CWE-755

Medium likelihood

Improper Handling of Exceptional Conditions

Parent: CWE-703 - Improper Check or Handling of Exceptional Conditions

The product does not handle or incorrectly handles an exceptional condition.

572 vulnerabilities with CWE-755
CVE-2019-1858 HIGH
Cisco FXOS/NX-OS - Memory Corruption
CVSS 8.6
CVE-2019-1731 MEDIUM
Cisco NX-OS < 7.0(3)I4(9) - Authenticated Private SSH Key Exposure via CLI Key Management
CVSS 4.4
CVE-2019-10917 MEDIUM
SIMATIC PCS 7 < 8.0 and WinCC < 7.2 - Denial of Service via Project File Loading
CVSS 5.5
CVE-2019-10742 HIGH
axios <= 0.18.0 - Denial of Service via maxContentLength Bypass
CVSS 7.5
CVE-2019-3565 HIGH
Facebook Thrift < 2019.05.06.00 - Denial of Service via Malicious Container Fields
CVSS 7.5
CVE-2019-3564 HIGH
Facebook Thrift < 2019.03.04.00 - Denial of Service via Malicious Container Fields
CVSS 7.5
CVE-2019-3559 HIGH
Facebook Thrift < 2019.02.18.00 - Denial of Service via Malicious Container Fields
CVSS 7.5
CVE-2019-3558 HIGH
Facebook Thrift < 2019.02.18.00 - Denial of Service via Malicious Container Field Messages
CVSS 7.5
CVE-2019-3552 HIGH
Facebook Thrift < 2019.02.18.00 - Denial of Service via Malformed Container Fields
CVSS 7.5
CVE-2019-1635 HIGH
Cisco IP Phone 7800 and 8800 Series - Denial of Service via Malicious XML Payload in SIP Packet
CVSS 7.5
CVE-2019-6575 HIGH
SIMATIC CP 443-1 OPC UA - Unauthenticated Denial of Service via Crafted Network Packets
CVSS 7.5
CVE-2019-9628 HIGH
XMLTooling <V3.0.4 - Info Disclosure
CVSS 7.5
CVE-2019-7474 MEDIUM
SonicWall SonicOS and SonicOSv - Denial of Service via Certificate Download
CVSS 6.5
CVE-2019-9735 MEDIUM
OpenStack Neutron <13.0.3 - Privilege Escalation
CVSS 6.5
CVE-2019-1691 MEDIUM
Cisco Firepower Threat Defense < 6.2.3.4 - Unauthenticated Denial of Service via SSL/TLS Packet Header
CVSS 5.8
CVE-2019-6256 CRITICAL
Live555 Media Server 0.93 - Denial of Service via RTSP-over-HTTP Tunneling x-sessioncookie Header
CVSS 9.8
CVE-2018-21088 HIGH
Android - Denial of Service via InputMethodManagerService
CVSS 7.5
CVE-2018-21091 HIGH
Samsung Android M(6.x) and N(7.x) - Denial of Service via Telecom Exception Handling
CVSS 7.5
CVE-2018-7852 HIGH
Modicon M580 M340 Quantum Premium Firmware - Denial of Service via Invalid Modbus Private Command Parameter
CVSS 7.5
CVE-2018-7849 HIGH
Modicon M580, M340, Quantum and Premium Firmware - Denial of Service via Modbus File Transfer
CVSS 7.5
CVE-2018-1677 MEDIUM
IBM DataPower Gateway 7.1.0.0-7.1.0.21 - Denial of Service via Full File System Handling
CVSS 5.1
CVE-2018-19991 CRITICAL
VeryNginx 0.3.3 - Web Application Firewall Bypass via API Misuse
CVSS 9.8
CVE-2018-11921 HIGH
Snapdragon Automobile/Wear/Mobile <various - Info Disclosure
CVSS 7.8
CVE-2018-16781 MEDIUM
ffjpeg < 2018-08-22 - Denial of Service via Progressive JPEG AC Huffman Table Handling
CVSS 6.5
CVE-2018-8039 HIGH
Apache CXF < 3.1.16 and 3.2.0-3.2.5 - Improper TLS Hostname Verification
CVSS 8.1
Details
Vulnerabilities 572
Exploit Likelihood Medium