CWE-617
683 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-617page 6 of 14
- CVE-2022-22890MEDIUMCVSS 5.5EG 5.52022-01-20
There is an Assertion 'arguments_type != SCANNER_ARGUMENTS_PRESENT && arguments_type != SCANNER_ARGUMENTS_PRESENT_NO_REG' failed at /jerry-core/parser/js/js-scanner-util.c in Jerryscript 3.0.0.
- CVE-2022-22892MEDIUMCVSS 5.5EG 5.52022-01-21
There is an Assertion 'ecma_is_value_undefined (value) || ecma_is_value_null (value) || ecma_is_value_boolean (value) || ecma_is_value_number (value) || ecma_is_value_string (value) || ecma_is_value_bigint (value) || ecma_is_value_symbol (…
- CVE-2022-22901MEDIUMCVSS 5.5EG 5.52022-02-17
There is an Assertion in 'context_p->next_scanner_info_p->type == SCANNER_TYPE_FUNCTION' failed at parser_parse_function_arguments in /js/js-parser.c of JerryScript commit a6ab5e9.
- CVE-2022-23564MEDIUMCVSS 6.5EG 6.52022-02-04
Tensorflow is an Open Source Machine Learning Framework. When decoding a resource handle tensor from protobuf, a TensorFlow process can encounter cases where a `CHECK` assertion is invalidated based on user controlled arguments. This allow…
- CVE-2022-23565MEDIUMCVSS 6.5EG 6.52022-02-04
Tensorflow is an Open Source Machine Learning Framework. An attacker can trigger denial of service via assertion failure by altering a `SavedModel` on disk such that `AttrDef`s of some operation are duplicated. The fix will be included in …
- CVE-2022-23569MEDIUMCVSS 6.5EG 6.52022-02-03
Tensorflow is an Open Source Machine Learning Framework. Multiple operations in TensorFlow can be used to trigger a denial of service via `CHECK`-fails (i.e., assertion failures). This is similar to TFSA-2021-198 and has similar fixes. We …
- CVE-2022-23570MEDIUMCVSS 6.5EG 6.52022-02-04
Tensorflow is an Open Source Machine Learning Framework. When decoding a tensor from protobuf, TensorFlow might do a null-dereference if attributes of some mutable arguments to some operations are missing from the proto. This is guarded by…
- CVE-2022-23571MEDIUMCVSS 6.5EG 6.52022-02-04
Tensorflow is an Open Source Machine Learning Framework. When decoding a tensor from protobuf, a TensorFlow process can encounter cases where a `CHECK` assertion is invalidated based on user controlled arguments, if the tensors have an inv…
- CVE-2022-23572MEDIUMCVSS 6.5EG 6.52022-02-04
Tensorflow is an Open Source Machine Learning Framework. Under certain scenarios, TensorFlow can fail to specialize a type during shape inference. This case is covered by the `DCHECK` function however, `DCHECK` is a no-op in production bui…
- CVE-2022-23579MEDIUMCVSS 6.5EG 6.52022-02-04
Tensorflow is an Open Source Machine Learning Framework. The Grappler optimizer in TensorFlow can be used to cause a denial of service by altering a `SavedModel` such that `SafeToRemoveIdentity` would trigger `CHECK` failures. The fix will…
- CVE-2022-23581MEDIUMCVSS 6.5EG 6.52022-02-04
Tensorflow is an Open Source Machine Learning Framework. The Grappler optimizer in TensorFlow can be used to cause a denial of service by altering a `SavedModel` such that `IsSimplifiableReshape` would trigger `CHECK` failures. The fix wil…
- CVE-2022-23582MEDIUMCVSS 6.5EG 6.52022-02-04
Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a denial of service by altering a `SavedModel` such that `TensorByteSize` would trigger `CHECK` failures. `TensorShape` constructor throws a `CHECK`-fail i…
- CVE-2022-23583MEDIUMCVSS 6.5EG 6.52022-02-04
Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a denial of service by altering a `SavedModel` such that any binary op would trigger `CHECK` failures. This occurs when the protobuf part corresponding to …
- CVE-2022-23586MEDIUMCVSS 6.5EG 6.52022-02-04
Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a denial of service by altering a `SavedModel` such that assertions in `function.cc` would be falsified and crash the Python interpreter. The fix will be i…
- CVE-2022-23588MEDIUMCVSS 6.5EG 6.52022-02-04
Tensorflow is an Open Source Machine Learning Framework. A malicious user can cause a denial of service by altering a `SavedModel` such that Grappler optimizer would attempt to build a tensor using a reference `dtype`. This would result in…
- CVE-2022-24272MEDIUMCVSS 6.5EG 6.52022-04-21
An authenticated user may trigger an invariant assertion during command dispatch due to incorrect validation on the $external database. This may result in mongod denial of service or server crash. This issue affects: MongoDB Inc. MongoDB S…
- CVE-2022-24777HIGHCVSS 7.5EG 7.52022-03-25
grpc-swift is the Swift language implementation of gRPC, a remote procedure call (RPC) framework. Prior to version 1.7.2, a grpc-swift server is vulnerable to a denial of service attack via a reachable assertion. This is due to incorrect l…
- CVE-2022-2520MEDIUMCVSS 6.5EG 6.52022-08-31
A flaw was found in libtiff 4.4.0rc1. There is a sysmalloc assertion fail in rotateImage() at tiffcrop.c:8621 that can cause program crash when reading a crafted input.
- CVE-2022-25484MEDIUMCVSS 5.5EG 5.52022-03-22
tcpprep v4.4.1 has a reachable assertion (assert(l2len > 0)) in packet2tree() at tree.c in tcpprep v4.4.1.
- CVE-2022-25671HIGHCVSS 7.5EG 7.52022-11-15
Denial of service in MODEM due to reachable assertion in Snapdragon Mobile
- CVE-2022-25672HIGHCVSS 7.5EG 7.52022-12-13
Denial of service in MODEM due to reachable assertion while processing SIB1 with invalid Bandwidth in Snapdragon Mobile
- CVE-2022-25673HIGHCVSS 7.5EG 7.52022-12-13
Denial of service in MODEM due to reachable assertion while processing configuration from network in Snapdragon Mobile
- CVE-2022-25675MEDIUMCVSS 5.5EG 5.52022-12-13
Denial of service due to reachable assertion in modem while processing filter rule from application client in Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile
- CVE-2022-25689HIGHCVSS 7.5EG 7.52022-12-13
Denial of service in Modem due to reachable assertion in Snapdragon Mobile
- CVE-2022-25691HIGHCVSS 7.5EG 7.52022-12-13
Denial of service in Modem due to reachable assertion while processing SIB1 with invalid SCS and bandwidth settings in Snapdragon Mobile
- CVE-2022-25692HIGHCVSS 7.5EG 7.52022-12-13
Denial of service in Modem due to reachable assertion while processing the common config procedure in Snapdragon Auto, Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
- CVE-2022-25702HIGHCVSS 7.5EG 7.52022-12-13
Denial of service in modem due to reachable assertion while processing reconfiguration message in Snapdragon Auto, Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
- CVE-2022-26446HIGHCVSS 7.5EG 7.52022-11-08
In Modem 4G RRC, there is a possible system crash due to improper input validation. This could lead to remote denial of service, when concatenating improper SIB12 (CMAS message), with no additional execution privileges needed. User interac…
- CVE-2022-2719MEDIUMCVSS 5.5EG 5.52022-08-10
In ImageMagick, a crafted file could trigger an assertion failure when a call to WriteImages was made in MagickWand/operation.c, due to a NULL image list. This could potentially cause a denial of service. This was fixed in upstream ImageMa…
- CVE-2022-27382HIGHCVSS 7.5EG 7.52022-04-12
MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component Item_field::used_tables/update_depend_map_for_order.
- CVE-2022-27448HIGHCVSS 7.5EG 7.52022-04-14
There is an Assertion failure in MariaDB Server v10.9 and below via 'node->pcur->rel_pos == BTR_PCUR_ON' at /row/row0mysql.cc.
- CVE-2022-27938MEDIUMCVSS 5.5EG 5.52022-03-26
stb_image.h (aka the stb image loader) 2.19, as used in libsixel and other products, has a reachable assertion in stbi__create_png_image_raw.
- CVE-2022-27939MEDIUMCVSS 5.5EG 5.52022-03-26
tcprewrite in Tcpreplay 4.4.1 has a reachable assertion in get_layer4_v6 in common/get.c.
- CVE-2022-29213MEDIUMCVSS 5.5EG 5.52022-05-21
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the `tf.compat.v1.signal.rfft2d` and `tf.compat.v1.signal.rfft3d` lack input validation and under certain condition can result in…
- CVE-2022-29228HIGHCVSS 7.5EG 7.52022-06-09
Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter would try to invoke the remaining filters in the chain after emitting a local response, which triggers an ASSERT() in newer versions and corrupts …
- CVE-2022-29339HIGHCVSS 7.5EG 7.52022-05-05
In GPAC 2.1-DEV-rev87-g053aae8-master, function BS_ReadByte() in utils/bitstream.c has a failed assertion, which causes a Denial of Service. This vulnerability was fixed in commit 9ea93a2.
- CVE-2022-29917CRITICALCVSS 9.8EG 9.82022-12-22
Mozilla developers Andrew McCreight, Gabriele Svelto, Tom Ritter and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 99 and Firefox ESR 91.8. Some of these bugs showed evidence of memory corruption and we presume th…
- CVE-2022-29977MEDIUMCVSS 6.5EG 6.52022-05-11
There is an assertion failure error in stbi__jpeg_huff_decode, stb_image.h:1894 in libsixel img2sixel 1.8.6. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted JPEG file.
- CVE-2022-31009MEDIUMCVSS 5.7EG 5.72022-06-23
wire-ios is an iOS client for the Wire secure messaging application. Invalid accent colors of Wire communication partners may render the iOS Wire Client partially unusable by causing it to crash multiple times on launch. These invalid acce…
- CVE-2022-31100MEDIUMCVSS 6.5EG 6.52022-06-27
rulex is a new, portable, regular expression language. When parsing untrusted rulex expressions, rulex may crash, possibly enabling a Denial of Service attack. This happens when the expression contains a multi-byte UTF-8 code point in a st…
- CVE-2022-31620MEDIUMCVSS 6.5EG 6.52022-05-25
In libjpeg before 1.64, BitStream<false>::Get in bitstream.hpp has an assertion failure that may cause denial of service. This is related to out-of-bounds array access during arithmetically coded lossless scan or arithmetically coded seque…
- CVE-2022-31651MEDIUMCVSS 5.5EG 7.52022-05-25
In SoX 14.4.2, there is an assertion failure in rate_init in rate.c in libsox.a.
- CVE-2022-32082HIGHCVSS 7.5EG 7.52022-07-01
MariaDB v10.5 to v10.7 was discovered to contain an assertion failure at table->get_ref_count() == 0 in dict0dict.cc.
- CVE-2022-32978MEDIUMCVSS 6.5EG 6.52022-06-10
There is an assertion failure in SingleComponentLSScan::ParseMCU in singlecomponentlsscan.cpp in libjpeg before 1.64 via an empty JPEG-LS scan.
- CVE-2022-33024HIGHCVSS 7.5EG 7.52022-06-23
There is an Assertion `int decode_preR13_entities(BITCODE_RL, BITCODE_RL, unsigned int, BITCODE_RL, BITCODE_RL, Bit_Chain *, Dwg_Data *' failed at dwg2dxf: decode.c:5801 in libredwg v0.12.4.4608.
- CVE-2022-33069MEDIUMCVSS 5.5EG 5.52022-06-23
Ethereum Solidity v0.8.14 contains an assertion failure via SMTEncoder::indexOrMemberAssignment() at SMTEncoder.cpp.
- CVE-2022-33244HIGHCVSS 7.5EG 7.52023-03-10
Transient DOS due to reachable assertion in modem during MIB reception and SIB timeout
- CVE-2022-33250HIGHCVSS 7.5EG 7.52023-03-10
Transient DOS due to reachable assertion in modem when network repeatedly sent invalid message container for NR to LTE handover.
- CVE-2022-33251HIGHCVSS 7.5EG 7.52023-06-06
Transient DOS due to reachable assertion in Modem because of invalid network configuration.
- CVE-2022-33254HIGHCVSS 7.5EG 7.52023-03-10
Transient DOS due to reachable assertion in Modem while processing SIB1 Message.
Map vulnerabilities like CWE-617 to your infrastructure
EchelonGraph correlates every CVE — across CWE-617 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →