CWE-670

Always-Incorrect Control Flow Implementation

Parent: CWE-691 - Insufficient Control Flow Management

The code contains a control flow path that does not reflect the algorithm that the path is intended to implement, leading to incorrect behavior any time this path is navigated.

142 vulnerabilities with CWE-670
CVE-2024-47168 MEDIUM
gradio < 4.44.0 - Unauthenticated Data Exposure via Monitoring Endpoint
CVSS 4.3
CVE-2024-47763 MEDIUM
Wasmtime 12.0.0-20.0.x (tail calls enabled) and 21.0.0-25.0.1 - Denial of Service via Tail Call Stack Trace Capture
CVSS 5.5
CVE-2024-20480 HIGH
Cisco IOS XE - Denial of Service via DHCP Snooping IPv4 Packet Handling
CVSS 8.6
CVE-2024-45807 HIGH
Envoy 1.31.0-1.31.1 - Denial of Service via oghttp2 Stream Management
CVSS 7.5
CVE-2024-45298 MEDIUM
Wiki.js 2.5.303 - Account Disabling Bypass via Password Reset
CVSS 4.3
CVE-2024-45311 HIGH
quinn 0.11.0-0.11.3 and quinn-proto 0.11.0-0.11.6 - Denial of Service via Unvalidated Connection Retry
CVSS 7.5
CVE-2024-45304 MEDIUM
Cairo-Contracts - Privilege Escalation
CVSS 5.3
CVE-2024-5659 MEDIUM
Rockwell Automation ControlLogix 5580 Firmware - Denial of Service via mDNS Packet
CVSS 6.5
CVE-2024-32896 HIGH KEV
Android - Local Privilege Escalation via Logic Error
CVSS 7.8
CVE-2024-37153 HIGH
evmos < 18.1.0 - Always-Incorrect Control Flow Implementation in ICS20 Transfer
CVSS 7.5
CVE-2024-35195 MEDIUM
Requests < 2.32.0 - Always-Incorrect Control Flow Implementation in Session Certificate Verification
CVSS 5.6
CVE-2024-35312 MEDIUM
Tor Arti 1.2.2 - Always-Incorrect Control Flow Implementation
CVSS 6.2
CVE-2024-35190 MEDIUM
Asterisk <18.23.0 - Info Disclosure
CVSS 5.8
CVE-2024-32971 CRITICAL
Apollo Router - Unintended Operations
CVSS 9.0
CVE-2024-33431 MEDIUM
phiola v2.0-rc22 - Denial of Service via Crafted WAV File
CVSS 6.5
CVE-2024-3376 HIGH
SourceCodester Computer Laboratory Management System 1.0 - RCE
CVSS 7.3
CVE-2024-30246 HIGH
Tuleap 14.11.99.34-15.7.99.5, 14.12-1-14.12-5 - Unauthenticated Information Disclosure and Data Deletion
CVSS 7.6
CVE-2024-0313 MEDIUM
Temporary Bypass - Privilege Escalation
CVSS 5.5
CVE-2023-52781 MEDIUM
Linux Kernel 3.16.79-3.17 - Always-Incorrect Control Flow Implementation in BOS Descriptor Parsing
CVSS 5.5
CVE-2023-52742 MEDIUM
Linux Kernel 2.6.14-4.14.306 - Incorrect Control Flow Implementation in plusb.c
CVSS 5.5
CVE-2023-46840 MEDIUM
Xen >= 4.17 - Always-Incorrect Control Flow Implementation
CVSS 4.1
CVE-2023-31211 HIGH
Checkmk <2.2.0p18-2.0.0p39 - Auth Bypass
CVSS 8.8
CVE-2023-49798 MEDIUM
OpenZeppelin Contracts <4.9.4 - Info Disclosure
CVSS 5.9
CVE-2023-41338 MEDIUM
Fiber < 2.49.2 - Unauthenticated Localhost Access Control Bypass via X-Forwarded-For Header
CVSS 5.3
CVE-2023-23623 HIGH
Electron 22.0.0-beta.1-22.0.0 - Always-Incorrect Control Flow Implementation via Disabled Sandbox
CVSS 7.5
Details
Vulnerabilities 142