CWE-754

Medium likelihood

Improper Check for Unusual or Exceptional Conditions

Parent: CWE-703 - Improper Check or Handling of Exceptional Conditions

The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.

605 vulnerabilities with CWE-754
CVE-2022-21676 HIGH
Engine.IO 4.0.0-4.1.1, 5.0.0-5.2.0, 6.0.0-6.1.0 - Denial of Service via Crafted HTTP Request
CVSS 7.5
CVE-2021-47227 MEDIUM
Linux Kernel 5.8-5.10.46 - State Corruption via FPU Restore Signal Handling
CVSS 5.5
CVE-2021-47014 HIGH
Linux Kernel 5.8-5.12.3 - Memory Corruption via act_ct Fragment Handling
CVSS 7.8
CVE-2021-47007 MEDIUM
Linux Kernel 5.8-5.10.37 5.11.21 5.12.4 - Denial of Service via F2FS Resize Filesystem
CVSS 5.5
CVE-2021-46934 LOW
Linux Kernel 4.15-4.19.223 - Denial of Service via Invalid I2C Compat IOCTL User Data
CVSS 3.3
CVE-2021-46909 MEDIUM
Linux kernel 4.13.0-4.14.232 - Denial of Service via PCI Interrupt Mapping
CVSS 5.5
CVE-2021-32846 HIGH
HyperKit 0.20210107 - Memory Corruption
CVSS 7.7
CVE-2021-44856 MEDIUM
MediaWiki < 1.35.5, 1.36.x < 1.36.3, 1.37.x < 1.37.1 - AbuseFilter Bypass via Special:ChangeContentModel
CVSS 5.3
CVE-2021-35108 MEDIUM
Snapdragon Connectivity - Privilege Escalation
CVSS 6.8
CVE-2021-42020 HIGH
Siemens RUGGEDCOM ROS - Denial of Service via TFTP Null Termination Check Bypass
CVSS 7.5
CVE-2021-3560 HIGH KEV
polkit < 0.119 - Unauthenticated Privilege Escalation via D-Bus Request
CVSS 7.8
CVE-2021-33147 MEDIUM
Intel(R) IPP Crypto <2021.2 - Info Disclosure
CVSS 5.5
CVE-2021-33139 MEDIUM
Intel(R) Wireless Bluetooth(R)/Killer(TM) Bluetooth(R) <22.100 - DoS
CVSS 5.7
CVE-2021-22285 HIGH
ABB SPIET800 and PNI800 Firmware - Denial of Service via Improper Exception Handling
CVSS 7.5
CVE-2021-22816 HIGH
Schneider Electric SCADAPack E-Series Firmware < 8.19.1 - Denial of Service via Crafted Modbus Request
CVSS 7.5
CVE-2021-37862 LOW
Mattermost < 6.0 - Email Address Spoofing via Crafted Invitation Token
CVSS 3.7
CVE-2021-43801 HIGH
Mercurius 8.10.0-8.11.1 - Denial of Service via Malformed JSON to GraphQL Endpoint
CVSS 7.5
CVE-2021-25525 LOW
Samsung Pay < 4.0.65 - Unauthenticated NFC Access via Exception Handling Issue
CVSS 2.0
CVE-2021-41135 MEDIUM
Cosmos-SDK 0.43.0-0.44.2 - Consensus Halt via Non-Deterministic Grant Expiration Validation
CVSS 6.5
CVE-2021-31364 MEDIUM
Juniper Junos OS SRX300/SRX500/SRX1500/SRX5000 with SPC2 < 20.4R2 - Unauthenticated DoS via Flow Daemon Race Condition
CVSS 5.9
CVE-2021-31361 MEDIUM
Juniper Junos OS on QFX and PTX Series - Unauthenticated Denial of Service via VXLAN Encapsulated IP Packets
CVSS 5.3
CVE-2021-31351 HIGH
Juniper Junos OS - Denial of Service via MS-MPC/MS-MIC Packet Processing
CVSS 7.5
CVE-2021-25481 MEDIUM
Exynos CP <SMR Oct-2021 Release 1 - Privilege Escalation
CVSS 6.4
CVE-2021-39162 HIGH
Envoy < 1.18.4 and Pomerium < 0.15.1 - Denial of Service via H/2 GOAWAY and SETTINGS Frame
CVSS 8.6
CVE-2021-39196 HIGH
pcapture < 3.12 - Authenticated Unauthorized Packet Capture via REST API
CVSS 7.7
Details
Vulnerabilities 605
Exploit Likelihood Medium