CWE-617
781 CVEs • Abstraction: Base
Reachable Assertion
The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.
CVEs (781)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Privoxy2Debian Linux PrivoxyJun 17, 2026 Mar 9, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in privoxy before 3.0.32. An assertion failure could be triggered with a crafted CGI request leading to server crash. |
Context-specific code was included in a shared jump table; resulting in assertions being triggered in multithreaded wasm code. This vulnerability affects Firefox < 86. |
1Qualcomm 532Apq8009 Firmware Apq8017 FirmwareApq8053 Firmware+529 moreJun 17, 2026 Feb 22, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Arithmetic overflow can happen while processing NOA IE due to improper error handling in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT...Show more |
1Qualcomm 412Aqt1000 Firmware Ar7420 FirmwareAr8031 Firmware+409 moreJun 17, 2026 Feb 22, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Denial of service while processing fine timing measurement request (FTMR) frame with reserved bits set in the FTM parameter IE due to improper error handling in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivit...Show more |
1Qualcomm 377Aqt1000 Firmware Ar8031 FirmwareAr8035 Firmware+374 moreJun 17, 2026 Feb 22, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Possible denial of service while handling host WMI command due to improper validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT...Show more |
2Debian Openldap2Debian Linux OpenldapJun 17, 2026 Feb 14, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function via a crafted packet, resulting in a denial of service (daemon exit) via a short t...Show more |
5Debian FujitsuGnu+2 more11Communications Cloud Native Core Security Edge Protection Proxy Debian LinuxE Series Santricity Os Controller+8 moreJun 17, 2026 Jan 27, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid input sequences in the ISO-2022-JP-3 encoding, fails an assertion in the code path and aborts the program, potentiall...Show more |
4Apache AppleDebian+1 more5Bookkeeper Debian LinuxMac Os X+2 moreJun 17, 2026 Jan 26, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_element, resulting in denial of service. |
3Apple DebianOpenldap4Debian Linux Mac Os XMacos+1 moreJun 17, 2026 Jan 26, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial of service. |
3Fedoraproject GnuNetapp3E Series Santricity Os Controller FedoraGlibcJun 17, 2026 Dec 4, 2020 N/A· v4 4.8 MEDIUM· v3 2.1 LOW· v2 The iconv function in the GNU C Library (aka glibc or libc6) 2.30 to 2.32, when converting UCS4 text containing an irreversible character, fails an assertion in the code path and aborts the program, potentially resulting...Show more |
A reachable assertion issue was found in the USB EHCI emulation code of QEMU. It could occur while processing USB requests due to missing handling of DMA memory map failure. A malicious privileged user within the guest m...Show more |
2Debian Qemu2Debian Linux QemuJun 17, 2026 Nov 6, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 eth_get_gso_type in net/eth.c in QEMU 4.2.1 allows guest OS users to trigger an assertion failure. A guest can crash the QEMU process via packet data that lacks a valid Layer 3 protocol. |
3Debian Fastd ProjectFedoraproject3Debian Linux FastdFedoraJun 17, 2026 Oct 22, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 receive.c in fastd before v21 allows denial of service (assertion failure) when receiving packets with an invalid type code. |
Receipt of a specifically malformed NDP packet sent from the local area network (LAN) to a device running Juniper Networks Junos OS Evolved can cause the ndp process to crash, resulting in a Denial of Service (DoS). The...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdJun 17, 2026 Oct 1, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Mozilla developers reported memory safety bugs present in Firefox for Android 79. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to...Show more |
In Tensorflow before version 2.3.1, the `SparseCountSparseOutput` implementation does not validate that the input arguments form a valid sparse tensor. In particular, there is no validation that the `indices` tensor has...Show more |
2Google Opensuse2Leap TensorflowJun 17, 2026 Sep 25, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `SparseFillEmptyRowsGrad` implementation has incomplete validation of the shapes of its arguments. Although `reverse_index_map_t` and `grad_values_...Show more |
3Atftp Project DebianOpensuse3Atftp Debian LinuxLeapJun 17, 2026 Sep 10, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An exploitable denial of service vulnerability exists in the atftpd daemon functionality of atftp 0.7.git20120829-3.1+b1. A specially crafted sequence of RRQ-Multicast requests trigger an assert() call resulting in denia...Show more |
1Qualcomm 27Apq8098 Firmware Kamorta FirmwareMsm8917 Firmware+24 moreJun 17, 2026 Sep 9, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 u'Reachable assertion when wrong data size is returned by parser for ape clips' in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in APQ8098, Kamorta, MSM8917, MSM8953, Nicobar, QC...Show more |
The Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.0 through 4.2 (for ESP32 devices) returns the wrong number of completed BLE packets and triggers a reachable assertion on the host stack whe...Show more |