CWE-670

Always-Incorrect Control Flow Implementation

Parent: CWE-691 - Insufficient Control Flow Management

The code contains a control flow path that does not reflect the algorithm that the path is intended to implement, leading to incorrect behavior any time this path is navigated.

142 vulnerabilities with CWE-670
CVE-2023-41058 HIGH
Parse Server < 5.5.5 - Always-Incorrect Control Flow Implementation in beforeFind Trigger
CVSS 7.5
CVE-2023-41052 LOW
vyperlang/vyper < 0.3.9 and pypi/vyper < 0.3.10rc1 - Always-Incorrect Control Flow Implementation in Builtin Functions
CVSS 3.7
CVE-2023-40015 LOW
vyperlang/vyper < 0.3.9 - Always-Incorrect Control Flow Implementation
CVSS 3.7
CVE-2023-41376 HIGH
Nokia SR OS/SR Linux <22.10 - Info Disclosure
CVSS 7.5
CVE-2023-28711 MEDIUM
Intel Hyperscan Library < 5.4.1 - Authenticated Denial of Service via Local Access
CVSS 5.5
CVE-2023-39152 MEDIUM
Jenkins Gradle Plugin 2.8 - Info Disclosure
CVSS 6.5
CVE-2023-32675 LOW
vyperlang/vyper < 0.3.8 - Incorrect Fund Transfer via Nonpayable Default Function
CVSS 3.7
CVE-2023-30629 HIGH
vyper 0.3.1-0.3.7 - Always-Incorrect Control Flow Implementation in raw_call
CVSS 7.5
CVE-2023-1668 HIGH
Open vSwitch 1.5.0-2.13.10 - Always-Incorrect Control Flow Implementation in IP Packet Handling
CVSS 8.2
CVE-2023-20558 HIGH
AmdCpmOemSmm - Privilege Escalation
CVSS 8.8
CVE-2023-0400 MEDIUM
DLP for Windows <11.10.0 - Privilege Escalation
CVSS 5.9
CVE-2023-20921 HIGH
Android - Local Privilege Escalation via AccessibilityManagerService Logic Error
CVSS 7.3
CVE-2023-20915 HIGH
Android - Local Privilege Escalation via PhoneAccountRegistrar Logic Error
CVSS 7.8
CVE-2022-49393 MEDIUM
Linux Kernel 5.18-5.18.2 - Denial of Service via Incorrect List Iterator in fastrpc_req_mem_unmap_impl
CVSS 5.5
CVE-2022-29609 MEDIUM
ONOS 2.5.1 - Always-Incorrect Control Flow Implementation in Intent Framework
CVSS 5.3
CVE-2022-29607 HIGH
ONOS 2.5.1 - Always-Incorrect Control Flow Implementation in Intent Framework
CVSS 7.5
CVE-2022-29605 HIGH
ONOS 2.5.1 - Always-Incorrect Control Flow Implementation in IntentManager
CVSS 7.5
CVE-2022-25745 CRITICAL
Qualcomm Modem Firmware - Memory Corruption via CoAP Message Handling
CVSS 9.8
CVE-2022-2993 HIGH
Zephyrproject Zephyr Project Zephyr <= 3.1.0 - Insufficient Condition Check in smp_check_keys
CVSS 8.6
CVE-2022-41884 MEDIUM
TensorFlow < 2.8.4 - Denial of Service via Numpy Array Shape Validation
CVSS 4.8
CVE-2022-45196 HIGH
Hyperledger Fabric 2.3 - Denial of Service via Crafted Channel Transaction
CVSS 7.5
CVE-2022-39354 MEDIUM
SputnikVM <0.36.0 - Info Disclosure
CVSS 5.9
CVE-2022-26461 MEDIUM
Android - Local Privilege Escalation via vow API Misuse
CVSS 6.7
CVE-2022-35917 MEDIUM
Solana Pay <0.2.1 - Info Disclosure
CVSS 5.3
CVE-2022-31111 MEDIUM
Frontier - Incorrect Balance Conversion in EVM Compatibility Layer
CVSS 5.3
Details
Vulnerabilities 142