CWE-697

Incorrect Comparison

The product compares two entities in a security-relevant context, but the comparison is incorrect.

150 vulnerabilities with CWE-697
CVE-2020-23360 CRITICAL
oscommerce v2.3.4.1 - Info Disclosure
CVSS 9.8
CVE-2020-23359 CRITICAL
WeBid 1.2.2 - Incorrect Password Comparison in Admin User Registration
CVSS 9.8
CVE-2020-13559 HIGH
FreyrSCADA IEC-60879-5-104 Server Simulator 21.04.028 - Denial of Service via Traffic-Logging Packet Handling
CVSS 7.5
CVE-2020-25696 HIGH
PostgreSQL < 9.5.24 - Remote Code Execution via \gset in psql Interactive Terminal
CVSS 7.5
CVE-2020-15811 MEDIUM
Squid <4.13-5.0.4 - HTTP Request Splitting
CVSS 6.5
CVE-2020-15131 HIGH
SLP Validate <1.2.2 - Info Disclosure
CVSS 7.5
CVE-2020-15130 HIGH
slpjs < 0.27.4 - Incorrect NFT1 Child Genesis Transaction Validation
CVSS 7.5
CVE-2020-13485 CRITICAL
verbb knock_knock < 1.2.8 - IP Whitelist Bypass via X-Forwarded-For Header
CVSS 9.1
CVE-2020-11072 HIGH
SLP Validate <1.2.1 - Info Disclosure
CVSS 8.6
CVE-2020-11071 HIGH
slpjs < 0.27.2 - Incorrect Comparison in MINT Transaction Validation
CVSS 8.6
CVE-2020-10027 HIGH
Zephyrproject-RTOS >=1.14.0, >=2.1.0 - Privilege Escalation
CVSS 7.8
CVE-2020-10024 HIGH
Zephyr <2.1.0 - Privilege Escalation
CVSS 7.8
CVE-2020-1741 MEDIUM
OpenShift Container Platform 3.11 - CSRF
CVSS 5.9
CVE-2020-8864 HIGH
D-Link DIR-867,DIR-878,DIR-882 <1.10B04 - Auth Bypass
CVSS 8.8
CVE-2020-5849 HIGH KEV
unraid 6.8.0 - Authentication Bypass
CVSS 7.5
CVE-2020-8862 HIGH
D-Link DAP-2610 Firmware v2.01RC067 - Auth Bypass
CVSS 8.8
CVE-2019-20925 HIGH
MongoDB <4.2.1, <4.0.13, <3.6.15, <3.4.24 - DoS
CVSS 7.5
CVE-2019-20634 LOW
Proofpoint Email Protection - Info Disclosure
CVSS 3.7
CVE-2016-10003 HIGH
Squid 3.5.0.1-3.5.22 and 4.0.1-4.0.16 - Incorrect HTTP Request Header Comparison in Collapsed Forwarding
CVSS 7.5
CVE-2015-10129 LOW
planet-freo <20150116 - Info Disclosure
CVSS 3.7
CVE-2015-6964 MEDIUM
MultiBit HD <0.1.2 - Info Disclosure
CVSS 5.3
CVE-2015-9238 MEDIUM
secure-compare < 3.0.1 - Incorrect String Comparison
CVSS 5.3
CVE-2014-125057 LOW
robitailletheknot < 2014-11-10 - Incorrect Comparison in CSRF Token Handler
CVSS 3.1
CVE-2011-3903
Google Chrome < 16.0.912.63 - Denial of Service via Regex Matching Out-of-Bounds Read
CVE-2005-2801 HIGH
Linux Kernel - Incorrect Comparison in ext2/ext3 xattr Block Sharing
CVSS 7.5
Details
Vulnerabilities 150