CWE-755

Medium likelihood

Improper Handling of Exceptional Conditions

Parent: CWE-703 - Improper Check or Handling of Exceptional Conditions

The product does not handle or incorrectly handles an exceptional condition.

583 vulnerabilities with CWE-755
CVE-2022-20057 MEDIUM
Android - Memory Corruption in btif
CVSS 6.5
CVE-2022-22300 MEDIUM
Fortinet FortiAnalyzer/FortiManager <7.0.3 - Privilege Escalation
CVSS 4.3
CVE-2022-24615 MEDIUM
zip4j < 2.10.0 - Denial of Service via Crafted ZIP File Parsing
CVSS 5.5
CVE-2022-24613 MEDIUM
metadata-extractor < 2.18.0 - Denial of Service via Crafted JPEG File
CVSS 5.5
CVE-2022-0016 HIGH
Palo Alto Networks GlobalProtect 5.2 < 5.2.9 - Local Privilege Escalation via Connect Before Logon
CVSS 7.4
CVE-2022-21218 MEDIUM
Intel Trace Analyzer and Collector < 2021.5 - Authenticated Information Disclosure via Uncaught Exception
CVSS 5.5
CVE-2022-20042 MEDIUM
Android - Local Information Disclosure via Bluetooth Error Handling
CVSS 5.5
CVE-2022-21814 MEDIUM
NVIDIA GPU Display Driver for Linux - Denial of Service via Improper Permission Handling
CVSS 6.1
CVE-2022-21813 MEDIUM
NVIDIA GPU Display Driver for Linux - Unprivileged Local Write Access to Protected Memory
CVSS 6.1
CVE-2022-22150 HIGH
Foxit Software's PDF Reader <11.1.0.52543 - Memory Corruption
CVSS 8.8
CVE-2022-0264 MEDIUM
Linux kernel <5.16-rc6 - Info Disclosure
CVSS 5.5
CVE-2022-24448 LOW
Linux kernel <5.16.5 - Info Disclosure
CVSS 3.3
CVE-2022-23018 HIGH
BIG-IP AFM DoS via HTTP Protocol Security and HTTP Proxy Connect
CVSS 7.5
CVE-2022-22177 MEDIUM
Juniper Junos OS - Denial of Service via SNMP Daemon Memory Release
CVSS 5.3
CVE-2022-22174 HIGH
Juniper Networks Junos OS - Memory Corruption
CVSS 7.5
CVE-2022-22290 MEDIUM
Samsung Internet <16.0.6.23 - Open Redirect
CVSS 6.5
CVE-2022-21676 HIGH
Engine.IO 4.0.0-4.1.1, 5.0.0-5.2.0, 6.0.0-6.1.0 - Denial of Service via Crafted HTTP Request
CVSS 7.5
CVE-2022-21667 HIGH
soketi < 0.24.1 - Unauthenticated Denial of Service via Empty POST Request Body
CVSS 7.5
CVE-2021-46928 MEDIUM
Linux Kernel < 5.10.90 - Denial of Service via Stale IIR Value on Instruction Access Rights Trap
CVSS 5.5
CVE-2021-42146 HIGH
Contiki-NG tinyDTLS - Sensitive Data Exposure via DTLS Epoch Reuse
CVSS 7.5
CVE-2021-42145 HIGH
Contiki-NG tinyDTLS < 2018-08-30 - Denial of Service via Certificate Request Check
CVSS 7.5
CVE-2021-42142 CRITICAL
Contiki-NG tinyDTLS < 2018-08-30 - Denial of Service via Large Epoch Number Mishandling
CVSS 9.8
CVE-2021-42141 CRITICAL
Contiki-NG tinyDTLS < 2018-08-30 - Denial of Service via Handshake Epoch Mismatch
CVSS 9.8
CVE-2021-38363 HIGH
ONOS 2.5.1 - Denial of Service via IntentManager Exception Handling
CVSS 7.5
CVE-2021-4105 CRITICAL
BG-TEK COSLAT Firewall 5.24.0.R.20180630-5.24.0.R.20210727 - Remote Code Inclusion via Improper Parameter Handling
CVSS 9.8
Details
Vulnerabilities 583
Exploit Likelihood Medium