CWE-754

Medium likelihood

Improper Check for Unusual or Exceptional Conditions

Parent: CWE-703 - Improper Check or Handling of Exceptional Conditions

The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.

605 vulnerabilities with CWE-754
CVE-2024-42154 MEDIUM
Linux Kernel 3.14-6.9.8 - DoS via TCP Metrics Source Address Validation
CVSS 4.4
CVE-2024-42139 MEDIUM
Linux Kernel 5.14-6.9.8 - Denial of Service via Improper Extts Event Handling
CVSS 5.5
CVE-2024-40968 MEDIUM
Linux Kernel - Improper Check for Unusual or Exceptional Conditions
CVSS 5.5
CVE-2024-40963 MEDIUM
Linux Kernel 5.4.240-5.4.278 - Denial of Service via Invalid CBR Address Handling
CVSS 5.5
CVE-2024-40933 MEDIUM
Linux Kernel 6.8-6.9.5 - NULL Pointer Dereference in mlx90635_probe()
CVSS 5.5
CVE-2024-39545 HIGH
Juniper Junos OS - Unauthenticated Denial of Service via IKE Daemon Crash
CVSS 7.5
CVE-2024-39540 HIGH
Juniper Junos OS 21.2R3-S5 - Unauthenticated Denial of Service via TCP Traffic
CVSS 7.5
CVE-2024-39535 MEDIUM
Juniper Junos OS Evolved 22.4R2-S1 and 22.4R2-S2 - Unauthenticated Denial of Service in Packet Forwarding Engine
CVSS 6.5
CVE-2024-39530 HIGH
Juniper Junos OS 21.4R3-22.4R2 - Unauthenticated DoS via Sensor Access
CVSS 7.5
CVE-2024-39519 MEDIUM
Juniper Junos OS Evolved 22.2-22.4 - Unauthenticated Denial of Service via Multicast Traffic Loop
CVSS 6.5
CVE-2024-37151 MEDIUM
Suricata 6.0.0-6.0.19 - Policy Bypass via Fragmented Packet Reassembly Failure
CVSS 5.3
CVE-2024-39561 MEDIUM
Juniper Junos < 21.2 - Improper Condition Check
CVSS 5.8
CVE-2024-39559 MEDIUM
Juniper Junos OS Evolved < 21.2 - Improper Condition Check
CVSS 5.9
CVE-2024-39517 MEDIUM
Juniper Junos OS & Evolved < 21.4R3-S7 - DoS via EVPN/VXLAN Packet Processing
CVSS 6.5
CVE-2024-39869 MEDIUM
SINEMA Remote Connect Server < V3.2 SP1 - Authenticated Denial of Service via Crafted Certificate Upload
CVSS 6.5
CVE-2024-21586 HIGH
Juniper Junos OS SRX and NFX Series - Unauthenticated Denial-of-Service via Packet Forwarding Engine Crash
CVSS 7.5
CVE-2024-36481 MEDIUM
Linux Kernel < 6.6 - Denial of Service via Improper Error Handling in parse_btf_field()
CVSS 5.5
CVE-2024-38355 HIGH
Socket.IO < 2.5.1 and 3.0.0-4.6.2 - Denial of Service via Crafted Packet
CVSS 7.3
CVE-2024-38461 HIGH
iRODS < 4.3.2 - Denial of Service via Invalid Directory Path Handling
CVSS 7.5
CVE-2024-34694 HIGH
LNbits < 0.12.6 - Payment Timeout Handling Leading to Fund Loss
CVSS 8.1
CVE-2024-5469 LOW
GitLab 16.10.0-16.10.5 and 16.11.0-16.11.2 - Denial of Service via Crafted gRPC Requests
CVSS 3.1
CVE-2024-36128 HIGH
Directus < 10.11.2 - Denial of Service via Random String Generation Utility
CVSS 7.5
CVE-2024-4611 HIGH
AppPresser < 4.4.0 - Unauthenticated Authentication Bypass via Missing OpenSSL Exception Handling
CVSS 8.1
CVE-2024-35785 HIGH
Linux Kernel - Denial of Service via OP-TEE Device Registration Error Handling
CVSS 7.1
CVE-2024-21809 MEDIUM
Intel Quartus Prime < 23.1 - Authenticated Privilege Escalation via Local Access
CVSS 6.7
Details
Vulnerabilities 605
Exploit Likelihood Medium