CWE-617
781 CVEs • Abstraction: Base
Reachable Assertion
The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.
CVEs (781)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
7Canonical DebianFedoraproject+4 more7Bind Debian LinuxDns Server+4 moreJun 17, 2026 Aug 21, 2020 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10.5-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker that can reach a vulnerable system with a specially crafted query p...Show more |
8Canonical DebianFedoraproject+5 more8Bind Communications Diameter Signaling RouterDebian Linux+5 moreJun 17, 2026 Aug 21, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker on the network path for a TSIG-signed request, or operating the serve...Show more |
5Canonical IscNetapp+2 more5Bind Dns ServerLeap+2 moreJun 17, 2026 Aug 21, 2020 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the...Show more |
4Canonical IscNetapp+1 more4Bind LeapSteelstore Cloud Integrated Storage+1 moreJun 17, 2026 Aug 21, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In BIND 9.15.6 -> 9.16.5, 9.17.0 -> 9.17.3, An attacker who can establish a TCP connection with the server and send data on that connection can exploit this to trigger the assertion failure, causing the server to exit. |
4Canonical DebianOpensuse+1 more4Debian Linux LeapQemu+1 moreJun 17, 2026 Aug 11, 2020 N/A· v4 3.8 LOW· v3 2.1 LOW· v2 In QEMU through 5.0.0, an assertion failure can occur in the network packet processing. This issue affects the e1000e and vmxnet3 network devices. A malicious guest user/process could use this flaw to abort the QEMU proc...Show more |
3Canonical MozillaOpensuse5Firefox Firefox EsrLeap+2 moreJun 17, 2026 Jul 9, 2020 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory corruption and a potentially exploitable crash. *Note: this issue only affects Firefox on ARM64 pla...Show more |
4Canonical IscNetapp+1 more4Bind LeapSteelstore Cloud Integrated Storage+1 moreJun 17, 2026 Jun 17, 2020 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 An attacker who is permitted to send zone data to a server via zone transfer can exploit this to intentionally trigger the assertion failure with a specially constructed zone, denying service to clients. |
4Canonical OpensuseQemu+1 more4Enterprise Linux LeapQemu+1 moreJun 17, 2026 Jun 9, 2020 N/A· v4 5.0 MEDIUM· v3 4.0 MEDIUM· v2 An assertion failure issue was found in the Network Block Device(NBD) Server in all QEMU versions before QEMU 5.0.1. This flaw occurs when an nbd-client sends a spec-compliant request that is near the boundary of maximum...Show more |
1Qualcomm 23Ipq6018 Firmware Ipq8074 FirmwareKamorta Firmware+20 moreJun 17, 2026 Jun 2, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Firmware will hit assert in WLAN firmware If encrypted data length in FILS IE of reassoc response is more than 528 bytes in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapd...Show more |
1Qualcomm 25Apq8009 Firmware Apq8053 FirmwareApq8096au Firmware+22 moreJun 17, 2026 Jun 2, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Valid deauth/disassoc frames is dropped in case if RMF is enabled and some rouge peer keep on sending rogue deauth/disassoc frames due to improper enum values used to check the frame subtype in Snapdragon Auto, Snapdrago...Show more |
VMware ESXi (6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), VMware Workstation (15.x before 15.5.2) and VMware Fusion (11.x before 11.5.2) contain a denial-of-service vulnerability in the shader fu...Show more |
parser/js/js-scanner.c in JerryScript 2.2.0 mishandles errors during certain out-of-memory conditions, as demonstrated by a scanner_reverse_info_list NULL pointer dereference and a scanner_scan_all assertion failure. |
JerryScript 2.2.0 allows attackers to cause a denial of service (assertion failure) because a property key query for a Proxy object returns unintended data. |
5Canonical DebianFedoraproject+2 more5Bind Debian LinuxFedora+2 moreJun 17, 2026 May 19, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the attacker knows (or successfully guesses) the name of a TSIG key used by the server. Since BIND, by...Show more |
1Qualcomm 40Apq8009 Firmware Apq8017 FirmwareApq8053 Firmware+37 moreJun 17, 2026 Apr 16, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Active command timeout since WM status change cmd is not removed from active queue if peer sends multiple deauth frames. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Co...Show more |
1Qualcomm 40Apq8096au Firmware Mdm9205 FirmwareMdm9206 Firmware+37 moreJun 17, 2026 Apr 16, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Error occurs While extracting the ipv6_header having an invalid length due to lack of length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon...Show more |
4Debian OpensuseVarnish Cache+1 more5Backports Sle Debian LinuxLeap+2 moreJun 17, 2026 Apr 8, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occurs when communication with a TLS termination proxy uses PROXY version 2. There can be an assertion f...Show more |
1Qualcomm 21Apq8017 Firmware Apq8053 FirmwareApq8096au Firmware+18 moreJun 17, 2026 Feb 7, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Stage-2 fault will occur while writing to an ION system allocation which has been assigned to non-HLOS memory which is non-standard in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Sn...Show more |
lldpd before 0.8.0 allows remote attackers to cause a denial of service (assertion failure and daemon crash) via a malformed packet. |
stb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_get_index. |