Vulnerability index

Browse CVEs

771 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Reachable AssertionCWE-617 × clear
Tensorflow HIGH 7.5
CVE-2022-35959

TensorFlow is an open source platform for machine learning. The implementation of `AvgPool3DGradOp` does not fully validate the input `orig_input_sha…

Fix: 2.7.2+
Fix from $1,950 2022-09-16
Tensorflow HIGH 7.5
CVE-2022-35960

TensorFlow is an open source platform for machine learning. In `core/kernels/list_kernels.cc's TensorListReserve`, `num_elements` is assumed to be a …

Fix: 2.7.2+
Fix from $1,950 2022-09-16
Tensorflow HIGH 7.5
CVE-2022-35963

TensorFlow is an open source platform for machine learning. The implementation of `FractionalAvgPoolGrad` does not fully validate the input `orig_inp…

Fix: 2.7.2+
Fix from $1,950 2022-09-16
Tensorflow HIGH 7.5
CVE-2022-35934

TensorFlow is an open source platform for machine learning. The implementation of tf.reshape op in TensorFlow is vulnerable to a denial of service vi…

Fix: 2.7.2 / 2.8.1+
Fix from $1,950 2022-09-16
Lief MEDIUM 5.5
CVE-2022-38496

LIEF commit 365a16a was discovered to contain a reachable assertion abort via the component BinaryStream.hpp.

Fix: after 0.12.1
Fix from $1,600 2022-09-13
Debian Linux MEDIUM 6.5
CVE-2022-2520

A flaw was found in libtiff 4.4.0rc1. There is a sysmalloc assertion fail in rotateImage() at tiffcrop.c:8621 that can cause program crash when readi…

Patch available
Fix from $1,600 2022-08-31
Routeros MEDIUM 6.5
CVE-2022-36522

Mikrotik RouterOs through stable v6.48.3 was discovered to contain an assertion failure in the component /advanced-tools/nova/bin/netwatch. This vuln…

Fix: after 6.48.3
Fix from $1,600 2022-08-26
Fedora MEDIUM 5.5
CVE-2022-2719

In ImageMagick, a crafted file could trigger an assertion failure when a call to WriteImages was made in MagickWand/operation.c, due to a NULL image …

Fix: 7.1.0-30+
Fix from $1,600 2022-08-10
Monetdb HIGH 7.5
CVE-2022-34967

The assertion `stmt->Dbc->FirstStmt' failed in MonetDB Database Server v11.43.13.

Patch available
Fix from $1,950 2022-08-03
Debian Linux MEDIUM 6.5
CVE-2021-46784

In Squid 3.x through 3.5.28, 4.x through 4.17, and 5.x before 5.6, due to improper buffer management, a Denial of Service can occur when processing l…

Fix: 5.6+
Fix from $1,600 2022-07-17
MariaDB HIGH 7.5
CVE-2022-32082

MariaDB v10.5 to v10.7 was discovered to contain an assertion failure at table->get_ref_count() == 0 in dict0dict.cc.

Fix: 10.5.17 / 10.6.9+
Fix from $1,950 2022-07-01
Zephyr HIGH 7.5
CVE-2021-3430

Assertion reachable with repeated LL_CONNECTION_PARAM_REQ. Zephyr versions >= v1.14 contain Reachable Assertion (CWE-617). For more information, see …

Fix: 2.6.0+
Fix from $1,950 2022-06-28
Zephyr HIGH 7.5
CVE-2021-3431

Assertion reachable with repeated LL_FEATURE_REQ. Zephyr versions >= v2.5.0 contain Reachable Assertion (CWE-617). For more information, see https://…

Fix: 2.6.0+
Fix from $1,950 2022-06-28
Pomsky MEDIUM 6.5
CVE-2022-31100

rulex is a new, portable, regular expression language. When parsing untrusted rulex expressions, rulex may crash, possibly enabling a Denial of Servi…

Fix: 0.4.3+
Fix from $1,600 2022-06-27
Solidity MEDIUM 5.5
CVE-2022-33069

Ethereum Solidity v0.8.14 contains an assertion failure via SMTEncoder::indexOrMemberAssignment() at SMTEncoder.cpp.

Patch available
Fix from $1,600 2022-06-23
Libredwg HIGH 7.5
CVE-2022-33024

There is an Assertion `int decode_preR13_entities(BITCODE_RL, BITCODE_RL, unsigned int, BITCODE_RL, BITCODE_RL, Bit_Chain *, Dwg_Data *' failed at dw…

No fix yet
Fix from $1,950 2022-06-23
Wire MEDIUM 6.5
CVE-2022-31009

wire-ios is an iOS client for the Wire secure messaging application. Invalid accent colors of Wire communication partners may render the iOS Wire Cli…

Fix: 3.100+
Fix from $1,600 2022-06-23
Libjxl MEDIUM 6.5
CVE-2022-34000

libjxl 0.6.1 has an assertion failure in LowMemoryRenderPipeline::Init() in render_pipeline/low_memory_render_pipeline.cc.

Patch available
Fix from $1,600 2022-06-19
Aqt1000 Firmware MEDIUM 6.5
CVE-2021-35101

Improper handling of writes to virtual GICR control can lead to assertion failure in the hypervisor in Snapdragon Auto, Snapdragon Compute, Snapdrago…

Mitigation only
Fix from $1,600 2022-06-14
Ar8035 Firmware HIGH 7.5
CVE-2021-35073

Possible assertion due to improper validation of rank restriction field in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon I…

Mitigation only
Fix from $1,950 2022-06-14
Ar8035 Firmware HIGH 7.5
CVE-2021-30340

Reachable assertion due to improper validation of coreset in PDCCH configuration in SA mode in Snapdragon Auto, Snapdragon Compute, Snapdragon Connec…

Mitigation only
Fix from $1,950 2022-06-14
Libjpeg MEDIUM 6.5
CVE-2022-32978

There is an assertion failure in SingleComponentLSScan::ParseMCU in singlecomponentlsscan.cpp in libjpeg before 1.64 via an empty JPEG-LS scan.

Fix: 1.64+
Fix from $1,600 2022-06-10
Envoy HIGH 7.5
CVE-2022-29228

Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter would try to invoke the remaining filters in the chain a…

Fix: 1.22.1+
Fix from $1,950 2022-06-09
Sound Exchange MEDIUM 5.5
CVE-2022-31651

In SoX 14.4.2, there is an assertion failure in rate_init in rate.c in libsox.a.

No fix yet
Fix from $1,600 2022-05-25
Libjpeg MEDIUM 6.5
CVE-2022-31620

In libjpeg before 1.64, BitStream<false>::Get in bitstream.hpp has an assertion failure that may cause denial of service. This is related to out-of-b…

Fix: 1.64+
Fix from $1,600 2022-05-25
Tensorflow MEDIUM 5.5
CVE-2022-29213

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the `tf.compat.v1.signal.rfft2d` and `t…

Fix: 2.6.4 / 2.7.2+
Fix from $1,600 2022-05-21
Bind HIGH 7.5
CVE-2022-1183EPSS 6%

On vulnerable configurations, the named daemon may, in some circumstances, terminate with an assertion failure. Vulnerable configurations are those t…

Fix: after 9.18.2
Fix from $1,950 2022-05-19
Opener HIGH 7.5
CVE-2021-27498

A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb 10, 2021 may result in a deni…

Fix: after 2.3
Fix from $1,950 2022-05-12
Opener HIGH 7.5
CVE-2021-27500

A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb 10, 2021 may result in a deni…

Fix: after 2.3
Fix from $1,950 2022-05-12
Libsixel MEDIUM 6.5
CVE-2022-29977

There is an assertion failure error in stbi__jpeg_huff_decode, stb_image.h:1894 in libsixel img2sixel 1.8.6. Remote attackers could leverage this vul…

No fix yet
Fix from $1,600 2022-05-11