CWE-617

Reachable Assertion

Parent: CWE-705 - Incorrect Control Flow Scoping

The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

750 vulnerabilities with CWE-617
CVE-2018-12687 HIGH
tinyexr 0.9.5 - Reachable Assertion in DecodePixelData
CVSS 7.5
CVE-2018-12504 HIGH
tinyexr 0.9.5 - Reachable Assertion in ComputeChannelLayout
CVSS 7.5
CVE-2018-10963 MEDIUM
libtiff < 4.0.9 - Denial of Service via TIFFWriteDirectorySec Assertion Failure
CVSS 6.5
CVE-2018-9303 MEDIUM
exiv2 < 0.26 - Reachable Assertion in BigTiffImage::readData
CVSS 6.5
CVE-2018-9252 MEDIUM
JasPer 2.0.14 - Denial of Service via Reachable Assertion in jpc_abstorelstepsize
CVSS 6.5
CVE-2018-4113 MEDIUM
Safari < 11.1 - Denial of Service via JavaScriptCore Array Indexing
CVSS 6.5
CVE-2018-9055 MEDIUM
JasPer 2.0.14 - Denial of Service via Reachable Assertion in jpc_firstone
CVSS 5.5
CVE-2018-7714 HIGH
OpenCV 3.4.1 - Denial of Service via validateInputImageSize Assertion Failure
CVSS 7.5
CVE-2018-7713 HIGH
OpenCV 3.4.1 - Denial of Service via validateInputImageSize Assertion Failure
CVSS 7.5
CVE-2018-7712 HIGH
OpenCV 3.4.1 - Denial of Service via validateInputImageSize Assertion Failure
CVSS 7.5
CVE-2018-5269 MEDIUM
OpenCV 3.3.1 - Reachable Assertion in cv::RBaseStream::setPos
CVSS 5.5
CVE-2017-3139 HIGH
Red Hat Enterprise Linux Server AUS - Denial of Service via DNSSEC Validation Assertion Failure
CVSS 7.5
CVE-2017-3138 MEDIUM
BIND 9.9.9-9.11.1rc2 - Denial of Service via Null Command String
CVSS 6.5
CVE-2017-3137 HIGH
BIND 9.9.9-P6 to 9.11.1rc1 - Reachable Assertion via CNAME/DNAME Ordering
CVSS 7.5
CVE-2017-3136 MEDIUM
BIND 9.8.0-9.8.8-P1, 9.9.0-9.9.9-S8, 9.10.0-9.10.5rc1, 9.11.0-9.11.1rc1 - DoS via DNS64 Query
CVSS 5.9
CVE-2017-7539 MEDIUM
Qemu < 2.10.1 - Denial of Service via NBD Server Connection Negotiation
CVSS 5.3
CVE-2017-18169 MEDIUM
Android - Denial of Service in ashmem Cache Maintenance
CVSS 5.5
CVE-2017-18252 MEDIUM
ImageMagick 7.0.7 - Denial of Service via Crafted File in MogrifyImageList
CVSS 6.5
CVE-2017-17722 MEDIUM
Exiv2 0.26 - Denial of Service via Crafted TIFF File
CVSS 6.5
CVE-2017-16818 MEDIUM
Ceph 12.1.0-12.2.1 - Authenticated Denial of Service via Invalid Profile Post to Admin API
CVSS 6.5
CVE-2017-17432 HIGH
OpenAFS 1.0-1.6.21 - Denial of Service via Rx Ack Packet Validation
CVSS 7.5
CVE-2017-15371 MEDIUM
Sound eXchange 14.4.2 - Denial of Service via Reachable Assertion in sox_append_comment
CVSS 5.5
CVE-2017-1000252 MEDIUM
Linux Kernel < 4.13.3 - Denial of Service via Out-of-Bounds Guest IRQ Value
CVSS 5.5
CVE-2017-14649 MEDIUM
GraphicsMagick 1.3.26 - Denial of Service via JNG Data Validation
CVSS 5.5
CVE-2017-12168 MEDIUM
Linux kernel < 4.8.11 - Denial of Service via KVM PMCCNTR Access
CVSS 6.0
Details
Vulnerabilities 750