CWE-617
781 CVEs • Abstraction: Base
Reachable Assertion
The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.
CVEs (781)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in Poppler 22.08.0. There is a reachable assertion in Object.h, will lead to denial of service because PDFDoc::replacePageDict in PDFDoc.cc lacks a stream check before saving an embedded file. |
A reachable Object::getString assertion in Poppler 22.07.0 allows attackers to cause a denial of service due to a failure in markObject. |
2Debian Freedesktop2Debian Linux PopplerJun 17, 2026 Aug 22, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An issue was discovered in Poppler 22.07.0. There is a reachable abort which leads to denial of service because the main function in pdfunite.cc lacks a stream check before saving an embedded file. |
An issue was discovered in Binutils readelf 2.38.50, reachable assertion failure in function display_debug_names allows attackers to cause a denial of service. |
Reachable Assertion vulnerability in upx before 4.0.0 allows attackers to cause a denial of service via crafted file passed to the the readx function. |
An issue in weaviate v.1.20.0 allows a remote attacker to cause a denial of service via the handleUnbatchedGraphQLRequest function. |
2Debian Eprosima2Debian Linux Fast DdsJun 17, 2026 Aug 11, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.9.1 and 2.6.5, improper validation of sequence numbers may lead to remotely reachabl...Show more |
2Debian Eprosima2Debian Linux Fast DdsJun 17, 2026 Aug 11, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.10.0, 2.9.2, and 2.6.5, a malformed GAP submessage can trigger assertion failure, cr...Show more |
Redis before 6cbea7d allows a replica to cause an assertion failure in a primary server by sending a non-administrative command (specifically, a SET command). NOTE: this was fixed for Redis 6.2.x and 7.x in 2021. Version...Show more |
A Reachable Assertion vulnerability in Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows a locally-based, low-privileged attacker to cause a Denial of Service (DoS). On all Junos OS...Show more |
libjpeg commit db33a6e was discovered to contain a reachable assertion via BitMapHook::BitMapHook at bitmaphook.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file. |
Jerryscript 3.0 (commit 05dbbd1) was discovered to contain an Assertion Failure via the parser_parse_for_statement_start at jerry-core/parser/js/js-parser-statm.c. |
Jerryscript 3.0 (commit 05dbbd1) was discovered to contain an Assertion Failure via the ecma_property_hashmap_create at jerry-core/ecma/base/ecma-property-hashmap.c. |
There exists an vulnerability causing an abort() to be called in gRPC. The following headers cause gRPC's C++ implementation to abort() when called via http2: te: x (x != trailers) :scheme: x (x != http, https) grpcl...Show more |
1Qualcomm 13Ar8035 Firmware Qca8081 FirmwareQca8337 Firmware+10 moreJun 17, 2026 Jun 6, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS due to reachable assertion in modem while processing sib with incorrect values from network. |
1Qualcomm 74315 5g Iot Modem Firmware Ar8035 FirmwareQca6390 Firmware+71 moreJun 17, 2026 Jun 6, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS due to reachable assertion in Modem because of invalid network configuration. |
1Qualcomm 74315 5g Iot Modem Firmware Ar8035 FirmwareQca6390 Firmware+71 moreJun 17, 2026 Jun 6, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Assertion occurs while processing Reconfiguration message due to improper validation |
Rekor's goals are to provide an immutable tamper resistant ledger of metadata generated within a software projects supply chain. A malformed proposed entry of the `intoto/v0.0.2` type can cause a panic on a thread within...Show more |
There is a vulnerability in the fizz library prior to v2023.01.30.00 where a CHECK failure can be triggered remotely. This behavior requires the client supported cipher advertisement changing between the original ClientH...Show more |
Jerryscript 3.0 (commit 05dbbd1) was discovered to contain an Assertion Failure via the ecma_big_uint_div_mod at jerry-core/ecma/operations/ecma-big-uint.c. |