CWE-617
781 CVEs • Abstraction: Base
Reachable Assertion
The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.
CVEs (781)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An exploitable denial of service vulnerability exists in the object lookup functionality of Yara 3.8.1. A specially crafted binary file can cause a negative value to be read to satisfy an assert, resulting in Denial of S...Show more |
2Openmpt Opensuse2Leap LibopenmptJun 17, 2026 Jul 30, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 J2B in libopenmpt before 0.4.2 allows an assertion failure during file parsing with debug STLs. |
DSM in libopenmpt before 0.4.2 allows an assertion failure during file parsing with debug STLs. |
Jsish 2.4.84 2.0484 is affected by: Reachable Assertion. The impact is: denial of service. The component is: function Jsi_ValueArrayIndex (jsiValue.c:366). The attack vector is: executing crafted javascript code. The fix...Show more |
3Canonical Exiv2Fedoraproject3Exiv2 FedoraUbuntu LinuxJun 17, 2026 Jun 30, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to assertion failure) via an invalid data location in a CRW image file. |
In Libreswan 3.27 an assertion failure can lead to a pluto IKE daemon restart. An attacker can trigger a NULL pointer dereference by initiating an IKEv2 IKE_SA_INIT exchange, followed by a bogus INFORMATIONAL exchange in...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdJun 17, 2026 Apr 26, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially be used by malicious JavaScript to trigger a potentially exploitable crash. This vulnerability affects Thunderbird < 60....Show more |
1Redhat 3Enterprise Linux Server Aus Enterprise Linux Server EusEnterprise Linux Server TusNov 21, 2024 Apr 9, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A denial of service flaw was found in the way BIND handled DNSSEC validation. A remote attacker could use this flaw to make named exit unexpectedly with an assertion failure via a specially crafted DNS response. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Apr 9, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the GSS-API dissector could crash. This was addressed in epan/dissectors/packet-gssapi.c by ensuring that a valid dissector is called. |
3Fedoraproject GnuSuse3Backports FedoraPsppJun 17, 2026 Feb 27, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 There is a reachable assertion abort in the function write_long_string_missing_values() in data/sys-file-writer.c in libdata.a in GNU PSPP 1.2.0 that will lead to denial of service. |
An issue was discovered in Bento4 v1.5.1-627. There is an assertion failure in AP4_AtomListWriter::Action in Core/Ap4Atom.cpp, leading to a denial of service (program crash), as demonstrated by mp42hls. |
An assertion failure was discovered in wasm::WasmBinaryBuilder::getType() in wasm-binary.cpp in Binaryen 1.38.22. This allows remote attackers to cause a denial of service (failed assertion and crash) via a crafted wasm...Show more |
7Canonical DebianHp+4 more11Bind Data Ontap EdgeDebian Linux+8 moreJun 17, 2026 Jan 16, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 "deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the security model used by client browsers....Show more |
2Isc Netapp3Bind Cloud BackupData Ontap EdgeJun 17, 2026 Jan 16, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A problem with the implementation of the new serve-stale feature in BIND 9.12 can lead to an assertion failure in rbtdb.c, even when stale-answer-enable is off. Additionally, problematic interaction between the serve-sta...Show more |
2Isc Netapp3Bind Cloud BackupData Ontap EdgeJun 17, 2026 Jan 16, 2019 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 An error in zone database reference counting can lead to an assertion failure if a server which is running an affected version of BIND attempts several transfers of a slave zone in quick succession. This defect could be...Show more |
2Isc Netapp3Bind Data Ontap EdgeSolidfire Element Os Management NodeJun 17, 2026 Jan 16, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 While handling a particular type of malformed packet BIND erroneously selects a SERVFAIL rcode instead of a FORMERR rcode. If the receiving view has the SERVFAIL cache feature enabled, this can trigger an assertion failu...Show more |
3Debian IscNetapp5Bind Data Ontap EdgeDebian Linux+2 moreNov 21, 2024 Jan 16, 2019 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 named contains a feature which allows operators to issue commands to a running server by communicating with the server process over a control channel, using a utility program such as rndc. A regression introduced in a re...Show more |
4Debian IscNetapp+1 more11Bind Data Ontap EdgeDebian Linux+8 moreNov 21, 2024 Jan 16, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resource records could lead to a situation in which named would exit with an assertion failure when process...Show more |
4Debian IscNetapp+1 more11Bind Data Ontap EdgeDebian Linux+8 moreNov 21, 2024 Jan 16, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A query with a specific set of characteristics could cause a server using DNS64 to encounter an assertion failure and terminate. An attacker could deliberately construct a query, enabling denial-of-service against a serv...Show more |
An issue was discovered in cairo 1.16.0. There is an assertion problem in the function _cairo_arc_in_direction in the file cairo-arc.c. |