← Back
CWE-755

585 CVEs • Abstraction: Class • Likelihood of Exploit: Medium

Improper Handling of Exceptional Conditions

The product does not handle or incorrectly handles an exceptional condition.

JSON object

Loading...

CVEs (585)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Chrome
Jun 17, 2026
Nov 25, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient policy enforcement in developer tools in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
1Apple
1Iphone 3gs
Jun 17, 2026
Nov 22, 2019
N/A· v4
6.8 MEDIUM· v3
6.9 MEDIUM· v2
Apple iPhone 3GS bootrom malloc implementation returns a non-NULL pointer when unable to allocate memory, aka 'alloc8'. An attacker with physical access to the device can install arbitrary firmware.
2Debian
Horms
2Debian Linux
Perdition
Nov 21, 2024
Nov 15, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Perdition before 2.2 may have weak security when handling outbound connections, caused by an error in the STARTTLS IMAP and POP server. ssl_outgoing_ciphers not being applied to STARTTLS connections
1Espressif
4Esp32 D0wd Firmware
Esp32 D2wd FirmwareEsp32 Pico D4 Firmware+1 more
Jun 17, 2026
Nov 14, 2019
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
An issue was discovered in the Espressif ESP32 mask ROM code 2016-06-08 0 through 2. Lack of anti-glitch mitigations in the first stage bootloader of the ESP32 chip allows an attacker (with physical access to the device)...Show more
An issue was discovered in the Espressif ESP32 mask ROM code 2016-06-08 0 through 2. Lack of anti-glitch mitigations in the first stage bootloader of the ESP32 chip allows an attacker (with physical access to the device) to read the contents of read-protected eFuses, such as flash encryption and secure boot keys, by injecting a glitch into the power supply of the chip shortly after reset.Show less
1Intel
7Ethernet 700 Series Software
Ethernet Controller 710 Bm1 FirmwareEthernet Controller X710 At2 Firmware+4 more
Jun 17, 2026
Nov 14, 2019
N/A· v4
6.5 MEDIUM· v3
4.9 MEDIUM· v2
Unhandled exception in firmware for Intel(R) Ethernet 700 Series Controllers before version 7.0 may allow an authenticated user to potentially enable a denial of service via local access.
1Intel
7Ethernet 700 Series Software
Ethernet Controller 710 Bm1 FirmwareEthernet Controller X710 At2 Firmware+4 more
Jun 17, 2026
Nov 14, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
Unhandled exception in Kernel-mode drivers for Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow an authenticated user to potentially enable a denial of service via local access.
1Intel
1Baseboard Management Controller Firmware
Jun 17, 2026
Nov 14, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Unhandled exception in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable denial of service via network access.
1Pediapress
1Mwlib
Nov 21, 2024
Nov 12, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
mwlib 0.13 through 0.13.4 has a denial of service vulnerability when parsing #iferror magic functions
3Ceph
FedoraprojectRedhat
3Ceph
Ceph StorageFedora
Jun 17, 2026
Nov 8, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated attacker could crash the Ceph RGW server by sending valid HTTP headers and terminating the connectio...Show more
A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated attacker could crash the Ceph RGW server by sending valid HTTP headers and terminating the connection, resulting in a remote denial of service for Ceph RGW clients.Show less
1Google
1Blink
Nov 21, 2024
Nov 7, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue exists in WebKit in Google Chrome before Blink M12. when clearing lists in AnimationControllerPrivate that signal when a hardware animation starts.
1Google
1Blink
Nov 21, 2024
Nov 7, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Incorrect handling of timer information in Timer.cpp in WebKit in Google Chrome before Blink M13.
2Debian
Simplesamlphp
2Debian Linux
Simplesamlphp
Nov 21, 2024
Nov 6, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
simplesamlphp before 1.6.3 (squeeze) and before 1.8.2 (sid) incorrectly handles XML encryption which could allow remote attackers to decrypt or forge messages.
1Wpwham
1Currency Switcher For Woocommerce
Jun 17, 2026
Nov 2, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in the Currency Switcher addon before 2.11.2 for WooCommerce if a user provides a currency that was not added by the administrator. In this case, even though the currency does not exist, it will b...Show more
An issue was discovered in the Currency Switcher addon before 2.11.2 for WooCommerce if a user provides a currency that was not added by the administrator. In this case, even though the currency does not exist, it will be selected, but a price amount will fall back to the default currency. This means that if an attacker provides a currency that does not exist and is worth less than this default, the attacker can eventually purchase an item for a significantly cheaper price.Show less
2Burn Project
Debian
2Burn
Debian Linux
Nov 21, 2024
Oct 31, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
burn allows file names to escape via mishandled quotation marks
1Schneider Electric
3Modicon Bmenoc 0311 Firmware
Modicon Bmenoc 0321 FirmwareModicon M580 Firmware
Jun 17, 2026
Oct 29, 2019
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 CPU (BMEx58*) and Modicon M580 communication module (BMENOC0311, BMENOC0321) (see notification for version info), which could ca...Show more
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 CPU (BMEx58*) and Modicon M580 communication module (BMENOC0311, BMENOC0321) (see notification for version info), which could cause a Denial of Service attack on the PLC when sending specific data on the REST API of the controller/communication module.Show less
1Schneider Electric
4Modicon 140cra Firmware
Modicon Bmxcra FirmwareModicon M340 Firmware+1 more
Jun 17, 2026
Oct 29, 2019
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause a Denial of Service attack on the FT...Show more
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause a Denial of Service attack on the FTP service when upgrading the firmware with a version incompatible with the application in the controller using FTP protocol.Show less
1Schneider Electric
4Modicon 140cra Firmware
Modicon Bmxcra FirmwareModicon M340 Firmware+1 more
Jun 17, 2026
Oct 29, 2019
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause a Denial of Service atack on the PLC...Show more
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause a Denial of Service atack on the PLC when upgrading the controller with a firmware package containing an invalid web server image using FTP protocol.Show less
1Schneider Electric
4Modicon 140cra Firmware
Modicon Bmxcra FirmwareModicon M340 Firmware+1 more
Jun 17, 2026
Oct 29, 2019
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 with firmware (version prior to V3.10), Modicon M340 (all firmware versions), and Modicon BMxCRA and 140CRA modules (all firmwar...Show more
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 with firmware (version prior to V3.10), Modicon M340 (all firmware versions), and Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause a Denial of Service attack on the PLC when upgrading the controller with an empty firmware package using FTP protocol.Show less
1Schneider Electric
4Modicon 140cra Firmware
Modicon Bmxcra FirmwareModicon M340 Firmware+1 more
Jun 17, 2026
Oct 29, 2019
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause a Denial of Service attack on the PL...Show more
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause a Denial of Service attack on the PLC when upgrading the firmware with a missing web server image inside the package using FTP protocol.Show less
1Schneider Electric
4Modicon 140cra Firmware
Modicon Bmxcra FirmwareModicon M340 Firmware+1 more
Jun 17, 2026
Oct 29, 2019
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 with firmware (version prior to V3.10), Modicon M340 (all firmware versions), and Modicon BMxCRA and 140CRA modules (all firmwar...Show more
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 with firmware (version prior to V3.10), Modicon M340 (all firmware versions), and Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause a Denial of Service attack on the PLC when upgrading the firmware with no firmware image inside the package using FTP protocol.Show less