İçeriğe atla
Noroxi

CWE-755 · 435 kayıt

Improper Handling of Exceptional Conditions

Bu sınıftaki CVE’ler

435 kayıt

  • The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mes

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    apache · struts10 Mar 2017

  • CVE-2021-38003
    77Bu hafta

    Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption v

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %39

    google · chrome23 Kas 2021

  • CVE-2024-29748
    61Bu hafta

    there is a possible way to bypass due to a logic error in the code.

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %1

    google · android5 Nis 2024

  • CVE-2019-12815
    56Planlayın

    An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure without

    KritikCVSS 9,8Kavram kanıtıEPSS %58

    proftpd · proftpd19 Tem 2019

  • CVE-2019-14287
    54Planlayın

    In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, a

    YüksekCVSS 8,8Kavram kanıtıEPSS %64

    sudo project · sudo17 Eki 2019

  • CVE-2023-36933
    52Planlayın

    In Progress MOVEit Transfer before 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), it is

    YüksekCVSS 7,5İstismar yokEPSS %72

    progress · moveit transfer5 Tem 2023

  • CVE-2018-0934
    50Planlayın

    ChakraCore and Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the Chakr

    YüksekCVSS 7,5Kavram kanıtıEPSS %66

    microsoft · edge14 Mar 2018

  • CVE-2019-6848
    44Planlayın

    A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 CPU (BMEx58*) and Modicon M580 communication mod

    YüksekCVSS 8,6İstismar yokEPSS %33

    schneider-electric · modicon m580 firmware29 Eki 2019

  • CVE-2019-17195
    42Planlayın

    Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash

    KritikCVSS 9,8Kavram kanıtıEPSS %11

    connect2id · nimbus jose\+jwt15 Eki 2019

  • CVE-2022-23121
    42Planlayın

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk.

    KritikCVSS 9,8İstismar yokEPSS %9

    netatalk · netatalk28 Mar 2023

  • CVE-2020-5807
    40Planlayın

    An unauthenticated remote attacker can send data to RsvcHost.exe listening on TCP port 5241 to add entries in the FactoryTalk Diagnostics ev

    YüksekCVSS 7,5İstismar yokEPSS %34

    rockwellautomation · factorytalk diagnostics29 Ara 2020

  • CVE-2024-21907
    40Planlayın

    Improper Handling of Exceptional Conditions in Newtonsoft.Json

    YüksekCVSS 7,5Kavram kanıtıEPSS %33

    newtonsoft · json.net3 Oca 2024

  • CVE-2019-14378
    40Planlayın

    ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a case involving the firs

    YüksekCVSS 8,8Kavram kanıtıEPSS %17

    libslirp project · libslirp29 Tem 2019

  • CVE-2021-43272
    40Planlayın

    An improper handling of exceptional conditions vulnerability exists in Open Design Alliance ODA Viewer sample before 2022.11.

    KritikCVSS 9,8İstismar yokEPSS %4

    opendesign · oda viewer14 Kas 2021

  • CVE-2019-14431
    40Planlayın

    In MatrixSSL 3.8.3 Open through 4.2.1 Open, the DTLS server mishandles incoming network messages leading to a heap-based buffer overflow of

    KritikCVSS 9,8İstismar yokEPSS %4

    matrixssl · matrixssl29 Tem 2019

  • CVE-2020-24753
    40Planlayın

    A memory corruption vulnerability in Objective Open CBOR Run-time (oocborrt) in versions before 2020-08-12 could allow an attacker to execut

    KritikCVSS 9,8İstismar yokEPSS %3

    objective open cbor run-time project · objective open cbor run-time17 Eyl 2020

  • CVE-2019-6256
    40Planlayın

    A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0.93.

    KritikCVSS 9,8İstismar yokEPSS %2

    live555 · live555 media server14 Oca 2019

  • CVE-2018-19991
    40Planlayın

    VeryNginx 0.3.3 allows remote attackers to bypass the Web Application Firewall feature because there is no error handler (for get_uri_args o

    KritikCVSS 9,8İstismar yokEPSS %2

    verynginx project · verynginx9 Ara 2018

  • CVE-2022-31799
    40Planlayın

    Bottle before 0.12.20 mishandles errors during early request binding.

    KritikCVSS 9,8İstismar yokEPSS %2

    bottlepy · bottle2 Haz 2022

  • CVE-2017-2877
    40Planlayın

    A missing error check exists in the Multi-Camera interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43.

    KritikCVSS 9,8İstismar yokEPSS %2

    foscam · c1 firmware19 Eyl 2018

  • CVE-2021-36128
    39İzleyin

    An issue was discovered in the CentralAuth extension in MediaWiki through 1.36.

    KritikCVSS 9,8İstismar yokEPSS %1

    mediawiki · mediawiki2 Tem 2021

  • CVE-2021-38384
    39İzleyin

    Serverless Offline 8.0.0 returns a 403 HTTP status code for a route that has a trailing / character, which might cause a developer to implem

    KritikCVSS 9,8İstismar yokEPSS %1

    serverless offline project · serverless offline10 Ağu 2021

  • CVE-2022-48328
    39İzleyin

    app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters.

    KritikCVSS 9,8İstismar yokEPSS %1

    misp-project · misp20 Şub 2023

  • CVE-2023-28631
    39İzleyin

    Attacker controlled data in AST nodes is not validated in comrak

    KritikCVSS 9,8İstismar yokEPSS %1

    comrak project · comrak28 Mar 2023

  • CVE-2009-5043
    39İzleyin

    burn allows file names to escape via mishandled quotation marks

    KritikCVSS 9,8İstismar yokEPSS %1

    burn project · burn31 Eki 2019

Tüm zafiyet sınıfları