CWE-754

Medium likelihood

Improper Check for Unusual or Exceptional Conditions

Parent: CWE-703 - Improper Check or Handling of Exceptional Conditions

The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.

588 vulnerabilities with CWE-754
CVE-2020-15223 HIGH
ORY Fosite <0.34.0 - Info Disclosure
CVSS 8.0
CVE-2020-14348 MEDIUM
AMQ Online < 1.5.2 - Denial of Service via Invalid AddressSpace Configuration Field
CVSS 4.3
CVE-2020-1122 MEDIUM
Windows 10 and Windows Server 2016/2019 - Elevation of Privilege via Language Pack Installer
CVSS 5.5
CVE-2020-5420 HIGH
Cloud Foundry Routing <0.206.0 - DoS
CVSS 7.7
CVE-2020-25056 HIGH
Android - Improper Version Check in NFC HAL
CVSS 7.5
CVE-2020-5925 HIGH
BIG-IP 11.6.1-15.1.0.4 DoS via TMM UDP Traffic Handling
CVSS 7.5
CVE-2020-3449 MEDIUM
Cisco IOS XR < 7.1.2 - Unauthenticated Denial of Service via BGP Additional Paths Feature
CVSS 4.3
CVE-2020-15658 MEDIUM
Firefox < 79.0 and Firefox ESR < 78.1 - File Extension Spoofing via Special Character Handling
CVSS 6.5
CVE-2020-15117 MEDIUM
Synergy < 1.12.0 - Denial of Service via Malformed kMsgHelloBack Packet
CVSS 6.5
CVE-2020-15566 MEDIUM
Xen 4.10.0-4.13.0 - Denial of Service via Event-Channel Port Allocation Error Handling
CVSS 6.5
CVE-2020-8334 MEDIUM
Lenovo ThinkPad - Privilege Escalation
CVSS 6.1
CVE-2020-13649 HIGH
JerryScript 2.2.0 - Denial of Service via Out-of-Memory Error Handling
CVSS 7.5
CVE-2020-7453 MEDIUM
FreeBSD Kernel Memory Disclosure via Jail osrelease Configuration
CVSS 6.0
CVE-2020-7800 HIGH
HUSKY RTU 6049-E70 <5.0 - Improper Check
CVSS 8.2
CVE-2020-8986 CRITICAL
ZendTo - Unauthenticated Administrative Access via Session Cookie Validation Flaw
CVSS 9.8
CVE-2020-7477 HIGH
Schneider Electric Quantum Ethernet Modules - Denial of Service via Modbus Command
CVSS 7.5
CVE-2020-7982 HIGH
OpenWrt 18.06.0-18.06.6, 19.07.0 & LEDE 17.01.0-17.01.7 - RCE via Opkg Checksum Bypass
CVSS 8.1
CVE-2020-10571 CRITICAL
psd-tools < 1.9.4 - Denial of Service via RLE Decoding
CVSS 9.8
CVE-2020-4217 HIGH
IBM Spectrum Scale 4.2.0.0-4.2.3.18 - Denial of Service via mmfsd/mmsdrserv Daemon Crash
CVSS 7.5
CVE-2020-6385 HIGH
Google Chrome <80.0.3987.87 - Auth Bypass
CVSS 8.8
CVE-2020-5215 MEDIUM
TensorFlow < 1.15.2 - Denial of Service via String to tf.float16 Conversion
CVSS 5.0
CVE-2019-20924 MEDIUM
MongoDB 4.2.0-4.2.1 - Denial of Service via IndexBoundsBuilder Invariant
CVSS 6.5
CVE-2019-8960 HIGH
FlexNet Publisher 11.16.2 - Denial of Service via Command Handling
CVSS 7.5
CVE-2019-15989 HIGH
Cisco IOS XR - Denial of Service via Malformed BGP Update Message
CVSS 8.6
CVE-2019-6857 HIGH
Modicon M580 < 2.80, M340 < 3.01, Quantum/TSX H/P 57 < 3.20 - Denial of Service via Modbus TCP Memory Block Read
CVSS 7.5
Details
Vulnerabilities 588
Exploit Likelihood Medium