CWE-617
781 CVEs • Abstraction: Base
Reachable Assertion
The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.
CVEs (781)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Libsixel Project Saitoha2Libsixel LibsixelJun 17, 2026 May 11, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 There is an assertion failure error in stbi__jpeg_huff_decode, stb_image.h:1894 in libsixel img2sixel 1.8.6. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted JPEG file. |
In GPAC 2.1-DEV-rev87-g053aae8-master, function BS_ReadByte() in utils/bitstream.c has a failed assertion, which causes a Denial of Service. This vulnerability was fixed in commit 9ea93a2. |
An authenticated user may trigger an invariant assertion during command dispatch due to incorrect validation on the $external database. This may result in mongod denial of service or server crash. This issue affects: Mon...Show more |
A vulnerability in the implementation of the Resource Public Key Infrastructure (RPKI) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the Border Gateway Protocol (BGP) process t...Show more |
2Debian Mariadb2Debian Linux MariadbJun 17, 2026 Apr 14, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 There is an Assertion failure in MariaDB Server v10.9 and below via 'node->pcur->rel_pos == BTR_PCUR_ON' at /row/row0mysql.cc. |
MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component Item_field::used_tables/update_depend_map_for_order. |
1Qualcomm 55Ar8035 Firmware Qca6390 FirmwareQca6391 Firmware+52 moreJun 17, 2026 Apr 1, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Possible assertion due to improper validation of OTA configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile |
1Qualcomm 53Ar8035 Firmware Qca6390 FirmwareQca6391 Firmware+50 moreJun 17, 2026 Apr 1, 2022 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Possible assertion due to improper validation of TCI configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile |
1Qualcomm 48Ar8035 Firmware Qca6390 FirmwareQca6391 Firmware+45 moreJun 17, 2026 Apr 1, 2022 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Possible assertion due to improper validation of invalid NR CSI-IM resource configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile |
2Broadcom Fedoraproject2Fedora TcpreplayJun 17, 2026 Mar 26, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 tcprewrite in Tcpreplay 4.4.1 has a reachable assertion in get_layer4_v6 in common/get.c. |
3Libsixel Libsixel ProjectSaitoha3Libsixel LibsixelLibsixelJun 17, 2026 Mar 26, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 stb_image.h (aka the stb image loader) 2.19, as used in libsixel and other products, has a reachable assertion in stbi__create_png_image_raw. |
grpc-swift is the Swift language implementation of gRPC, a remote procedure call (RPC) framework. Prior to version 1.7.2, a grpc-swift server is vulnerable to a denial of service attack via a reachable assertion. This is...Show more |
2Isc Netapp9Bind H300e FirmwareH300s Firmware+6 moreJun 17, 2026 Mar 23, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Versions affected: BIND 9.18.0 When a vulnerable version of named receives a series of specific queries, the named process will eventually terminate due to a failed assertion check. |
tcpprep v4.4.1 has a reachable assertion (assert(l2len > 0)) in packet2tree() at tree.c in tcpprep v4.4.1. |
2Isc Netapp9Bind H300e FirmwareH300s Firmware+6 moreJun 17, 2026 Mar 22, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 When the vulnerability is triggered the BIND process will exit. BIND 9.18.0 |
4Debian FedoraprojectLibtiff+1 more4Active Iq Unified Manager Debian LinuxFedora+1 moreJun 17, 2026 Mar 10, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Reachable Assertion in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 5e180045. |
There is an Assertion `num <= INT_BIT' failed at BitStreamReader::skipBits in /bitStream.h:132 of tsMuxer git-c6a0277. |
There is an Assertion in 'context_p->next_scanner_info_p->type == SCANNER_TYPE_FUNCTION' failed at parser_parse_function_arguments in /js/js-parser.c of JerryScript commit a6ab5e9. |
tcpreplay 4.3.4 has a Reachable Assertion in add_tree_ipv4() at tree.c. |
tcpreplay 4.3.4 has a Reachable Assertion in add_tree_ipv6() at tree.c |