Vulnerability index

Browse CVEs

771 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Reachable AssertionCWE-617 × clear
Gpac HIGH 7.5
CVE-2022-29339

In GPAC 2.1-DEV-rev87-g053aae8-master, function BS_ReadByte() in utils/bitstream.c has a failed assertion, which causes a Denial of Service. This vul…

Fix: 2022-04-12+
Fix from $1,950 2022-05-05
MongoDB MEDIUM 6.5
CVE-2022-24272

An authenticated user may trigger an invariant assertion during command dispatch due to incorrect validation on the $external database. This may resu…

Fix: after 5.0.6
Fix from $1,600 2022-04-21
Ios Xe MEDIUM 6.8
CVE-2022-20694

A vulnerability in the implementation of the Resource Public Key Infrastructure (RPKI) feature of Cisco IOS XE Software could allow an unauthenticate…

Mitigation only
Fix from $1,600 2022-04-15
MariaDB HIGH 7.5
CVE-2022-27448

There is an Assertion failure in MariaDB Server v10.9 and below via 'node->pcur->rel_pos == BTR_PCUR_ON' at /row/row0mysql.cc.

Fix: 10.3.35 / 10.4.25+
Fix from $1,950 2022-04-14
MariaDB HIGH 7.5
CVE-2022-27382

MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component Item_field::used_tables/update_depend_map_for_order.

Fix: 10.4.25 / 10.5.16+
Fix from $1,950 2022-04-12
Ar8035 Firmware HIGH 7.5
CVE-2021-30328

Possible assertion due to improper validation of invalid NR CSI-IM resource configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connecti…

No fix yet
Fix from $1,950 2022-04-01
Ar8035 Firmware HIGH 7.5
CVE-2021-30329

Possible assertion due to improper validation of TCI configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Indust…

Mitigation only
Fix from $1,950 2022-04-01
Ar8035 Firmware HIGH 7.5
CVE-2021-30332

Possible assertion due to improper validation of OTA configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Indust…

Mitigation only
Fix from $1,950 2022-04-01
Libsixel MEDIUM 5.5
CVE-2022-27938

stb_image.h (aka the stb image loader) 2.19, as used in libsixel and other products, has a reachable assertion in stbi__create_png_image_raw.

Fix: 1.8.7 / 1.10.4+
Fix from $1,600 2022-03-26
Fedora MEDIUM 5.5
CVE-2022-27939

tcprewrite in Tcpreplay 4.4.1 has a reachable assertion in get_layer4_v6 in common/get.c.

No fix yet
Fix from $1,600 2022-03-26
Grpc Swift HIGH 7.5
CVE-2022-24777

grpc-swift is the Swift language implementation of gRPC, a remote procedure call (RPC) framework. Prior to version 1.7.2, a grpc-swift server is vuln…

Fix: 1.7.2+
Fix from $1,950 2022-03-25
Bind HIGH 7.5
CVE-2022-0635

Versions affected: BIND 9.18.0 When a vulnerable version of named receives a series of specific queries, the named process will eventually terminate …

Mitigation only
Fix from $1,950 2022-03-23
Tcpreplay MEDIUM 5.5
CVE-2022-25484

tcpprep v4.4.1 has a reachable assertion (assert(l2len > 0)) in packet2tree() at tree.c in tcpprep v4.4.1.

No fix yet
Fix from $1,600 2022-03-22
Bind HIGH 7.5
CVE-2022-0667

When the vulnerability is triggered the BIND process will exit. BIND 9.18.0

No fix yet
Fix from $1,950 2022-03-22
Debian Linux MEDIUM 6.5
CVE-2022-0865

Reachable Assertion in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff …

Patch available
Fix from $1,600 2022-03-10
Tsmuxer MEDIUM 5.5
CVE-2021-45861

There is an Assertion `num <= INT_BIT' failed at BitStreamReader::skipBits in /bitStream.h:132 of tsMuxer git-c6a0277.

Fix: 2021-10-19+
Fix from $1,600 2022-03-02
Jerryscript MEDIUM 5.5
CVE-2022-22901

There is an Assertion in 'context_p->next_scanner_info_p->type == SCANNER_TYPE_FUNCTION' failed at parser_parse_function_arguments in /js/js-parser.c…

Patch available
Fix from $1,600 2022-02-17
Tcpreplay MEDIUM 5.5
CVE-2021-45386

tcpreplay 4.3.4 has a Reachable Assertion in add_tree_ipv6() at tree.c

No fix yet
Fix from $1,600 2022-02-11
Tcpreplay MEDIUM 5.5
CVE-2021-45387

tcpreplay 4.3.4 has a Reachable Assertion in add_tree_ipv4() at tree.c.

No fix yet
Fix from $1,600 2022-02-11
Ar8035 Firmware HIGH 7.5
CVE-2021-30326

Possible assertion due to improper size validation while processing the DownlinkPreemption IE in an RRC Reconfiguration/RRC Setup message in Snapdrag…

Mitigation only
Fix from $1,950 2022-02-11
Tensorflow MEDIUM 6.5
CVE-2022-23588

Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a denial of service by altering a `SavedModel` such that Grappler…

Fix: after 2.6.2
Fix from $1,600 2022-02-04
Tensorflow MEDIUM 6.5
CVE-2022-23565

Tensorflow is an Open Source Machine Learning Framework. An attacker can trigger denial of service via assertion failure by altering a `SavedModel` o…

Fix: after 2.6.2
Fix from $1,600 2022-02-04
Tensorflow MEDIUM 6.5
CVE-2022-23570

Tensorflow is an Open Source Machine Learning Framework. When decoding a tensor from protobuf, TensorFlow might do a null-dereference if attributes o…

Fix: after 2.6.2
Fix from $1,600 2022-02-04
Tensorflow MEDIUM 6.5
CVE-2022-23571

Tensorflow is an Open Source Machine Learning Framework. When decoding a tensor from protobuf, a TensorFlow process can encounter cases where a `CHEC…

Fix: after 2.6.2
Fix from $1,600 2022-02-04
Tensorflow MEDIUM 6.5
CVE-2022-23572

Tensorflow is an Open Source Machine Learning Framework. Under certain scenarios, TensorFlow can fail to specialize a type during shape inference. Th…

Fix: after 2.6.2
Fix from $1,600 2022-02-04
Tensorflow MEDIUM 6.5
CVE-2022-23579

Tensorflow is an Open Source Machine Learning Framework. The Grappler optimizer in TensorFlow can be used to cause a denial of service by altering a …

Fix: after 2.6.2
Fix from $1,600 2022-02-04
Tensorflow MEDIUM 6.5
CVE-2022-23581

Tensorflow is an Open Source Machine Learning Framework. The Grappler optimizer in TensorFlow can be used to cause a denial of service by altering a …

Fix: after 2.6.2
Fix from $1,600 2022-02-04
Tensorflow MEDIUM 6.5
CVE-2022-23582

Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a denial of service by altering a `SavedModel` such that `TensorB…

Fix: after 2.6.2
Fix from $1,600 2022-02-04
Tensorflow MEDIUM 6.5
CVE-2022-23583

Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a denial of service by altering a `SavedModel` such that any bina…

Fix: after 2.6.2
Fix from $1,600 2022-02-04
Tensorflow MEDIUM 6.5
CVE-2022-23586

Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a denial of service by altering a `SavedModel` such that assertio…

Fix: after 2.6.2
Fix from $1,600 2022-02-04