CWE-754

Medium likelihood

Improper Check for Unusual or Exceptional Conditions

Parent: CWE-703 - Improper Check or Handling of Exceptional Conditions

The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.

605 vulnerabilities with CWE-754
CVE-2019-15900 CRITICAL
slicer69 doas <6.2 - Privilege Escalation
CVSS 9.8
CVE-2019-0068 MEDIUM
Juniper Junos OS on SRX Series DoS via Multicast Packet Processing
CVSS 6.5
CVE-2019-17257 MEDIUM
IrfanView 4.53 - Exception Handler Chain Corruption in EXR Image Parser
CVSS 5.5
CVE-2019-11779 MEDIUM
Eclipse Mosquitto <1.7 - Buffer Overflow
CVSS 6.5
CVE-2019-6833 MEDIUM
Magelis HMI Panels - Info Disclosure
CVSS 6.5
CVE-2019-6831 HIGH
BMXNOR0200H Ethernet / Serial RTU Module - Denial of Service via High Volume IEC 60870-5-104 Packets
CVSS 8.6
CVE-2019-6813 HIGH
Schneider Electric Modicon M340 and BMXNOR0200H - Denial of Service via Truncated SNMP Packets
CVSS 7.5
CVE-2019-6811 HIGH
Modicon Quantum 140 NOE771x1 Firmware <= 6.9 - Denial of Service via Oversized IP Fragmented Packet
CVSS 7.5
CVE-2019-10051 HIGH
Suricata 4.1.3 - Denial of Service in SMB File Tracking
CVSS 7.5
CVE-2019-5020 MEDIUM
Yara 3.8.1 - Denial of Service via Malicious Binary File
CVSS 5.5
CVE-2019-1010239 HIGH
davegamble/cjson 1.7.8 - Denial of Service via Crafted JSON File
CVSS 7.5
CVE-2019-6819 HIGH
Modicon M340 < 3.01, M580 < 2.80, Quantum, and Premium - Denial of Service via Modbus Frame Handling
CVSS 7.5
CVE-2019-1849 HIGH
Cisco IOS XR 6.1.0-6.3.2 - Unauthenticated Denial of Service via EVPN Routing Information
CVSS 7.4
CVE-2019-11459 MEDIUM
GNOME Evince <3.32.0 - Memory Corruption
CVSS 5.5
CVE-2019-5673 MEDIUM
NVIDIA Jetson TX2 < R28.3 - Denial of Service via SMMU Fault Condition Mishandling
CVSS 6.1
CVE-2019-0036 CRITICAL
Junos OS - Improper Access Control via Stateless Firewall Filter Term Naming
CVSS 9.8
CVE-2019-7167 HIGH
Zcash <2018-10-28 - Privilege Escalation
CVSS 7.5
CVE-2019-9633 MEDIUM
GNOME GLib - Denial of Service via Crafted Web Site
CVSS 6.5
CVE-2019-5763 HIGH
Google Chrome < 72.0.3626.81 - Remote Code Execution via V8 Error Handling Failure
CVSS 8.8
CVE-2018-25007 LOW
Vaadin Flow 1.0.0-1.0.5 - Unauthenticated Element Property Update via UIDL Request Handler
CVSS 2.6
CVE-2018-7794 HIGH
Modicon M580 < 2.80, M340 < 3.01, Quantum/TSX < 3.20 - Denial of Service via Modbus TCP Invalid Index
CVSS 7.5
CVE-2018-20840 HIGH
Google API C++ Client < 2019-04-10 - Denial of Service via ID Token Handling
CVSS 8.6
CVE-2018-7857 HIGH
Modicon Premium, Quantum, M340, M580 Firmware - Denial of Service via Modbus Out-of-Bounds Variable Write
CVSS 7.5
CVE-2018-7856 HIGH
Modicon M580 < 2.90, M340 < 3.10, Quantum, and Premium - Denial of Service via Invalid Modbus Memory Block Write
CVSS 7.5
CVE-2018-7855 HIGH
Modicon M580 < 2.90, M340 < 3.10, Quantum, and Premium - Denial of Service via Invalid Modbus Breakpoint Parameters
CVSS 7.5
Details
Vulnerabilities 605
Exploit Likelihood Medium