CWE-670

Always-Incorrect Control Flow Implementation

Parent: CWE-691 - Insufficient Control Flow Management

The code contains a control flow path that does not reflect the algorithm that the path is intended to implement, leading to incorrect behavior any time this path is navigated.

134 vulnerabilities with CWE-670
CVE-2024-32896 HIGH KEV
Android - Local Privilege Escalation via Logic Error
CVSS 7.8
CVE-2024-37153 HIGH
evmos < 18.1.0 - Always-Incorrect Control Flow Implementation in ICS20 Transfer
CVSS 7.5
CVE-2024-35195 MEDIUM
Requests < 2.32.0 - Always-Incorrect Control Flow Implementation in Session Certificate Verification
CVSS 5.6
CVE-2024-35312 MEDIUM
Tor Arti 1.2.2 - Always-Incorrect Control Flow Implementation
CVSS 6.2
CVE-2024-35190 MEDIUM
Asterisk <18.23.0 - Info Disclosure
CVSS 5.8
CVE-2024-32971 CRITICAL
Apollo Router - Unintended Operations
CVSS 9.0
CVE-2024-33431 MEDIUM
phiola v2.0-rc22 - Denial of Service via Crafted WAV File
CVSS 6.5
CVE-2024-3376 HIGH
SourceCodester Computer Laboratory Management System 1.0 - RCE
CVSS 7.3
CVE-2024-30246 HIGH
Tuleap 14.11.99.34-15.7.99.5, 14.12-1-14.12-5 - Unauthenticated Information Disclosure and Data Deletion
CVSS 7.6
CVE-2024-0313 MEDIUM
Temporary Bypass - Privilege Escalation
CVSS 5.5
CVE-2023-52781 MEDIUM
Linux Kernel 3.16.79-3.17 - Always-Incorrect Control Flow Implementation in BOS Descriptor Parsing
CVSS 5.5
CVE-2023-52742 MEDIUM
Linux Kernel 2.6.14-4.14.306 - Incorrect Control Flow Implementation in plusb.c
CVSS 5.5
CVE-2023-46840 MEDIUM
Xen >= 4.17 - Always-Incorrect Control Flow Implementation
CVSS 4.1
CVE-2023-31211 HIGH
Checkmk <2.2.0p18-2.0.0p39 - Auth Bypass
CVSS 8.8
CVE-2023-49798 MEDIUM
OpenZeppelin Contracts <4.9.4 - Info Disclosure
CVSS 5.9
CVE-2023-41338 MEDIUM
Fiber < 2.49.2 - Unauthenticated Localhost Access Control Bypass via X-Forwarded-For Header
CVSS 5.3
CVE-2023-23623 HIGH
Electron 22.0.0-beta.1-22.0.0 - Always-Incorrect Control Flow Implementation via Disabled Sandbox
CVSS 7.5
CVE-2023-41058 HIGH
Parse Server < 5.5.5 - Always-Incorrect Control Flow Implementation in beforeFind Trigger
CVSS 7.5
CVE-2023-41052 LOW
vyperlang/vyper < 0.3.9 and pypi/vyper < 0.3.10rc1 - Always-Incorrect Control Flow Implementation in Builtin Functions
CVSS 3.7
CVE-2023-40015 LOW
vyperlang/vyper < 0.3.9 - Always-Incorrect Control Flow Implementation
CVSS 3.7
CVE-2023-41376 HIGH
Nokia SR OS/SR Linux <22.10 - Info Disclosure
CVSS 7.5
CVE-2023-28711 MEDIUM
Intel Hyperscan Library < 5.4.1 - Authenticated Denial of Service via Local Access
CVSS 5.5
CVE-2023-39152 MEDIUM
Jenkins Gradle Plugin 2.8 - Info Disclosure
CVSS 6.5
CVE-2023-32675 LOW
vyperlang/vyper < 0.3.8 - Incorrect Fund Transfer via Nonpayable Default Function
CVSS 3.7
CVE-2023-30629 HIGH
vyper 0.3.1-0.3.7 - Always-Incorrect Control Flow Implementation in raw_call
CVSS 7.5
Details
Vulnerabilities 134