Skip to main content

CWE archive

CWE-617 CVEs

Programmatic archive

789 CVEs tagged with CWE-6174 Critical, 327 High, 428 Medium, 30 Low, 0 Unrated.

CVE-2024-57806

Published Jan 11, 2025

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix transaction atomicity bug when enabling simple quotas Set squota incompat bit before committing th…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-56783

Published Jan 8, 2025

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_socket: remove WARN_ON_ONCE on maximum cgroup level cgroup maximum depth is INT_MAX by default…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8361

Published Jan 7, 2025

In SiWx91x devices, the SHA2/224 algorithm returns a hash of 256 bits instead of 224 bits. This incorrect hash length triggers a software assertion, which subsequently causes a De…

CVSS 7.5 · High

CVE-2024-56705

Published Dec 28, 2024

In the Linux kernel, the following vulnerability has been resolved: media: atomisp: Add check for rgby_data memory allocation failure In ia_css_3a_statistics_allocate(), there i…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7139

Published Dec 19, 2024

Due to an unchecked buffer length, a specially crafted L2CAP packet can cause a buffer overflow. This buffer overflow triggers an assert, which results in a temporary denial of se…

CVSS 6.5 · Medium

CVE-2024-7138

Published Dec 19, 2024

An assert may be triggered, causing a temporary denial of service when a peer device sends a specially crafted malformed L2CAP packet. If a watchdog timer is not enabled, a hard r…

CVSS 6.5 · Medium

CVE-2024-53856

Published Dec 5, 2024

rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows an attacker to trigger rpgp crashes by providing crafted data. This vulnerability is fixed in 0.14.1.

CVSS 7.5 · High

CVE-2024-20139

Published Dec 2, 2024

In Bluetooth firmware, there is a possible firmware asssert due to improper handling of exceptional conditions. This could lead to local denial of service with no additional execu…

CVSS 6.5 · Medium

CVE-2024-53429

Published Nov 21, 2024

Open62541 v1.4.6 is has an assertion failure in fuzz_binary_decode, which leads to a crash.

CVSS 7.5 · High

CVE-2021-1440

Published Nov 18, 2024

A vulnerability in the implementation of the Resource Public Key Infrastructure (RPKI) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cau…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10455

Published Oct 28, 2024

Reachable Assertion in BPv7 parser in µD3TN v0.14.0 allows attacker to disrupt service via malformed Extension Block

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-50615

Published Oct 27, 2024

TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/digit, that may lead to application exit, in tinyxml2.cpp XMLUtil::GetCharacterRef.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-50614

Published Oct 27, 2024

TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/16, that may lead to application exit, in tinyxml2.cpp XMLUtil::GetCharacterRef.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-49932

Published Oct 21, 2024

In the Linux kernel, the following vulnerability has been resolved: btrfs: don't readahead the relocation inode on RST On relocation we're doing readahead on the relocation inod…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-47522

Published Oct 16, 2024

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.7, invalid ALPN in TLS/QUIC traffic when…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-45795

Published Oct 16, 2024

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.7, rules using datasets with the non-fun…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-45403

Published Oct 11, 2024

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. When h2o is configured as a reverse proxy and HTTP/3 requests are cancelled by the client, h2o might crash due…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-45396

Published Oct 11, 2024

Quicly is an IETF QUIC protocol implementation. Quicly up to commtit d720707 is susceptible to a denial-of-service attack. A remote attacker can exploit these bugs to trigger an a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-20094

Published Oct 7, 2024

In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interact…

CVSS 7.5 · High

CVE-2024-8354

Published Sep 19, 2024

A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from a USB device. This flaw may allow…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-46753

Published Sep 18, 2024

In the Linux kernel, the following vulnerability has been resolved: btrfs: handle errors from btrfs_dec_ref() properly In walk_up_proc() we BUG_ON(ret) from btrfs_dec_ref(). Th…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8768

Published Sep 17, 2024

A flaw was found in the vLLM library. A completions API request with an empty prompt will crash the vLLM API server, resulting in a denial of service.

CVSS 7.5 · High
Showing 276-300 of 789 CVEsPage 12 of 32