CWE-697
Incorrect Comparison
The product compares two entities in a security-relevant context, but the comparison is incorrect.
161 vulnerabilities with CWE-697
CVE-2023-36829
MEDIUM
Sentry 23.6.0-23.6.2 - Permissive Cross-domain Security Policy via Origin Header
CVSS 6.8
CVE-2023-32571
CRITICAL
System.Linq.Dynamic.Core 1.0.7.10-1.2.25 - Remote Code Execution via Untrusted Input Parsing
CVSS 9.8
CVE-2023-28936
MEDIUM
Apache OpenMeetings <7.1.0 - Info Disclosure
CVSS 5.3
CVE-2023-23762
MEDIUM
GitHub Enterprise Server <3.9 - Info Disclosure
CVSS 6.5
CVE-2023-27579
HIGH
TensorFlow < 2.12.0 - Denial of Service via Filter Input Channel Parameter
CVSS 7.5
CVE-2023-25675
HIGH
TensorFlow <2.12.0, 2.11.1 - Use After Free
CVSS 7.5
CVE-2023-25673
HIGH
TensorFlow <2.12.0, 2.11.1 - Info Disclosure
CVSS 7.5
CVE-2023-25669
HIGH
TensorFlow <2.12.0, 2.11.1 - Info Disclosure
CVSS 7.5
CVE-2023-25666
HIGH
TensorFlow <2.12.0-2.11.1 - Info Disclosure
CVSS 7.5
CVE-2022-29944
MEDIUM
ONOS 2.5.1 - Incorrect Path Comparison in Intent Framework
CVSS 5.3
CVE-2022-43621
HIGH
D-Link DIR-1935 Firmware < 1.02 - Unauthenticated Authentication Bypass via HNAP Login Request
CVSS 8.8
CVE-2022-27645
HIGH
NETGEAR R6700v3 Firmware - Unauthenticated Authentication Bypass via readycloud_control.cgi
CVSS 8.8
CVE-2022-47034
CRITICAL
playsms < 1.4.5 - Authentication Bypass via Type Juggling in /auth/fn.php
CVSS 9.8
CVE-2022-34366
MEDIUM
Dell SupportAssist < 3.11.2 Authenticated Information Disclosure via Cross-domain Whitelist
CVSS 6.5
CVE-2022-34888
LOW
Lenovo ThinkAgile VX3331 Firmware < 1.80_afbt20n - Authenticated Internal Service Access via Remote Mount Feature
CVSS 2.7
CVE-2022-23554
MEDIUM
Alpine < 1.10.4 - Authentication Filter Bypass via URI Path Manipulation
CVSS 6.5
CVE-2022-41317
MEDIUM
Squid 4.9-4.17 and 5.0.6-5.6 - Exposure of Sensitive Information via HTTPS Request to Internal Cache Manager URL
CVSS 6.5
CVE-2022-4293
MEDIUM
vim < 9.0.0804 - Floating Point Comparison with Incorrect Operator
CVSS 5.5
CVE-2022-39308
MEDIUM
GoCD 19.2.0-19.10.0 - Timing Attack via Access Token Validation
CVSS 6.5
CVE-2022-35091
MEDIUM
SWFTools - Denial of Service via DCTStream::readMCURow() Floating Point Exception
CVSS 5.5
CVE-2022-35962
HIGH
Zulip Mobile <27.189 - Info Disclosure
CVSS 8.0
CVE-2022-38230
MEDIUM
XPDF - Denial of Service via DCTStream::decodeImage() Floating Point Exception
CVSS 5.5
CVE-2022-36148
MEDIUM
fdkaac < 1.0.3 - Denial of Service via Floating Point Exception in wav_open
CVSS 5.5
CVE-2022-35434
MEDIUM
jpeg-quantsmooth <8879454 - Memory Corruption
CVSS 5.5
CVE-2022-34999
MEDIUM
JPEGDEC <be4843c - Memory Corruption
CVSS 5.5
Details
Vulnerabilities
161