Vulnerability index

Browse CVEs

771 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Reachable AssertionCWE-617 × clear
Routeros MEDIUM 6.5
CVE-2020-20262

Mikrotik RouterOs before 6.47 (stable tree) suffers from an assertion failure vulnerability in the /ram/pckg/security/nova/bin/ipsec process. An auth…

Fix: 6.47+
Fix from $1,600 2021-07-21
Secure Firewall Threat Defense HIGH 7.7
CVE-2021-1422

A vulnerability in the software cryptography module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Soft…

Mitigation only
Fix from $1,950 2021-07-16
Polipo HIGH 7.5
CVE-2020-36420

Polipo through 1.1.1, when NDEBUG is omitted, allows denial of service via a reachable assertion during parsing of a malformed Range header. NOTE: Th…

Fix: after 1.1.1
Fix from $1,950 2021-07-15
Aqt1000 Firmware HIGH 7.5
CVE-2021-1953

Improper handling of received malformed FTMR request frame can lead to reachable assertion while responding with FTM1 frame in Snapdragon Auto, Snapd…

Mitigation only
Fix from $1,950 2021-07-13
Apq8009 Firmware HIGH 7.5
CVE-2021-1955

Denial of service in SAP case due to improper handling of connections when association is rejected in Snapdragon Auto, Snapdragon Compute, Snapdragon…

Patch available
Fix from $1,950 2021-07-13
Aqt1000 Firmware HIGH 7.5
CVE-2021-1938

Possible assertion due to improper verification while creating and deleting the peer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity,…

Mitigation only
Fix from $1,950 2021-07-13
Ar7420 Firmware HIGH 7.5
CVE-2021-1887

An assertion can be reached in the WLAN subsystem while using the Wi-Fi Fine Timing Measurement protocol in Snapdragon Wired Infrastructure and Netwo…

Mitigation only
Fix from $1,950 2021-07-13
Routeros MEDIUM 6.5
CVE-2020-20211

Mikrotik RouterOs 6.44.5 (long-term tree) suffers from an assertion failure vulnerability in the /nova/bin/console process. An authenticated remote a…

No fix yet
Fix from $1,600 2021-07-07
Routeros MEDIUM 6.5
CVE-2020-20225

Mikrotik RouterOs before 6.47 (stable tree) suffers from an assertion failure vulnerability in the /nova/bin/user process. An authenticated remote at…

Fix: 6.47+
Fix from $1,600 2021-07-07
Jerryscript HIGH 7.5
CVE-2020-23313

There is an Assertion 'scope_stack_p > context_p->scope_stack_p' failed at js-scanner-util.c:2510 in scanner_literal_is_created in JerryScript 2.2.0

Patch available
Fix from $1,950 2021-06-10
Jerryscript HIGH 7.5
CVE-2020-23314

There is an Assertion 'block_found' failed at js-parser-statm.c:2003 parser_parse_try_statement_end in JerryScript 2.2.0.

Patch available
Fix from $1,950 2021-06-10
Jerryscript HIGH 7.5
CVE-2020-23319

There is an Assertion in '(flags >> CBC_STACK_ADJUST_SHIFT) >= CBC_STACK_ADJUST_BASE || (CBC_STACK_ADJUST_BASE - (flags >> CBC_STACK_ADJUST_SHIFT)) <…

Patch available
Fix from $1,950 2021-06-10
Jerryscript HIGH 7.5
CVE-2020-23320

There is an Assertion in 'context_p->next_scanner_info_p->type == SCANNER_TYPE_FUNCTION' in parser_parse_function_arguments in JerryScript 2.2.0.

Patch available
Fix from $1,950 2021-06-10
Jerryscript HIGH 7.5
CVE-2020-23322

There is an Assertion in 'context_p->token.type == LEXER_RIGHT_BRACE || context_p->token.type == LEXER_ASSIGN || context_p->token.type == LEXER_COMMA…

Patch available
Fix from $1,950 2021-06-10
Jerryscript HIGH 7.5
CVE-2020-23308

There is an Assertion 'context_p->stack_top_uint8 == LEXER_EXPRESSION_START' at js-parser-expr.c:3565 in parser_parse_expression in JerryScript 2.2.0.

Patch available
Fix from $1,950 2021-06-10
Jerryscript HIGH 7.5
CVE-2020-23309

There is an Assertion 'context_p->stack_depth == context_p->context_stack_depth' failed at js-parser-statm.c:2756 in parser_parse_statements in Jerry…

Patch available
Fix from $1,950 2021-06-10
Jerryscript HIGH 7.5
CVE-2020-23310

There is an Assertion 'context_p->next_scanner_info_p->type == SCANNER_TYPE_FUNCTION' failed at js-parser-statm.c:733 in parser_parse_function_statem…

Patch available
Fix from $1,950 2021-06-10
Jerryscript HIGH 7.5
CVE-2020-23311

There is an Assertion 'context_p->token.type == LEXER_RIGHT_BRACE || context_p->token.type == LEXER_ASSIGN || context_p->token.type == LEXER_COMMA' f…

Patch available
Fix from $1,950 2021-06-10
Jerryscript HIGH 7.5
CVE-2020-23312

There is an Assertion 'context.status_flags & PARSER_SCANNING_SUCCESSFUL' failed at js-parser.c:2185 in parser_parse_source in JerryScript 2.2.0.

Patch available
Fix from $1,950 2021-06-10
Aqt1000 Firmware HIGH 7.5
CVE-2021-1937

Reachable assertion is possible while processing peer association WLAN message from host and nonstandard incoming packet in Snapdragon Auto, Snapdrag…

Mitigation only
Fix from $1,950 2021-06-09
Openvpn Access Server HIGH 7.5
CVE-2020-36382

OpenVPN Access Server 2.7.3 to 2.8.7 allows remote attackers to trigger an assert during the user authentication phase via incorrect authentication t…

Fix: after 2.8.7
Fix from $1,950 2021-06-04
Jboss Core Services HIGH 7.5
CVE-2020-25710

A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an attacker who sends a malicious packet processed by OpenLDAP to force a fa…

Fix: 2.4.56+
Fix from $1,950 2021-05-28
Enterprise Linux MEDIUM 5.5
CVE-2021-30501

An assertion abort was found in upx MemBuffer::alloc() in mem.cpp, in version UPX 4.0.0. The flow allows attackers to cause a denial of service (abor…

Patch available
Fix from $1,600 2021-05-27
Libyang HIGH 7.5
CVE-2021-28905

In function lys_node_free() in libyang <= v1.0.225, it asserts that the value of node->module can't be NULL. But in some cases, node->module can be n…

Fix: after 1.0.225
Fix from $1,950 2021-05-20
Envoy HIGH 7.5
CVE-2021-29258

An issue was discovered in Envoy 1.14.0. There is a remotely exploitable crash for HTTP2 Metadata, because an empty METADATA map triggers a Reachable…

Patch available
Fix from $1,950 2021-05-20
Routeros MEDIUM 6.5
CVE-2020-20214

Mikrotik RouterOs 6.44.6 (long-term tree) suffers from an assertion failure vulnerability in the btest process. An authenticated remote attacker can …

No fix yet
Fix from $1,600 2021-05-18
Ceph MEDIUM 5.3
CVE-2021-3531

A flaw was found in the Red Hat Ceph Storage RGW in versions before 14.2.21. When processing a GET Request for a swift URL that ends with two slashes…

Fix: 14.2.21+
Fix from $1,600 2021-05-18
Debian Linux HIGH 7.5
CVE-2020-25709

A flaw was found in OpenLDAP. This flaw allows an attacker who can send a malicious packet to be processed by OpenLDAP’s slapd server, to trigger an …

Fix: 2.4.56 / 10.14.6+
Fix from $1,950 2021-05-18
Tensorflow MEDIUM 5.5
CVE-2021-29552

TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service by controlling the values of `num_se…

Fix: 2.1.4 / 2.2.3+
Fix from $1,600 2021-05-14
Tensorflow MEDIUM 5.5
CVE-2021-29561

TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service by exploiting a `CHECK`-failure comi…

Fix: 2.1.4 / 2.2.3+
Fix from $1,600 2021-05-14