CWE-754

Medium likelihood

Improper Check for Unusual or Exceptional Conditions

Parent: CWE-703 - Improper Check or Handling of Exceptional Conditions

The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.

605 vulnerabilities with CWE-754
CVE-2024-4367 HIGH
Firefox < 126 and ESR < 115.11 - Arbitrary JavaScript Execution in PDF.js via Missing Type Check
CVSS 8.8
CVE-2024-34360 HIGH
go-spacemesh < 1.5.2-hotfix1 and api < 1.37.1 - Improper ATX Chain Validation
CVSS 8.2
CVE-2024-32867 MEDIUM
Suricata 6.0.0-6.0.18 - Rule and Policy Mis-detection via Fragmentation Anomaly Handling
CVSS 5.3
CVE-2024-3729 CRITICAL
Frontend Admin by DynamiApps <= 3.19.4 - Privilege Escalation & Auth Bypass via Encryption Handling
CVSS 9.8
CVE-2024-4182 MEDIUM
Mattermost 8.1.0-8.1.11, 9.4.0-9.4.4, 9.5.0-9.5.2 - Authenticated Denial of Service via Malformed Custom Status JSON
CVSS 4.3
CVE-2024-30402 MEDIUM
Juniper Junos OS and Junos OS Evolved - Unauthenticated Denial of Service via l2ald Crash
CVSS 5.9
CVE-2024-30397 HIGH
Juniper Junos Multiple Versions - Unauthenticated DoS in PKI Daemon
CVSS 7.5
CVE-2024-30384 MEDIUM
Juniper Junos OS < 20.4R3-S10; 21.2 < 21.2R3-S7; 21.4 < 21.4R3-S6 - Authenticated Denial of Service via CLI Command
CVSS 5.5
CVE-2024-30409 MEDIUM
Juniper Junos OS and Junos OS Evolved 22.1-22.1R1 - Authenticated Denial of Service via Telemetry Processing
CVSS 5.3
CVE-2024-1713 HIGH
plv8 3.2.1 - Privilege Escalation via Deferred Trigger Execution
CVSS 7.2
CVE-2024-20037 MEDIUM
Android - Local Privilege Escalation via Incorrect Bounds Check in pq
CVSS 6.7
CVE-2024-1622 HIGH
Routinator < 0.13.2 - Denial of Service via RTR Connection Reset
CVSS 7.5
CVE-2024-1556 MEDIUM
Firefox < 123.0 - Invalid Memory Access via Built-in Profiler NULL Check
CVSS 6.5
CVE-2024-25739 MEDIUM
Linux Kernel < 6.7.4 - Denial of Service via Zero-Byte Allocation in UBI Volume Table
CVSS 5.5
CVE-2024-23650 MEDIUM
BuildKit < 0.12.5 - Denial of Service via Crafted Frontend Request
CVSS 5.3
CVE-2024-24567 MEDIUM
vyperlang/vyper < 0.3.10 - Incorrect Value Handling in raw_call Builtin
CVSS 4.8
CVE-2024-0675 MEDIUM
Lamassu Bitcoin ATM Douro <7.1 - Privilege Escalation
CVSS 6.3
CVE-2024-22422 HIGH
AnythingLLM < 2024-01-18 - Unauthenticated Denial of Service via File Export Endpoint
CVSS 7.5
CVE-2024-21614 HIGH
Juniper Junos OS and Junos OS Evolved 22.2-22.3 - Unauthenticated Denial of Service via Dynamic Rendering Query
CVSS 7.5
CVE-2024-21603 MEDIUM
Juniper Junos OS - Denial of Service via SCU/DCU Statistics Collection
CVSS 6.5
CVE-2023-28910 HIGH
Volkswagen MIB3 infotainment system MIB3 OI MQB <0304 - Assertion Bypass via Disabled Abortion Flag in Bluetooth Stack
CVSS 8.0
CVE-2023-52710 HIGH
Huawei Matebook D16 BIOS v2.26 - Improper Check for Unusual or Exceptional Conditions in Communication Buffer
CVSS 7.8
CVE-2023-52678 MEDIUM
Linux Kernel - Denial of Service via Empty List Handling in kfd_topology.c
CVSS 5.5
CVE-2023-38420 LOW
Intel(R) Power Gadget - Info Disclosure
CVSS 3.8
CVE-2023-32871 MEDIUM
Yocto - Local Privilege Escalation via Incorrect Status Check
CVSS 5.3
Details
Vulnerabilities 605
Exploit Likelihood Medium