CWE-697
Incorrect Comparison
The product compares two entities in a security-relevant context, but the comparison is incorrect.
161 vulnerabilities with CWE-697
CVE-2023-45213
MEDIUM
Westermo L206-f2g Firmware - Permissive CORS Policy
CVSS 6.6
CVE-2023-50940
MEDIUM
IBM PowerSC 1.3, 2.0, 2.1 - Permissive Cross-domain Security Policy with Untrusted Domains
CVSS 5.3
CVE-2023-49994
MEDIUM
Espeak-ng <1.52-dev - Memory Corruption
CVSS 5.5
CVE-2023-46660
MEDIUM
Jenkins Zanata Plugin <0.6 - Info Disclosure
CVSS 5.3
CVE-2023-46658
MEDIUM
Jenkins MSTeams Webhook Trigger Plugin <0.1.1 - Info Disclosure
CVSS 5.3
CVE-2023-46657
MEDIUM
Jenkins Gogs Plugin <1.0.15 - Info Disclosure
CVSS 5.3
CVE-2023-46656
MEDIUM
Jenkins Multibranch Scan Webhook Trigger Plugin <1.0.9 - Info Discl...
CVSS 5.3
CVE-2023-46009
HIGH
gifsicle 1.94 - Denial of Service via Floating Point Exception in resize_stream
CVSS 7.8
CVE-2023-45133
CRITICAL
Babel traverse <7.23.2 and 8.0.0-alpha.4 - Code Execution via path.evaluate
CVSS 9.3
CVE-2023-44378
HIGH
gnark < 0.9.0 - Incorrect Comparison via Field Overflow
CVSS 7.1
CVE-2023-23766
MEDIUM
GitHub Enterprise Server - Info Disclosure
CVSS 4.5
CVE-2023-23845
MEDIUM
SolarWinds Platform - Privilege Escalation
CVSS 6.8
CVE-2023-23840
MEDIUM
SolarWinds Platform - Privilege Escalation
CVSS 6.8
CVE-2023-40271
HIGH
Trusted Firmware-M < TF-Mv1.8.0 - Buffer Overflow
CVSS 7.5
CVE-2023-41936
HIGH
Jenkins Google Login Plugin <1.7 - Info Disclosure
CVSS 7.5
CVE-2023-41935
HIGH
Jenkins Azure AD Plugin < 396.v86ce29279947 - Non-Constant Time Comparison in CSRF Nonce Check
CVSS 7.5
CVE-2023-23765
MEDIUM
GitHub Enterprise Server - Info Disclosure
CVSS 4.8
CVE-2023-40037
MEDIUM
Apache NiFi 1.21.0-1.23.0 - Authenticated Connection URL Validation Bypass via Custom Input Formatting
CVSS 6.5
CVE-2023-23764
MEDIUM
GitHub Enterprise Server <3.7.9-3.9.1 - Info Disclosure
CVSS 4.8
CVE-2023-33225
HIGH
SolarWinds Platform - Privilege Escalation
CVSS 7.2
CVE-2023-23844
HIGH
SolarWinds Platform - Privilege Escalation
CVSS 7.2
CVE-2023-23843
HIGH
SolarWinds Platform - Privilege Escalation
CVSS 7.2
CVE-2023-22435
HIGH
Honeywell Experion Server 501.1-501.6hf8 - Denial of Service via Crafted Message
CVSS 7.5
CVE-2023-32627
MEDIUM
Sound Exchange - Denial of Service
CVSS 6.2
CVE-2023-26590
MEDIUM
sound_exchange - Denial of Service via Floating Point Exception in lsx_aiffstartwrite
CVSS 6.2
Details
Vulnerabilities
161