CWE-670

Always-Incorrect Control Flow Implementation

Parent: CWE-691 - Insufficient Control Flow Management

The code contains a control flow path that does not reflect the algorithm that the path is intended to implement, leading to incorrect behavior any time this path is navigated.

134 vulnerabilities with CWE-670
CVE-2023-1668 HIGH
Open vSwitch 1.5.0-2.13.10 - Always-Incorrect Control Flow Implementation in IP Packet Handling
CVSS 8.2
CVE-2023-20558 HIGH
AmdCpmOemSmm - Privilege Escalation
CVSS 8.8
CVE-2023-0400 MEDIUM
DLP for Windows <11.10.0 - Privilege Escalation
CVSS 5.9
CVE-2023-20921 HIGH
Android - Local Privilege Escalation via AccessibilityManagerService Logic Error
CVSS 7.3
CVE-2023-20915 HIGH
Android - Local Privilege Escalation via PhoneAccountRegistrar Logic Error
CVSS 7.8
CVE-2022-49393 MEDIUM
Linux Kernel 5.18-5.18.2 - Denial of Service via Incorrect List Iterator in fastrpc_req_mem_unmap_impl
CVSS 5.5
CVE-2022-29609 MEDIUM
ONOS 2.5.1 - Always-Incorrect Control Flow Implementation in Intent Framework
CVSS 5.3
CVE-2022-29607 HIGH
ONOS 2.5.1 - Always-Incorrect Control Flow Implementation in Intent Framework
CVSS 7.5
CVE-2022-29605 HIGH
ONOS 2.5.1 - Always-Incorrect Control Flow Implementation in IntentManager
CVSS 7.5
CVE-2022-25745 CRITICAL
Qualcomm Modem Firmware - Memory Corruption via CoAP Message Handling
CVSS 9.8
CVE-2022-2993 HIGH
Zephyrproject Zephyr Project Zephyr <= 3.1.0 - Insufficient Condition Check in smp_check_keys
CVSS 8.6
CVE-2022-41884 MEDIUM
TensorFlow < 2.8.4 - Denial of Service via Numpy Array Shape Validation
CVSS 4.8
CVE-2022-45196 HIGH
Hyperledger Fabric 2.3 - Denial of Service via Crafted Channel Transaction
CVSS 7.5
CVE-2022-39354 MEDIUM
SputnikVM <0.36.0 - Info Disclosure
CVSS 5.9
CVE-2022-26461 MEDIUM
Android - Local Privilege Escalation via vow API Misuse
CVSS 6.7
CVE-2022-35917 MEDIUM
Solana Pay <0.2.1 - Info Disclosure
CVSS 5.3
CVE-2022-31111 MEDIUM
Frontier - Incorrect Balance Conversion in EVM Compatibility Layer
CVSS 5.3
CVE-2022-31116 HIGH
ultrajson < 5.4.0 - Key Confusion and Value Overwrite via Improper Surrogate Pair Decoding
CVSS 7.5
CVE-2022-31017 LOW
Zulip 2.1.0-5.2 - Unauthorized Message Exposure via Stream Edit Event
CVSS 2.0
CVE-2022-29255 HIGH
vyper < 0.3.4 - Always-Incorrect Control Flow Implementation in External Contract Calls
CVSS 8.2
CVE-2022-26890 HIGH
F5 BIG-IP <16.1.2.1, <15.1.5, <14.1.4.6, <13.1.5 - DoS
CVSS 7.5
CVE-2022-21655 HIGH
envoyproxy/envoy < 1.18.6 - Denial of Service via Internal Redirect to Direct Response Route
CVSS 7.5
CVE-2022-21679 MEDIUM
Istio 1.12.0-1.12.1 - Authorization Policy Bypass via Incorrect Envoy API Usage
CVSS 6.8
CVE-2021-43819 HIGH
Stargate-Bukkit <0.11.5.1 - Info Disclosure
CVSS 7.5
CVE-2021-45852 MEDIUM
Projectworlds Hospital Management System 1.0 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities 134