CWE-754
Medium likelihoodImproper Check for Unusual or Exceptional Conditions
The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.
605 vulnerabilities with CWE-754
CVE-2019-15900
CRITICAL
slicer69 doas <6.2 - Privilege Escalation
CVSS 9.8
CVE-2019-0068
MEDIUM
Juniper Junos OS on SRX Series DoS via Multicast Packet Processing
CVSS 6.5
CVE-2019-17257
MEDIUM
IrfanView 4.53 - Exception Handler Chain Corruption in EXR Image Parser
CVSS 5.5
CVE-2019-11779
MEDIUM
Eclipse Mosquitto <1.7 - Buffer Overflow
CVSS 6.5
CVE-2019-6833
MEDIUM
Magelis HMI Panels - Info Disclosure
CVSS 6.5
CVE-2019-6831
HIGH
BMXNOR0200H Ethernet / Serial RTU Module - Denial of Service via High Volume IEC 60870-5-104 Packets
CVSS 8.6
CVE-2019-6813
HIGH
Schneider Electric Modicon M340 and BMXNOR0200H - Denial of Service via Truncated SNMP Packets
CVSS 7.5
CVE-2019-6811
HIGH
Modicon Quantum 140 NOE771x1 Firmware <= 6.9 - Denial of Service via Oversized IP Fragmented Packet
CVSS 7.5
CVE-2019-10051
HIGH
Suricata 4.1.3 - Denial of Service in SMB File Tracking
CVSS 7.5
CVE-2019-5020
MEDIUM
Yara 3.8.1 - Denial of Service via Malicious Binary File
CVSS 5.5
CVE-2019-1010239
HIGH
davegamble/cjson 1.7.8 - Denial of Service via Crafted JSON File
CVSS 7.5
CVE-2019-6819
HIGH
Modicon M340 < 3.01, M580 < 2.80, Quantum, and Premium - Denial of Service via Modbus Frame Handling
CVSS 7.5
CVE-2019-1849
HIGH
Cisco IOS XR 6.1.0-6.3.2 - Unauthenticated Denial of Service via EVPN Routing Information
CVSS 7.4
CVE-2019-11459
MEDIUM
GNOME Evince <3.32.0 - Memory Corruption
CVSS 5.5
CVE-2019-5673
MEDIUM
NVIDIA Jetson TX2 < R28.3 - Denial of Service via SMMU Fault Condition Mishandling
CVSS 6.1
CVE-2019-0036
CRITICAL
Junos OS - Improper Access Control via Stateless Firewall Filter Term Naming
CVSS 9.8
CVE-2019-7167
HIGH
Zcash <2018-10-28 - Privilege Escalation
CVSS 7.5
CVE-2019-9633
MEDIUM
GNOME GLib - Denial of Service via Crafted Web Site
CVSS 6.5
CVE-2019-5763
HIGH
Google Chrome < 72.0.3626.81 - Remote Code Execution via V8 Error Handling Failure
CVSS 8.8
CVE-2018-25007
LOW
Vaadin Flow 1.0.0-1.0.5 - Unauthenticated Element Property Update via UIDL Request Handler
CVSS 2.6
CVE-2018-7794
HIGH
Modicon M580 < 2.80, M340 < 3.01, Quantum/TSX < 3.20 - Denial of Service via Modbus TCP Invalid Index
CVSS 7.5
CVE-2018-20840
HIGH
Google API C++ Client < 2019-04-10 - Denial of Service via ID Token Handling
CVSS 8.6
CVE-2018-7857
HIGH
Modicon Premium, Quantum, M340, M580 Firmware - Denial of Service via Modbus Out-of-Bounds Variable Write
CVSS 7.5
CVE-2018-7856
HIGH
Modicon M580 < 2.90, M340 < 3.10, Quantum, and Premium - Denial of Service via Invalid Modbus Memory Block Write
CVSS 7.5
CVE-2018-7855
HIGH
Modicon M580 < 2.90, M340 < 3.10, Quantum, and Premium - Denial of Service via Invalid Modbus Breakpoint Parameters
CVSS 7.5
Details
Vulnerabilities
605
Exploit Likelihood
Medium