CWE-670

Always-Incorrect Control Flow Implementation

Parent: CWE-691 - Insufficient Control Flow Management

The code contains a control flow path that does not reflect the algorithm that the path is intended to implement, leading to incorrect behavior any time this path is navigated.

142 vulnerabilities with CWE-670
CVE-2020-25603 HIGH
Xen < 4.14.0 - Denial of Service via Missing Memory Barriers in Event Channel Access
CVSS 7.8
CVE-2020-25598 MEDIUM
Xen 4.12.0-4.13.9 - Denial of Service via RCU Reference Leak in XENMEM_acquire_resource
CVSS 5.5
CVE-2020-17466 CRITICAL
Turcom TRCwifiZone < 2020-08-10 - Authentication Bypass via 302 Redirect Ignore
CVSS 9.8
CVE-2020-5753 MEDIUM
Signal Private Messenger - Info Disclosure
CVSS 5.3
CVE-2020-3885 MEDIUM
iCloud < 7.18 - Always-Incorrect Control Flow Implementation
CVSS 4.3
CVE-2020-9425 HIGH
rconfig < 3.9.4 - Unauthenticated Sensitive Information Disclosure via settings.php
CVSS 7.5
CVE-2019-19324 HIGH
Xmidt cjwt <1.0.1 - Info Disclosure
CVSS 7.5
CVE-2019-20430 HIGH
Lustre < 2.12.3 - Denial of Service via MDT Body eadatasize Field
CVSS 7.5
CVE-2019-19729 HIGH
BSON ObjectID 1.3.0 - Info Disclosure
CVSS 7.5
CVE-2019-17192 CRITICAL
Signal Private Messenger < 4.47.7 - Denial of Service via Malformed WebRTC RTP Packets
CVSS 9.8
CVE-2019-11412 HIGH
Artifex MuJS 1.0.5 - Denial of Service via Missing ENDTRY Opcode
CVSS 7.5
CVE-2019-9946 HIGH
CNCF CNI 0.7.4 - Privilege Escalation
CVSS 7.5
CVE-2018-19212 MEDIUM
libwebm < 1.0.0.27 - Denial of Service via Webm2Pes Parser Initialization
CVSS 6.5
CVE-2018-19058 MEDIUM
Poppler 0.71.0 - Denial of Service via Missing Stream Check in EmbFile::save2
CVSS 6.5
CVE-2018-16766 HIGH
WebAssembly Virtual Machine < 2018-07-26 - Denial of Service via Crafted File
CVSS 8.8
CVE-2017-0604 HIGH
Android < 7.1.2 - Local Privilege Escalation via Qualcomm Power Driver
CVSS 7.8
CVE-2014-2686 HIGH
Ansible < 1.5.4 - Always-Incorrect Control Flow Implementation
CVSS 7.5
Details
Vulnerabilities 142