CWE-697

Incorrect Comparison

The product compares two entities in a security-relevant context, but the comparison is incorrect.

161 vulnerabilities with CWE-697
CVE-2023-36829 MEDIUM
Sentry 23.6.0-23.6.2 - Permissive Cross-domain Security Policy via Origin Header
CVSS 6.8
CVE-2023-32571 CRITICAL
System.Linq.Dynamic.Core 1.0.7.10-1.2.25 - Remote Code Execution via Untrusted Input Parsing
CVSS 9.8
CVE-2023-28936 MEDIUM
Apache OpenMeetings <7.1.0 - Info Disclosure
CVSS 5.3
CVE-2023-23762 MEDIUM
GitHub Enterprise Server <3.9 - Info Disclosure
CVSS 6.5
CVE-2023-27579 HIGH
TensorFlow < 2.12.0 - Denial of Service via Filter Input Channel Parameter
CVSS 7.5
CVE-2023-25675 HIGH
TensorFlow <2.12.0, 2.11.1 - Use After Free
CVSS 7.5
CVE-2023-25673 HIGH
TensorFlow <2.12.0, 2.11.1 - Info Disclosure
CVSS 7.5
CVE-2023-25669 HIGH
TensorFlow <2.12.0, 2.11.1 - Info Disclosure
CVSS 7.5
CVE-2023-25666 HIGH
TensorFlow <2.12.0-2.11.1 - Info Disclosure
CVSS 7.5
CVE-2022-29944 MEDIUM
ONOS 2.5.1 - Incorrect Path Comparison in Intent Framework
CVSS 5.3
CVE-2022-43621 HIGH
D-Link DIR-1935 Firmware < 1.02 - Unauthenticated Authentication Bypass via HNAP Login Request
CVSS 8.8
CVE-2022-27645 HIGH
NETGEAR R6700v3 Firmware - Unauthenticated Authentication Bypass via readycloud_control.cgi
CVSS 8.8
CVE-2022-47034 CRITICAL
playsms < 1.4.5 - Authentication Bypass via Type Juggling in /auth/fn.php
CVSS 9.8
CVE-2022-34366 MEDIUM
Dell SupportAssist < 3.11.2 Authenticated Information Disclosure via Cross-domain Whitelist
CVSS 6.5
CVE-2022-34888 LOW
Lenovo ThinkAgile VX3331 Firmware < 1.80_afbt20n - Authenticated Internal Service Access via Remote Mount Feature
CVSS 2.7
CVE-2022-23554 MEDIUM
Alpine < 1.10.4 - Authentication Filter Bypass via URI Path Manipulation
CVSS 6.5
CVE-2022-41317 MEDIUM
Squid 4.9-4.17 and 5.0.6-5.6 - Exposure of Sensitive Information via HTTPS Request to Internal Cache Manager URL
CVSS 6.5
CVE-2022-4293 MEDIUM
vim < 9.0.0804 - Floating Point Comparison with Incorrect Operator
CVSS 5.5
CVE-2022-39308 MEDIUM
GoCD 19.2.0-19.10.0 - Timing Attack via Access Token Validation
CVSS 6.5
CVE-2022-35091 MEDIUM
SWFTools - Denial of Service via DCTStream::readMCURow() Floating Point Exception
CVSS 5.5
CVE-2022-35962 HIGH
Zulip Mobile <27.189 - Info Disclosure
CVSS 8.0
CVE-2022-38230 MEDIUM
XPDF - Denial of Service via DCTStream::decodeImage() Floating Point Exception
CVSS 5.5
CVE-2022-36148 MEDIUM
fdkaac < 1.0.3 - Denial of Service via Floating Point Exception in wav_open
CVSS 5.5
CVE-2022-35434 MEDIUM
jpeg-quantsmooth <8879454 - Memory Corruption
CVSS 5.5
CVE-2022-34999 MEDIUM
JPEGDEC <be4843c - Memory Corruption
CVSS 5.5
Details
Vulnerabilities 161