CWE-755

Medium likelihood

Improper Handling of Exceptional Conditions

Parent: CWE-703 - Improper Check or Handling of Exceptional Conditions

The product does not handle or incorrectly handles an exceptional condition.

572 vulnerabilities with CWE-755
CVE-2021-37786 MEDIUM
COVID Certificate App iOS < 2.2.0 - Denial of Service via Crafted QR Code
CVSS 4.6
CVE-2021-32999 HIGH
AVEVA SuiteLink < 3.2.002 - Denial of Service via Command 0x01 Processing
CVSS 7.5
CVE-2021-37175 MEDIUM
Siemens RUGGEDCOM ROX Firmware < 2.14.1 - Unauthenticated Directory Traversal
CVSS 5.3
CVE-2021-3053 HIGH
Palo Alto Networks PAN-OS <8.1.20, <9.0 - DoS
CVSS 7.5
CVE-2021-39187 HIGH
parse-server < 4.10.3 - Denial of Service via Invalid Explain Query Option
CVSS 7.5
CVE-2021-1578 HIGH
Cisco APIC/Cloud APIC - Privilege Escalation
CVSS 8.8
CVE-2021-39157 HIGH
detect-character-encoding < 0.7.0 - Denial of Service via Unhandled Charset Matching
CVSS 7.5
CVE-2021-23429 MEDIUM
transpile - Denial of Service via Improper Exception Handling in .to() Function
CVSS 6.5
CVE-2021-34716 MEDIUM
Cisco Expressway and TelePresence VCS - Authenticated Remote Code Execution via Crafted Software Image Upload
CVSS 6.7
CVE-2021-39131 HIGH
ced < 1.0.0 - Denial of Service via Non-Buffer Data Type
CVSS 7.5
CVE-2021-39242 HIGH
HAProxy 2.2.0-2.2.15, 2.3.0-2.3.12, 2.4.0-2.4.2 - HTTP Host Header Handling Issue
CVSS 7.5
CVE-2021-21592 LOW
Dell EMC PowerScale OneFS 8.2.x-9.2.x - Unauthorized Information Disclosure via Exception Handling
CVSS 3.1
CVE-2021-0007 MEDIUM
Intel Ethernet Controller E810 Firmware < 1.5.1.0 - Denial of Service via Uncaught Exception
CVSS 4.4
CVE-2021-0006 MEDIUM
Intel Ethernet Controller E810 Firmware < 1.5.4.0 - Denial of Service via Improper Exception Handling
CVSS 4.4
CVE-2021-0005 MEDIUM
Intel Ethernet Controller E810 Firmware < 1.5.3.0 - Denial of Service via Uncaught Exception
CVSS 4.4
CVE-2021-0003 MEDIUM
Intel Ethernet Controller E810 Firmware < 1.4.11 - Authenticated Information Disclosure via Improper Exception Handling
CVSS 5.5
CVE-2021-38384 CRITICAL
Serverless Offline 8.0.0 - Info Disclosure
CVSS 9.8
CVE-2021-22922 MEDIUM
curl 7.27.0-7.77.0 - Unauthenticated Malicious Content Retention via Metalink Hash Mismatch
CVSS 6.5
CVE-2021-33486 HIGH
CODESYS V3 Runtime Toolkit for VxWorks <V3.5.17.10 - Memory Corruption
CVSS 7.5
CVE-2021-32066 HIGH
Ruby < 2.6.7, 2.7.x < 2.7.3, 3.x < 3.0.1 - TLS Protection Bypass via StartTLS Stripping
CVSS 7.4
CVE-2021-1102 MEDIUM
NVIDIA vGPU <12.3, <11.5, <8.8 - Memory Corruption
CVSS 5.5
CVE-2021-0290 MEDIUM
Juniper Junos OS 16.1-19.3 - Denial of Service via Ethernet Frame Processing
CVSS 6.5
CVE-2021-30639 HIGH
Apache Tomcat 10.0.3-10.0.4, 9.0.44, 8.5.64 - Denial of Service via Non-Blocking I/O Error Flag
CVSS 7.5
CVE-2021-33795 MEDIUM
Foxit Reader and PhantomPDF < 10.1.4 - Incorrect PDF Document Signature Handling
CVSS 5.5
CVE-2021-36128 CRITICAL
MediaWiki < 1.36 - Improper Handling of Exceptional Conditions in CentralAuth Autoblocks
CVSS 9.8
Details
Vulnerabilities 572
Exploit Likelihood Medium