CWE-248
239 CVEs • Abstraction: Base
Uncaught Exception
An exception is thrown from a function, but it is not caught.
CVEs (239)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Google LinuxfoundationOpenwrt+1 more4Android OpenwrtRdk B+1 moreJun 17, 2026 Apr 1, 2024 N/A· v4 4.4 MEDIUM· v3 N/A· v2 In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation...Show more |
In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation...Show more |
An uncaught exception in Elasticsearch >= 8.4.0 and < 8.11.1 occurs when an encrypted PDF is passed to an attachment processor through the REST API. The Elasticsearch ingest node that attempts to parse the PDF file will...Show more |
A vulnerability in Cisco IOS Software for Cisco Catalyst 6000 Series Switches could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly. This vulnerability is due to improper...Show more |
A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .pem bundle using the "certtool --verify-chain" command. |
1Intel 4Ethernet Adapter Complete Driver Ethernet Controller I225 It FirmwareEthernet Controller I225 Lm Firmware+1 moreJun 17, 2026 Feb 23, 2024 N/A· v4 7.2 HIGH· v3 N/A· v2 Uncaught exception in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable escalation of privilege via local access. |
2Fedoraproject Openvswitch2Fedora OpenvswitchJun 17, 2026 Feb 22, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in Open vSwitch where multiple versions are vulnerable to crafted Geneve packets, which may result in a denial of service and invalid memory accesses. Triggering this issue requires that hardware offload...Show more |
Malformed S2 Nonce Get Command Class packets can be sent to crash PC Controller v5.54.0 and earlier. |
Malformed Device Reset Locally Command Class packets can be sent to the controller, causing the controller to assume the end device has left the network. After this, frames sent by the end device will not be acknowledged...Show more |
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8 are susceptible to a Denial of Service (DoS) vulnerability. Successful exploit by an authenticated attacker could lead to an out of memory condition o...Show more |
Uncaught exception for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access. |
Envoy is a high-performance edge/middle/service proxy. Envoy crashes in Proxy protocol when using an address type that isn’t supported by the OS. Envoy is susceptible to crashing on a host with IPv6 disabled and a listen...Show more |
StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.13 are susceptible to a Denial of Service (DoS) vulnerability. A successful exploit could lead to a crash of the Local Distribution Router (LD...Show more |
Some WASM source files could have caused a crash when loaded in devtools. This vulnerability affects Firefox < 122. |
1Silabs 1Z Wave Software Development Kit Jun 17, 2026 Dec 15, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A denial of service vulnerability exists in all Silicon Labs Z-Wave controller and endpoint devices running Z-Wave SDK v7.20.3 (Gecko SDK v4.3.3) and earlier. This attack can be carried out only by devices on the network...Show more |
Uncaught exception for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via local access. |
Uncaught exception for some Intel Unison software may allow an authenticated user to potentially enable denial of service via network access. |
1Cisco 2Adaptive Security Appliance Software Firepower Threat DefenseJun 17, 2026 Nov 1, 2023 N/A· v4 8.6 HIGH· v3 N/A· v2 A vulnerability in ICMPv6 processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS...Show more |
quic-go is an implementation of the QUIC protocol in Go. Starting in version 0.37.0 and prior to version 0.37.3, by serializing an ACK frame after the CRYTPO that allows a node to complete the handshake, a remote node co...Show more |
rs-stellar-strkey is a Rust lib for encode/decode of Stellar Strkeys. A panic vulnerability occurs when a specially crafted payload is used.`inner_payload_len` should not above 64. This vulnerability has been patched in...Show more |