CWE-697

Incorrect Comparison

The product compares two entities in a security-relevant context, but the comparison is incorrect.

161 vulnerabilities with CWE-697
CVE-2023-45213 MEDIUM
Westermo L206-f2g Firmware - Permissive CORS Policy
CVSS 6.6
CVE-2023-50940 MEDIUM
IBM PowerSC 1.3, 2.0, 2.1 - Permissive Cross-domain Security Policy with Untrusted Domains
CVSS 5.3
CVE-2023-49994 MEDIUM
Espeak-ng <1.52-dev - Memory Corruption
CVSS 5.5
CVE-2023-46660 MEDIUM
Jenkins Zanata Plugin <0.6 - Info Disclosure
CVSS 5.3
CVE-2023-46658 MEDIUM
Jenkins MSTeams Webhook Trigger Plugin <0.1.1 - Info Disclosure
CVSS 5.3
CVE-2023-46657 MEDIUM
Jenkins Gogs Plugin <1.0.15 - Info Disclosure
CVSS 5.3
CVE-2023-46656 MEDIUM
Jenkins Multibranch Scan Webhook Trigger Plugin <1.0.9 - Info Discl...
CVSS 5.3
CVE-2023-46009 HIGH
gifsicle 1.94 - Denial of Service via Floating Point Exception in resize_stream
CVSS 7.8
CVE-2023-45133 CRITICAL
Babel traverse <7.23.2 and 8.0.0-alpha.4 - Code Execution via path.evaluate
CVSS 9.3
CVE-2023-44378 HIGH
gnark < 0.9.0 - Incorrect Comparison via Field Overflow
CVSS 7.1
CVE-2023-23766 MEDIUM
GitHub Enterprise Server - Info Disclosure
CVSS 4.5
CVE-2023-23845 MEDIUM
SolarWinds Platform - Privilege Escalation
CVSS 6.8
CVE-2023-23840 MEDIUM
SolarWinds Platform - Privilege Escalation
CVSS 6.8
CVE-2023-40271 HIGH
Trusted Firmware-M < TF-Mv1.8.0 - Buffer Overflow
CVSS 7.5
CVE-2023-41936 HIGH
Jenkins Google Login Plugin <1.7 - Info Disclosure
CVSS 7.5
CVE-2023-41935 HIGH
Jenkins Azure AD Plugin < 396.v86ce29279947 - Non-Constant Time Comparison in CSRF Nonce Check
CVSS 7.5
CVE-2023-23765 MEDIUM
GitHub Enterprise Server - Info Disclosure
CVSS 4.8
CVE-2023-40037 MEDIUM
Apache NiFi 1.21.0-1.23.0 - Authenticated Connection URL Validation Bypass via Custom Input Formatting
CVSS 6.5
CVE-2023-23764 MEDIUM
GitHub Enterprise Server <3.7.9-3.9.1 - Info Disclosure
CVSS 4.8
CVE-2023-33225 HIGH
SolarWinds Platform - Privilege Escalation
CVSS 7.2
CVE-2023-23844 HIGH
SolarWinds Platform - Privilege Escalation
CVSS 7.2
CVE-2023-23843 HIGH
SolarWinds Platform - Privilege Escalation
CVSS 7.2
CVE-2023-22435 HIGH
Honeywell Experion Server 501.1-501.6hf8 - Denial of Service via Crafted Message
CVSS 7.5
CVE-2023-32627 MEDIUM
Sound Exchange - Denial of Service
CVSS 6.2
CVE-2023-26590 MEDIUM
sound_exchange - Denial of Service via Floating Point Exception in lsx_aiffstartwrite
CVSS 6.2
Details
Vulnerabilities 161