CWE-754

Medium likelihood

Improper Check for Unusual or Exceptional Conditions

Parent: CWE-703 - Improper Check or Handling of Exceptional Conditions

The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.

588 vulnerabilities with CWE-754
CVE-2019-9633 MEDIUM
GNOME GLib - Denial of Service via Crafted Web Site
CVSS 6.5
CVE-2019-5763 HIGH
Google Chrome < 72.0.3626.81 - Remote Code Execution via V8 Error Handling Failure
CVSS 8.8
CVE-2018-25007 LOW
Vaadin Flow 1.0.0-1.0.5 - Unauthenticated Element Property Update via UIDL Request Handler
CVSS 2.6
CVE-2018-7794 HIGH
Modicon M580 < 2.80, M340 < 3.01, Quantum/TSX < 3.20 - Denial of Service via Modbus TCP Invalid Index
CVSS 7.5
CVE-2018-20840 HIGH
Google API C++ Client < 2019-04-10 - Denial of Service via ID Token Handling
CVSS 8.6
CVE-2018-7857 HIGH
Modicon Premium, Quantum, M340, M580 Firmware - Denial of Service via Modbus Out-of-Bounds Variable Write
CVSS 7.5
CVE-2018-7856 HIGH
Modicon M580 < 2.90, M340 < 3.10, Quantum, and Premium - Denial of Service via Invalid Modbus Memory Block Write
CVSS 7.5
CVE-2018-7855 HIGH
Modicon M580 < 2.90, M340 < 3.10, Quantum, and Premium - Denial of Service via Invalid Modbus Breakpoint Parameters
CVSS 7.5
CVE-2018-7854 HIGH
Modicon M580, M340, Quantum, and Premium - Denial of Service via Invalid Modbus Debug Parameters
CVSS 7.5
CVE-2018-7853 HIGH
Modicon M580 < 2.90, M340 < 3.10, Quantum, and Premium - Denial of Service via Invalid Physical Memory Block Read
CVSS 7.5
CVE-2018-7803 MEDIUM
Triconex TriStation Emulator V1.2.0 - Info Disclosure
CVSS 5.9
CVE-2018-4026 HIGH
Anker Roav A1 Dashcam Firmware - Denial of Service via XML_GetScreen Wi-Fi Command
CVSS 7.5
CVE-2018-15815 MEDIUM
FastStone Image Viewer 6.5 - Denial of Service via Crafted Image File
CVSS 5.5
CVE-2018-12189 MEDIUM
Intel Converged Security Management Engine Firmware < 11.8.60 - Improper Condition Check
CVSS 4.4
CVE-2018-7833 HIGH
Modicon M340, Premium, Quantum, and BMXNOR0200 Firmware - Denial of Service via Crafted XML POST Request
CVSS 7.5
CVE-2018-18690 MEDIUM
Linux Kernel < 4.17 - Denial of Service via XFS Attribute Handling
CVSS 5.5
CVE-2018-7789 HIGH
Schneider Electric Modicon M221 - Info Disclosure
CVSS 7.5
CVE-2018-13013 HIGH
SafenSoft Enterprise Suite, SysWatch, and TPSecure < 4.4.9 - Local Code-Signing Bypass via MSI File Forgery
CVSS 7.8
CVE-2018-7287 MEDIUM
Asterisk 15.x-15.2.1 - Denial of Service via WebSocket Payload
CVSS 5.9
CVE-2018-0005 HIGH
Juniper Junos OS - Denial of Service via MAC Move Limit Handling
CVSS 7.4
CVE-2017-20166 CRITICAL
Ecto 2.2.0 - Improper Check for Unusual or Exceptional Conditions in is_nil and raise Interaction
CVSS 9.8
CVE-2017-18914 MEDIUM
Mattermost Server <3.8.2-3.6.7 - Open Redirect
CVSS 5.3
CVE-2017-18657 MEDIUM
Samsung Mobile <M(6.0),N(7.x) - Arbitrary Write
CVSS 5.3
CVE-2017-18650 HIGH
Android - Denial of Service via Malformed wpa_supplicant.conf
CVSS 7.5
CVE-2017-12119 HIGH
cpp-ethereum - Denial of Service via Malicious JSON-RPC Request
CVSS 7.5
Details
Vulnerabilities 588
Exploit Likelihood Medium