returns a 403 HTTP status code for a route that has a trailing / character, which might cause a developer to implem
KritikCVSS 9,8İstismar yokEPSS %1serverless offline project · serverless offline10 Ağu 2021
- CVE-2022-4832839İzleyin
app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters.
KritikCVSS 9,8İstismar yokEPSS %1misp-project · misp20 Şub 2023
- CVE-2023-2863139İzleyin
Attacker controlled data in AST nodes is not validated in comrak
KritikCVSS 9,8İstismar yokEPSS %1comrak project · comrak28 Mar 2023
- CVE-2009-504339İzleyin
burn allows file names to escape via mishandled quotation marks
KritikCVSS 9,8İstismar yokEPSS %1burn project · burn31 Eki 2019