← Back
CWE-617

781 CVEs • Abstraction: Base

Reachable Assertion

The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

JSON object

Loading...

CVEs (781)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Libsixel Project
Saitoha
2Libsixel
Libsixel
Jun 17, 2026
May 11, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
There is an assertion failure error in stbi__jpeg_huff_decode, stb_image.h:1894 in libsixel img2sixel 1.8.6. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted JPEG file.
1Gpac
1Gpac
Jun 17, 2026
May 5, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In GPAC 2.1-DEV-rev87-g053aae8-master, function BS_ReadByte() in utils/bitstream.c has a failed assertion, which causes a Denial of Service. This vulnerability was fixed in commit 9ea93a2.
1Mongodb
1Mongodb
Jun 17, 2026
Apr 21, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An authenticated user may trigger an invariant assertion during command dispatch due to incorrect validation on the $external database. This may result in mongod denial of service or server crash. This issue affects: Mon...Show more
An authenticated user may trigger an invariant assertion during command dispatch due to incorrect validation on the $external database. This may result in mongod denial of service or server crash. This issue affects: MongoDB Inc. MongoDB Server v5.0 versions, prior to and including v5.0.6.Show less
1Cisco
1Ios Xe
Jun 17, 2026
Apr 15, 2022
N/A· v4
6.8 MEDIUM· v3
7.1 HIGH· v2
A vulnerability in the implementation of the Resource Public Key Infrastructure (RPKI) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the Border Gateway Protocol (BGP) process t...Show more
A vulnerability in the implementation of the Resource Public Key Infrastructure (RPKI) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the Border Gateway Protocol (BGP) process to crash, resulting in a denial of service (DoS) condition. This vulnerability is due to the incorrect handling of a specific RPKI to Router (RTR) Protocol packet header. An attacker could exploit this vulnerability by compromising the RPKI validator server and sending a specifically crafted RTR packet to an affected device. Alternatively, the attacker could use man-in-the-middle techniques to impersonate the RPKI validator server and send a crafted RTR response packet over the established RTR TCP connection to the affected device. A successful exploit could allow the attacker to cause a DoS condition because the BGP process could constantly restart and BGP routing could become unstable.Show less
2Debian
Mariadb
2Debian Linux
Mariadb
Jun 17, 2026
Apr 14, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
There is an Assertion failure in MariaDB Server v10.9 and below via 'node->pcur->rel_pos == BTR_PCUR_ON' at /row/row0mysql.cc.
1Mariadb
1Mariadb
Jun 17, 2026
Apr 12, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component Item_field::used_tables/update_depend_map_for_order.
1Qualcomm
55Ar8035 Firmware
Qca6390 FirmwareQca6391 Firmware+52 more
Jun 17, 2026
Apr 1, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Possible assertion due to improper validation of OTA configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
1Qualcomm
53Ar8035 Firmware
Qca6390 FirmwareQca6391 Firmware+50 more
Jun 17, 2026
Apr 1, 2022
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Possible assertion due to improper validation of TCI configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
1Qualcomm
48Ar8035 Firmware
Qca6390 FirmwareQca6391 Firmware+45 more
Jun 17, 2026
Apr 1, 2022
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Possible assertion due to improper validation of invalid NR CSI-IM resource configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
2Broadcom
Fedoraproject
2Fedora
Tcpreplay
Jun 17, 2026
Mar 26, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
tcprewrite in Tcpreplay 4.4.1 has a reachable assertion in get_layer4_v6 in common/get.c.
3Libsixel
Libsixel ProjectSaitoha
3Libsixel
LibsixelLibsixel
Jun 17, 2026
Mar 26, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
stb_image.h (aka the stb image loader) 2.19, as used in libsixel and other products, has a reachable assertion in stbi__create_png_image_raw.
1Linuxfoundation
1Grpc Swift
Jun 17, 2026
Mar 25, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
grpc-swift is the Swift language implementation of gRPC, a remote procedure call (RPC) framework. Prior to version 1.7.2, a grpc-swift server is vulnerable to a denial of service attack via a reachable assertion. This is...Show more
grpc-swift is the Swift language implementation of gRPC, a remote procedure call (RPC) framework. Prior to version 1.7.2, a grpc-swift server is vulnerable to a denial of service attack via a reachable assertion. This is due to incorrect logic when handling GOAWAY frames. The attack is low-effort: it takes very little resources to construct and send the required sequence of frames. The impact on availability is high as the server will crash, dropping all in flight connections and requests. This issue is fixed in version 1.7.2. There are currently no known workarounds.Show less
2Isc
Netapp
9Bind
H300e FirmwareH300s Firmware+6 more
Jun 17, 2026
Mar 23, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Versions affected: BIND 9.18.0 When a vulnerable version of named receives a series of specific queries, the named process will eventually terminate due to a failed assertion check.
1Broadcom
1Tcpreplay
Jun 17, 2026
Mar 22, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
tcpprep v4.4.1 has a reachable assertion (assert(l2len > 0)) in packet2tree() at tree.c in tcpprep v4.4.1.
2Isc
Netapp
9Bind
H300e FirmwareH300s Firmware+6 more
Jun 17, 2026
Mar 22, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
When the vulnerability is triggered the BIND process will exit. BIND 9.18.0
4Debian
FedoraprojectLibtiff+1 more
4Active Iq Unified Manager
Debian LinuxFedora+1 more
Jun 17, 2026
Mar 10, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Reachable Assertion in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 5e180045.
1Tsmuxer Project
1Tsmuxer
Jun 17, 2026
Mar 2, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
There is an Assertion `num <= INT_BIT' failed at BitStreamReader::skipBits in /bitStream.h:132 of tsMuxer git-c6a0277.
1Jerryscript
1Jerryscript
Jul 9, 2026
Feb 17, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
There is an Assertion in 'context_p->next_scanner_info_p->type == SCANNER_TYPE_FUNCTION' failed at parser_parse_function_arguments in /js/js-parser.c of JerryScript commit a6ab5e9.
1Broadcom
1Tcpreplay
Jun 17, 2026
Feb 11, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
tcpreplay 4.3.4 has a Reachable Assertion in add_tree_ipv4() at tree.c.
1Broadcom
1Tcpreplay
Jun 17, 2026
Feb 11, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
tcpreplay 4.3.4 has a Reachable Assertion in add_tree_ipv6() at tree.c