CWE-697
158 CVEs • Abstraction: Pillar
Incorrect Comparison
The product compares two entities in a security-relevant context, but the comparison is incorrect, which may lead to resultant weaknesses.
CVEs (158)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Jpeg Quant Smooth Project 1Jpeg Quant Smooth Jun 17, 2026 Aug 16, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 jpeg-quantsmooth before commit 8879454 contained a floating point exception (FPE) via /jpeg-quantsmooth/jpegqs+0x4f5d6c. |
JPEGDEC commit be4843c was discovered to contain a FPE via DecodeJPEG at /src/jpeg.inl. |
JetBrains Ktor before 2.1.0 was vulnerable to the Reflect File Download attack |
An Incorrect Comparison vulnerability in PFE of Juniper Networks Junos OS allows an adjacent unauthenticated attacker to cause a Denial of Service (DoS). On QFX5000 Series, and EX4600 and EX4650 platforms, the fxpc proce...Show more |
Cross-origin resource sharing (CORS) enables browsers to perform cross domain requests in a controlled manner. This request has an Origin header that identifies the domain that is making the initial request and defines t...Show more |
4Apple DebianFedoraproject+1 more6Cups CupsDebian Linux+3 moreJun 17, 2026 May 26, 2022 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. An application may be able to gain elevated privileges. |
1Sound Exchange Project 1Sound Exchange Jun 17, 2026 May 25, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In SoX 14.4.2, there is a floating-point exception in lsx_aiffstartwrite in aiff.c in libsox.a. |
In search engine service, there is a possible way to change the default search engine due to an incorrect comparison. This could lead to local escalation of privilege with System execution privileges needed. User interac...Show more |
Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. In version 0.3.1 and prior, bytestrings can have dirty bytes in them, resulting in the word-for-word comparisons giving incorrect results. Eve...Show more |
1Tenda 2Ac15 Firmware Ac5 FirmwareJul 9, 2026 Jan 28, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_multi and so on. an attacker can obtain sensitive information, and even combine it...Show more |
1F5 14Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+11 moreJun 17, 2026 Jan 25, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 On BIG-IP versions 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, 13.1.x beginning in 13.1.3.6, 12.1.5.3-12.1.6, and 11.6.5.2, when a FastL4 profile and an HTTP, FIX, and/or hash persistence profile are configured on the...Show more |
1Netgear 17Ac2100 Firmware Ac2400 FirmwareAc2600 Firmware+14 moreJun 17, 2026 Jan 25, 2022 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of multiple NETGEAR routers. Authentication is not required to exploit this vulnerability. The specific flaw exists...Show more |
A limited authentication bypass vulnerability was discovered that could allow an attacker to achieve remote code execution and escalate privileges on the My Cloud devices. Addressed this vulnerability by changing access...Show more |
A Segmentation fault caused by a floating point exception exists in Gpac through 1.0.1 using mp4box via the naludmx_enqueue_or_dispatch function in reframe_nalu.c, which causes a denial of service. |
1Unicorn Engine 1Unicorn Engine Jun 17, 2026 Dec 26, 2021 N/A· v4 8.1 HIGH· v3 6.9 MEDIUM· v2 An issue was discovered in split_region in uc.c in Unicorn Engine before 2.0.0-rc5. It allows local attackers to escape the sandbox. An attacker must first obtain the ability to execute crafted code in the target sandbox...Show more |
2Cvxopt Project Fedoraproject2Cvxopt FedoraJun 17, 2026 Dec 17, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Incomplete string comparison vulnerability exits in cvxopt.org cvxop <= 1.2.6 in APIs (cvxopt.cholmod.diag, cvxopt.cholmod.getfactor, cvxopt.cholmod.solve, cvxopt.cholmod.spsolve), which allows attackers to conduct Denia...Show more |
2Numpy Oracle2Communications Cloud Native Core Policy NumpyJun 17, 2026 Dec 17, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An incomplete string comparison in the numpy.core component in NumPy before 1.22.0 allows attackers to trigger slightly incorrect copying by constructing specific string objects. NOTE: the vendor states that this reporte...Show more |
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A regular expression rel...Show more |
An Incomplete Comparison with Missing Factors vulnerability in the Gallagher Controller allows an attacker to bypass PIV verification. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.40.1888 (MR3);...Show more |
Integria IMS login check uses a loose comparator ("==") to compare the MD5 hash of the password provided by the user and the MD5 hash stored in the database. An attacker with a specific formatted password could exploit t...Show more |