Vulnerability index

Browse CVEs

771 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Reachable AssertionCWE-617 × clear
Debian Linux MEDIUM 6.5
CVE-2022-37051

An issue was discovered in Poppler 22.07.0. There is a reachable abort which leads to denial of service because the main function in pdfunite.cc lack…

Patch available
Fix from $1,600 2023-08-22
Poppler MEDIUM 6.5
CVE-2022-37052

A reachable Object::getString assertion in Poppler 22.07.0 allows attackers to cause a denial of service due to a failure in markObject.

Patch available
Fix from $1,600 2023-08-22
Poppler MEDIUM 6.5
CVE-2022-38349

An issue was discovered in Poppler 22.08.0. There is a reachable assertion in Object.h, will lead to denial of service because PDFDoc::replacePageDic…

Patch available
Fix from $1,600 2023-08-22
Upx MEDIUM 6.5
CVE-2021-46179

Reachable Assertion vulnerability in upx before 4.0.0 allows attackers to cause a denial of service via crafted file passed to the the readx function.

Fix: 4.0.0+
Fix from $1,600 2023-08-22
Weaviate HIGH 7.5
CVE-2023-38976

An issue in weaviate v.1.20.0 allows a remote attacker to cause a denial of service via the handleUnbatchedGraphQLRequest function.

No fix yet
Fix from $1,950 2023-08-21
Debian Linux HIGH 7.5
CVE-2023-39534

eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.10.0, 2.9.2, …

Fix: 2.6.5 / 2.9.2+
Fix from $1,950 2023-08-11
Debian Linux HIGH 7.5
CVE-2023-39949

eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.9.1 and 2.6.5…

Fix: 2.6.5+
Fix from $1,950 2023-08-11
Redis MEDIUM 5.9
CVE-2021-31294

Redis before 6cbea7d allows a replica to cause an assertion failure in a primary server by sending a non-administrative command (specifically, a SET …

Fix: 6.2.0+
Fix from $1,600 2023-07-15
Junos MEDIUM 5.5
CVE-2023-36840

A Reachable Assertion vulnerability in Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows a locally-based, low-pr…

Fix: 19.3 / 20.4+
Fix from $1,600 2023-07-14
Libjpeg MEDIUM 6.5
CVE-2023-37836

libjpeg commit db33a6e was discovered to contain a reachable assertion via BitMapHook::BitMapHook at bitmaphook.cpp. This vulnerability allows attack…

Fix: 1.66+
Fix from $1,600 2023-07-13
Jerryscript HIGH 7.5
CVE-2023-34867

Jerryscript 3.0 (commit 05dbbd1) was discovered to contain an Assertion Failure via the ecma_property_hashmap_create at jerry-core/ecma/base/ecma-pro…

No fix yet
Fix from $1,950 2023-06-14
Jerryscript HIGH 7.5
CVE-2023-34868

Jerryscript 3.0 (commit 05dbbd1) was discovered to contain an Assertion Failure via the parser_parse_for_statement_start at jerry-core/parser/js/js-p…

No fix yet
Fix from $1,950 2023-06-14
Grpc HIGH 7.5
CVE-2023-1428

There exists an vulnerability causing an abort() to be called in gRPC.  The following headers cause gRPC's C++ implementation to abort() when called …

Fix: 1.53.0+
Fix from $1,950 2023-06-09
Ar8035 Firmware HIGH 7.5
CVE-2022-40538

Transient DOS due to reachable assertion in modem while processing sib with incorrect values from network.

Mitigation only
Fix from $1,950 2023-06-06
315 5g Iot Modem Firmware HIGH 7.5
CVE-2022-33251

Transient DOS due to reachable assertion in Modem because of invalid network configuration.

No fix yet
Fix from $1,950 2023-06-06
315 5g Iot Modem Firmware HIGH 7.5
CVE-2022-22060

Assertion occurs while processing Reconfiguration message due to improper validation

No fix yet
Fix from $1,950 2023-06-06
Rekor MEDIUM 5.3
CVE-2023-33199

Rekor's goals are to provide an immutable tamper resistant ledger of metadata generated within a software projects supply chain. A malformed proposed…

Fix: 1.2.0+
Fix from $1,600 2023-05-26
Fizz HIGH 7.5
CVE-2023-23759

There is a vulnerability in the fizz library prior to v2023.01.30.00 where a CHECK failure can be triggered remotely. This behavior requires the clie…

Fix: 2023.01.30.00+
Fix from $1,950 2023-05-18
Jerryscript MEDIUM 5.5
CVE-2023-31921

Jerryscript 3.0 (commit 05dbbd1) was discovered to contain an Assertion Failure via the ecma_big_uint_div_mod at jerry-core/ecma/operations/ecma-big-…

Patch available
Fix from $1,600 2023-05-12
Jerryscript MEDIUM 5.5
CVE-2023-31913

Jerryscript 3.0 *commit 1a2c047) was discovered to contain an Assertion Failure via the component parser_parse_class at jerry-core/parser/js/js-parse…

No fix yet
Fix from $1,600 2023-05-12
Jerryscript MEDIUM 5.5
CVE-2023-31916

Jerryscript 3.0 (commit 1a2c047) was discovered to contain an Assertion Failure via the jmem_heap_finalize at jerry-core/jmem/jmem-heap.c.

No fix yet
Fix from $1,600 2023-05-12
Jerryscript MEDIUM 5.5
CVE-2023-31918

Jerryscript 3.0 (commit 1a2c047) was discovered to contain an Assertion Failure via the parser_parse_function_arguments at jerry-core/parser/js/js-pa…

No fix yet
Fix from $1,600 2023-05-12
Jerryscript MEDIUM 5.5
CVE-2023-31919

Jerryscript 3.0 (commit 05dbbd1) was discovered to contain an Assertion Failure via the jcontext_raise_exception at jerry-core/jcontext/jcontext.c.

No fix yet
Fix from $1,600 2023-05-12
Jerryscript MEDIUM 5.5
CVE-2023-31920

Jerryscript 3.0 (commit 05dbbd1) was discovered to contain an Assertion Failure via the vm_loop at jerry-core/vm/vm.c.

Patch available
Fix from $1,600 2023-05-12
Linux Kernel HIGH 7.5
CVE-2023-2156EPSS 6%

A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL protocol. This issue results from the lack of proper …

Fix: 5.10.184 / 5.15.117+
Fix from $1,950 2023-05-09
Llvm MEDIUM 5.5
CVE-2023-29935

llvm-project commit a0138390 was discovered to contain an assertion failure at !replacements.count(op) && "operation was already replaced.

Patch available
Fix from $1,600 2023-05-05
315 5g Iot Modem Firmware HIGH 7.5
CVE-2022-40504

Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network.

Mitigation only
Fix from $1,950 2023-05-02
315 5g Iot Modem Firmware HIGH 7.5
CVE-2022-34144

Transient DOS due to reachable assertion in Modem during OSI decode scheduling.

No fix yet
Fix from $1,950 2023-05-02
315 5g Iot Modem Firmware HIGH 7.5
CVE-2022-40508

Transient DOS due to reachable assertion in Modem while processing config related to cross carrier scheduling, which is not supported.

Mitigation only
Fix from $1,950 2023-05-02
Redis MEDIUM 6.5
CVE-2023-28856

Redis is an open source, in-memory database that persists on disk. Authenticated users can use the `HINCRBYFLOAT` command to create an invalid hash f…

Fix: 6.0.19 / 6.2.12+
Fix from $1,600 2023-04-18