← Back
CWE-617

781 CVEs • Abstraction: Base

Reachable Assertion

The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

JSON object

Loading...

CVEs (781)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sap
1Hana Xs
May 13, 2026
May 23, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
sinopia, as used in SAP HANA XS 1.00 and 2.00, allows remote attackers to cause a denial of service (assertion failure and service crash) by pushing a package with a filename containing a $ (dollar sign) or % (percent) c...Show more
sinopia, as used in SAP HANA XS 1.00 and 2.00, allows remote attackers to cause a denial of service (assertion failure and service crash) by pushing a package with a filename containing a $ (dollar sign) or % (percent) character, aka SAP Security Note 2407694.Show less
2Debian
Imagemagick
2Debian Linux
Imagemagick
May 13, 2026
May 22, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In ImageMagick 7.0.5-7 Q16, a crafted file could trigger an assertion failure in the WriteBlob function in MagickCore/blob.c because of missing checks in the ReadOneJNGImage function in coders/png.c.
2Debian
Imagemagick
2Debian Linux
Imagemagick
May 13, 2026
May 22, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In ImageMagick 7.0.5-7 Q16, a crafted file could trigger an assertion failure in the ResetImageProfileIterator function in MagickCore/profile.c because of missing checks in the ReadDDSImage function in coders/dds.c.
1Openvpn
1Openvpn
May 13, 2026
May 15, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
OpenVPN versions before 2.3.15 and before 2.4.2 are vulnerable to reachable assertion when packet-ID counter rolls over resulting into Denial of Service of server by authenticated attacker.
1Openvpn
1Openvpn
May 13, 2026
May 15, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue is fixed in 2.3.15 and 2.4.2.
1Underbit
1Mad Libmad
May 13, 2026
May 1, 2017
N/A· v4
4.7 MEDIUM· v3
2.6 LOW· v2
The mad_layer_III function in layer3.c in Underbit MAD libmad 0.15.1b, if NDEBUG is omitted, allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted audio file.
1Libaacplus Project
1Libaacplus
May 13, 2026
Apr 9, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
aacplusenc.c in HE-AAC+ Codec (aka libaacplus) 2.0.2 has an assertion failure, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted a...Show more
aacplusenc.c in HE-AAC+ Codec (aka libaacplus) 2.0.2 has an assertion failure, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted audio file.Show less
3Fedoraproject
Jasper ProjectOpensuse
3Fedora
JasperLeap
May 13, 2026
Mar 23, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The calcstepsizes function in jpc_dec.c in JasPer 1.900.22 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors.
4Fedoraproject
Jasper ProjectOpensuse+1 more
6Fedora
JasperLeap+3 more
May 13, 2026
Mar 23, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The jpc_floorlog2 function in jpc_math.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors.
2Fedoraproject
Jasper Project
2Fedora
Jasper
May 13, 2026
Mar 23, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The jpc_dequantize function in jpc_dec.c in JasPer 1.900.13 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors.
2Canonical
Jasper Project
2Jasper
Ubuntu Linux
May 13, 2026
Mar 23, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The ras_getcmap function in ras_dec.c in JasPer before 1.900.14 allows remote attackers to cause a denial of service (assertion failure) via a crafted image file.
1Gdraheim
1Zziplib
May 13, 2026
Mar 1, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
seeko.c in zziplib 0.13.62 allows remote attackers to cause a denial of service (assertion failure and crash) via a crafted ZIP file.
1Linux
1Linux Kernel
May 13, 2026
Feb 18, 2017
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
Race condition in the sctp_wait_for_sndbuf function in net/sctp/socket.c in the Linux kernel before 4.9.11 allows local users to cause a denial of service (assertion failure and panic) via a multithreaded application tha...Show more
Race condition in the sctp_wait_for_sndbuf function in net/sctp/socket.c in the Linux kernel before 4.9.11 allows local users to cause a denial of service (assertion failure and panic) via a multithreaded application that peels off an association in a certain buffer-full state.Show less
2Debian
Qemu
2Debian Linux
Qemu
May 6, 2026
Dec 29, 2016
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue. It could occur while reading Interrupt Mask Registers (IMR). A privileged (CAP_SYS_RAWIO) guest user co...Show more
QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue. It could occur while reading Interrupt Mask Registers (IMR). A privileged (CAP_SYS_RAWIO) guest user could use this flaw to crash the QEMU process instance resulting in DoS.Show less
4Debian
IscNetapp+1 more
11Bind
Data Ontap EdgeDebian Linux+8 more
May 6, 2026
Nov 2, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9.11.x before 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNAME record in the answer sectio...Show more
named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9.11.x before 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNAME record in the answer section of a response to a recursive query, related to db.c and resolver.c.Show less
1Google
1Chrome
Apr 29, 2026
Sep 16, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Google Chrome before 6.0.472.59 on Linux does not properly handle cursors, which might allow attackers to cause a denial of service (assertion failure) via unspecified vectors.
1Time Travellers
1Oftpd
Apr 23, 2026
Jan 16, 2007
N/A· v4
7.5 HIGH· v3
9.4 HIGH· v2
oftpd before 0.3.7 allows remote attackers to cause a denial of service (daemon abort) via a (1) LPRT or (2) LPASV command with an unsupported address family, which triggers an assertion failure.
2Canonical
Kde
2Ksirc
Ubuntu Linux
Apr 23, 2026
Dec 29, 2006
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
KsIRC 1.3.12 allows remote attackers to cause a denial of service (crash) via a long PRIVMSG string when connecting to an Internet Relay Chat (IRC) server, which causes an assertion failure and results in a NULL pointer...Show more
KsIRC 1.3.12 allows remote attackers to cause a denial of service (crash) via a long PRIVMSG string when connecting to an Internet Relay Chat (IRC) server, which causes an assertion failure and results in a NULL pointer dereference. NOTE: this issue was originally reported as a buffer overflow.Show less
2Canonical
Openldap
2Openldap
Ubuntu Linux
Apr 23, 2026
Nov 7, 2006
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
OpenLDAP before 2.3.29 allows remote attackers to cause a denial of service (daemon crash) via LDAP BIND requests with long authcid names, which triggers an assertion failure.
1Wireshark
1Wireshark
Apr 23, 2026
Oct 28, 2006
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Off-by-one error in the MIME Multipart dissector in Wireshark (formerly Ethereal) 0.10.1 through 0.99.3 allows remote attackers to cause a denial of service (crash) via certain vectors that trigger an assertion error rel...Show more
Off-by-one error in the MIME Multipart dissector in Wireshark (formerly Ethereal) 0.10.1 through 0.99.3 allows remote attackers to cause a denial of service (crash) via certain vectors that trigger an assertion error related to unexpected length values.Show less