CWE-670
Always-Incorrect Control Flow Implementation
The code contains a control flow path that does not reflect the algorithm that the path is intended to implement, leading to incorrect behavior any time this path is navigated.
142 vulnerabilities with CWE-670
CVE-2022-31116
HIGH
ultrajson < 5.4.0 - Key Confusion and Value Overwrite via Improper Surrogate Pair Decoding
CVSS 7.5
CVE-2022-31017
LOW
Zulip 2.1.0-5.2 - Unauthorized Message Exposure via Stream Edit Event
CVSS 2.0
CVE-2022-29255
HIGH
vyper < 0.3.4 - Always-Incorrect Control Flow Implementation in External Contract Calls
CVSS 8.2
CVE-2022-26890
HIGH
F5 BIG-IP <16.1.2.1, <15.1.5, <14.1.4.6, <13.1.5 - DoS
CVSS 7.5
CVE-2022-21655
HIGH
envoyproxy/envoy < 1.18.6 - Denial of Service via Internal Redirect to Direct Response Route
CVSS 7.5
CVE-2022-21679
MEDIUM
Istio 1.12.0-1.12.1 - Authorization Policy Bypass via Incorrect Envoy API Usage
CVSS 6.8
CVE-2021-43819
HIGH
Stargate-Bukkit <0.11.5.1 - Info Disclosure
CVSS 7.5
CVE-2021-45852
MEDIUM
Projectworlds Hospital Management System 1.0 - Info Disclosure
CVSS 5.3
CVE-2021-38019
MEDIUM
Google Chrome <96.0.4664.45 - Info Disclosure
CVSS 6.5
CVE-2021-43839
HIGH
Cronos < 0.6.5 - Transaction Fee Theft via Custom MsgEthereumTx
CVSS 7.5
CVE-2021-43979
MEDIUM
Styra Open Policy Agent (OPA) Gatekeeper <3.7.0 - Info Disclosure
CVSS 5.3
CVE-2021-41153
HIGH
evm < 0.31.0 - Always-Incorrect Control Flow Implementation in JUMPI Opcode
CVSS 8.7
CVE-2021-34767
HIGH
Cisco IOS XE Wireless Controller Software - Unauthenticated Denial of Service via IPv6 Traffic Processing
CVSS 7.4
CVE-2021-37605
HIGH
Microchip MiWi <6.5 - Buffer Overflow
CVSS 7.5
CVE-2021-37604
HIGH
Microchip MiWi - Denial of Service via Frame Counter Validation Bypass
CVSS 7.5
CVE-2021-0517
HIGH
Android 11 - Incorrect Network State Determination in ConnectivityService
CVSS 7.5
CVE-2021-32684
MEDIUM
magento-scripts <1.5.3 - Info Disclosure
CVSS 6.2
CVE-2021-0273
MEDIUM
Juniper Junos OS and Junos OS Evolved - Denial of Service via Infinite Loop in Trio Chipset PFE UCODE
CVSS 5.3
CVE-2021-1236
MEDIUM
Cisco IOS XE < 17.4.1 - Unauthenticated Policy Bypass via Snort Detection Algorithm Flaw
CVSS 5.3
CVE-2021-3011
MEDIUM
NXP SmartMX/P5x/A7x - Info Disclosure
CVSS 4.2
CVE-2020-36277
HIGH
leptonica < 1.80.0 - Denial of Service via Incorrect Left Shift in pixConvert2To8
CVSS 7.5
CVE-2020-35477
MEDIUM
MediaWiki <1.35.1 - Info Disclosure
CVSS 5.3
CVE-2020-26506
MEDIUM
Marmind 4.1.141.0 - Authorization Bypass
CVSS 4.3
CVE-2020-1914
CRITICAL
Facebook Hermes < 2020-10-01 - Always-Incorrect Control Flow Implementation in SaveGeneratorLong Instruction
CVSS 9.8
CVE-2020-3596
MEDIUM
Cisco Expressway and TelePresence VCS < 12.6.3 - Unauthenticated Denial of Service via SIP Traffic
CVSS 5.9
Details
Vulnerabilities
142