CWE-755

Medium likelihood

Improper Handling of Exceptional Conditions

Parent: CWE-703 - Improper Check or Handling of Exceptional Conditions

The product does not handle or incorrectly handles an exceptional condition.

583 vulnerabilities with CWE-755
CVE-2023-1732 MEDIUM
cloudflare/circl < 1.3.3 - Predictable Shared Secret via Insufficient Randomness Check
CVSS 5.3
CVE-2023-29092 LOW
Samsung Exynos Modem 5123, 5300, 980, and 1080 - Improper Handling of Exceptional Conditions
CVSS 3.1
CVE-2023-23837 HIGH
No Exception Handling - Info Disclosure
CVSS 7.5
CVE-2023-0204 MEDIUM
NVIDIA ConnectX-5, ConnectX-6, and ConnectX6-DX < 35.1012 - Denial of Service via NIC Firmware Exception Handling
CVSS 6.5
CVE-2023-29520 MEDIUM
XWiki < 13.10.11 - Denial of Service via Corrupted Translation Document
CVSS 4.3
CVE-2023-28970 MEDIUM
Juniper Junos OS on JRR200 DoS via Network Packet Processing
CVSS 6.5
CVE-2023-28842 MEDIUM
Moby 1.12.0-20.10.24 - Unauthenticated Arbitrary Ethernet Frame Injection via VXLAN Datagrams
CVSS 6.8
CVE-2023-28841 MEDIUM
Moby 1.12.0-20.10.24 - Unencrypted Data Transmission in Overlay Network Driver
CVSS 6.8
CVE-2023-28840 HIGH
Moby 1.12.0-20.10.24 - Denial of Service via VXLAN Packet Injection
CVSS 7.5
CVE-2023-28631 MEDIUM
comrak < 0.17.0 - Denial of Service via Malformed AST Input
CVSS 5.3
CVE-2023-24308 HIGH
PDF-XChange Editor <9.3 - Memory Corruption
CVSS 7.8
CVE-2023-20993 HIGH
Android 11-13 - Local Privilege Escalation via Uncaught Exception in SnoozeHelper
CVSS 7.8
CVE-2023-28114 MEDIUM
cilium-cli < 0.13.2 - Permission Enforcement Removal via Incorrect Mount Point
CVSS 4.8
CVE-2023-27595 MEDIUM
Cilium 1.13.0 - Network Policy Bypass and Load Balancing Disruption during eBPF Program Attachment
CVSS 6.5
CVE-2023-26479 MEDIUM
XWiki Platform <6.0 - Info Disclosure
CVSS 6.5
CVE-2023-25561 MEDIUM
DataHub < 0.8.45 - Unauthenticated Authentication Bypass via JAAS Error Handling
CVSS 5.7
CVE-2023-22391 HIGH
Juniper Networks Junos OS ACX2K - DoS
CVSS 7.5
CVE-2022-48673 MEDIUM
Linux Kernel 4.11-5.19.8 - Use-After-Free in SMC Link Clear
CVSS 5.5
CVE-2022-48619 MEDIUM
Linux Kernel < 5.17.10 - Denial of Service via Input Event Code Bitmap Mishandling
CVSS 5.5
CVE-2022-27978 HIGH
Tooljet v1.6 - Arbitrary Password Reset via Missing Value Handling
CVSS 7.5
CVE-2022-23121 CRITICAL
netatalk < 3.1.13 - Unauthenticated Remote Code Execution via AppleDouble Entry Parsing
CVSS 9.8
CVE-2022-45155 MEDIUM
openSUSE Factory obs-service-go_modules < 0.6.1 - Arbitrary File and Directory Deletion
CVSS 5.5
CVE-2022-48329 CRITICAL
MISP < 2.4.166 - Improper Handling of Exceptional Conditions via Order Parameter
CVSS 9.8
CVE-2022-48328 CRITICAL
MISP < 2.4.167 - SQL Injection via IndexFilterComponent Parameter Handling
CVSS 9.8
CVE-2022-36287 MEDIUM
Intel Field Programmable Gate Array Crypto Service Server < 1.1.79.3 - Denial of Service via Uncaught Exception
CVSS 4.0
Details
Vulnerabilities 583
Exploit Likelihood Medium