CWE-617
781 CVEs • Abstraction: Base
Reachable Assertion
The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.
CVEs (781)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service by exploiting a `CHECK`-failure coming from the implementation of `tf.raw_ops.RFFT`. Eigen code operating o...Show more |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service by exploiting a `CHECK`-failure coming from the implementation of `tf.raw_ops.IRFFT`. The fix will be inclu...Show more |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service by exploiting a `CHECK`-failure coming from `tf.raw_ops.LoadAndRemapMatrix`. This is because the implementa...Show more |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service by controlling the values of `num_segments` tensor argument for `UnsortedSegmentJoin`. This is because the...Show more |
TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a denial of service via a `CHECK`-fail in `tf.raw_ops.CTCGreedyDecoder`. This is because the implementation(https://github.co...Show more |
A flaw was found in avahi 0.8-5. A reachable assertion is present in avahi_s_host_name_resolver_start function allowing a local attacker to crash the avahi service by requesting hostname resolutions through the avahi soc...Show more |
1Qualcomm 407Aqt1000 Firmware Ar8031 FirmwareAr8035 Firmware+404 moreJun 17, 2026 May 7, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Possible denial of service scenario due to improper handling of group management action frame in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Cons...Show more |
1Qualcomm 246Aqt1000 Firmware Csrb31024 FirmwareFsm10055 Firmware+243 moreJun 17, 2026 May 7, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Denial of service in MODEM due to assert to the invalid configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile |
6Debian FedoraprojectIsc+3 more16500f Firmware A250 FirmwareActive Iq Unified Manager+13 moreJun 17, 2026 Apr 29, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In BIND 9.0.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 developm...Show more |
5Debian FedoraprojectIsc+2 more15Active Iq Unified Manager Aff 500f FirmwareAff A250 Firmware+12 moreJun 17, 2026 Apr 29, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In BIND 9.8.5 -> 9.8.8, 9.9.3 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND 9 Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the...Show more |
2Debian Nlnetlabs2Debian Linux UnboundJun 17, 2026 Apr 27, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Unbound before 1.9.5 allows an assertion failure via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot...Show more |
2Debian Nlnetlabs2Debian Linux UnboundJun 17, 2026 Apr 27, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Unbound before 1.9.5 allows an assertion failure and denial of service in dname_pkt_copy via an invalid packet. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbou...Show more |
2Debian Nlnetlabs2Debian Linux UnboundJun 17, 2026 Apr 27, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Unbound before 1.9.5 allows an assertion failure and denial of service in synth_cname. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be...Show more |
A flaw was found in Privoxy in versions before 3.0.31. An assertion failure triggered by a crafted CGI request may lead to denial of service. The highest threat from this vulnerability is to system availability. |
2Fedoraproject Torproject2Fedora TorJun 17, 2026 Mar 19, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Tor before 0.4.5.7 allows a remote attacker to cause Tor directory authorities to exit with an assertion failure, aka TROVE-2021-002. |
A denial of service vulnerability was discovered in nbdkit. A client issuing a certain sequence of commands could possibly trigger an assertion failure, causing nbdkit to exit. This issue only affected nbdkit versions 1....Show more |
1Qualcomm 274Apq8017 Firmware Apq8053 FirmwareAqt1000 Firmware+271 moreJun 17, 2026 Mar 17, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Denial of service in baseband when NW configures LTE betaOffset-RI-Index due to lack of data validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,...Show more |
2Fedoraproject Varnish Cache3Fedora Varnish ModulesVarnish Modules KlarlackJun 17, 2026 Mar 16, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Varnish varnish-modules before 0.17.1 allows remote attackers to cause a denial of service (daemon restart) in some configurations. This does not affect organizations that only install the Varnish Cache product; however,...Show more |
A packet of death scenario is possible in mvfst via a specially crafted message during a QUIC session, which causes a crash via a failed assertion. Per QUIC specification, this particular message should be treated as a c...Show more |
1Redhat 2Enterprise Linux LibnbdJun 17, 2026 Mar 15, 2021 N/A· v4 2.7 LOW· v3 4.0 MEDIUM· v2 A flaw was found in libnbd 1.7.3. An assertion failure in nbd_unlocked_opt_go in ilb/opt.c may lead to denial of service. |