CWE-697— Incorrect Comparison
148 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-697page 1 of 3
- CVE-2005-2801HIGHCVSS 7.5EG 7.52005-09-06
xattr.c in the ext2 and ext3 file system code for Linux kernel 2.6 does not properly compare the name_index fields when sharing xattr blocks, which could prevent default ACLs from being applied.
- CVE-2011-3903NONECVSS 0.0EG 0.02011-12-13
Google Chrome before 16.0.912.63 does not properly perform regex matching, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
- CVE-2014-125057LOWCVSS 3.1EG 9.82023-01-07
A vulnerability was found in mrobit robitailletheknot. It has been classified as problematic. This affects an unknown part of the file app/filters.php of the component CSRF Token Handler. The manipulation of the argument _token leads to in…
- CVE-2015-10129LOWCVSS 3.7EG 3.72024-02-04
A vulnerability was found in planet-freo up to 20150116 and classified as problematic. Affected by this issue is some unknown functionality of the file admin/inc/auth.inc.php. The manipulation of the argument auth leads to incorrect compar…
- CVE-2015-6964MEDIUMCVSS 5.3EG 5.32023-09-25
MultiBit HD before 0.1.2 allows attackers to conduct bit-flipping attacks that insert unspendable Bitcoin addresses into the list that MultiBit uses to send fees to the developers. (Attackers cannot realistically steal these fees for thems…
- CVE-2015-9238MEDIUMCVSS 5.3EG 5.32018-05-31
secure-compare 3.0.0 and below do not actually compare two strings properly. compare was actually comparing the first argument with itself, meaning the check passed for any two strings of the same length.
- CVE-2019-20634LOWCVSS 3.7EG 3.72020-03-30
An issue was discovered in Proofpoint Email Protection through 2019-09-08. By collecting scores from Proofpoint email headers, it is possible to build a copy-cat Machine Learning Classification model and extract insights from this model. T…
- CVE-2019-20925HIGHCVSS 7.5EG 7.52020-11-24
An unauthenticated client can trigger denial of service by issuing specially crafted wire protocol messages, which cause the message decompressor to incorrectly allocate memory. This issue affects MongoDB Server v4.2 versions prior to 4.2.…
- CVE-2020-10024HIGHCVSS 7.8EG 7.82020-05-11
The arm platform-specific code uses a signed integer comparison when validating system call numbers. An attacker who has obtained code execution within a user thread is able to elevate privileges to that of the kernel. See NCC-ZEP-001 This…
- CVE-2020-10027HIGHCVSS 7.8EG 7.82020-05-11
An attacker who has obtained code execution within a user thread is able to elevate privileges to that of the kernel. See NCC-ZEP-001 This issue affects: zephyrproject-rtos zephyr version 1.14.0 and later versions. version 2.1.0 and later …
- CVE-2020-11071HIGHCVSS 8.6EG 8.62020-05-12
SLPJS (npm package slpjs) before version 0.27.2, has a vulnerability where users could experience false-negative validation outcomes for MINT transaction operations. A poorly implemented SLP wallet could allow spending of the affected toke…
- CVE-2020-11072HIGHCVSS 8.6EG 8.62020-05-12
In SLP Validate (npm package slp-validate) before version 1.2.1, users could experience false-negative validation outcomes for MINT transaction operations. A poorly implemented SLP wallet could allow spending of the affected tokens which w…
- CVE-2020-13485CRITICALCVSS 9.1EG 9.12020-05-25
The Knock Knock plugin before 1.2.8 for Craft CMS allows IP Whitelist bypass via an X-Forwarded-For HTTP header.
- CVE-2020-13559HIGHCVSS 7.5EG 7.52021-01-11
A denial-of-service vulnerability exists in the traffic-logging functionality of FreyrSCADA IEC-60879-5-104 Server Simulator 21.04.028. A specially crafted packet can lead to denial of service. An attacker can send a malicious packet to tr…
- CVE-2020-15130HIGHCVSS 7.5EG 7.52020-07-30
In SLPJS (npm package slpjs) before version 0.27.4, there is a vulnerability to false-positive validation outcomes for the NFT1 Child Genesis transaction type. A poorly implemented SLP wallet or opportunistic attacker could create a seemin…
- CVE-2020-15131HIGHCVSS 7.5EG 7.52020-07-30
In SLP Validate (npm package slp-validate) before version 1.2.2, there is a vulnerability to false-positive validation outcomes for the NFT1 Child Genesis transaction type. A poorly implemented SLP wallet or opportunistic attacker could cr…
- CVE-2020-15811MEDIUMCVSS 6.5EG 6.52020-09-02
An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Splitting attacks may succeed against HTTP and HTTPS traffic. This leads to cache poisoning. This allows any client, includin…
- CVE-2020-1741MEDIUMCVSS 5.9EG 5.92020-04-24
A flaw was found in openshift-ansible. OpenShift Container Platform (OCP) 3.11 is too permissive in the way it specified CORS allowed origins during installation. An attacker, able to man-in-the-middle the connection between the user's bro…
- CVE-2020-1920HIGHCVSS 7.5EG 7.52021-06-01
A regular expression denial of service (ReDoS) vulnerability in the validateBaseUrl function can cause the application to use excessive resources, become unresponsive, or crash. This was introduced in react-native version 0.59.0 and fixed …
- CVE-2020-22784HIGHCVSS 7.5EG 7.52021-04-28
In Etherpad UeberDB < 0.4.4, due to MySQL omitting trailing spaces on char / varchar columns during comparisons, retrieving database records using UeberDB's MySQL connector could allow bypassing access controls enforced on key names.
- CVE-2020-23355HIGHCVSS 7.5EG 7.52021-01-27
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Codiad 2.8.4 /componetns/user/class.user.php:Authenticate() is vulnerable in magic hash authentication bypass. If encrypted or hash value for the passwords form certain formats of magic hash, e.g, …
- CVE-2020-23359CRITICALCVSS 9.8EG 9.82021-01-27
WeBid 1.2.2 admin/newuser.php has an issue with password rechecking during registration because it uses a loose comparison to check the identicalness of two passwords. Two non-identical passwords can still bypass the check.
- CVE-2020-23360CRITICALCVSS 9.8EG 9.82021-01-27
oscommerce v2.3.4.1 has a functional problem in user registration and password rechecking, where a non-identical password can bypass the checks in /catalog/admin/administrators.php and /catalog/password_reset.php
- CVE-2020-23361CRITICALCVSS 9.8EG 9.82021-01-27
phpList 3.5.3 allows type juggling for login bypass because == is used instead of === for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical characters.
- CVE-2020-23478HIGHCVSS 7.5EG 7.52021-09-22
Leo Editor v6.2.1 was discovered to contain a regular expression denial of service (ReDoS) vulnerability in the component plugins/importers/dart.py.
- CVE-2020-25580MEDIUMCVSS 5.3EG 5.32021-03-26
In FreeBSD 12.2-STABLE before r369346, 11.4-STABLE before r369345, 12.2-RELEASE before p4 and 11.4-RELEASE before p8 a regression in the login.access(5) rule processor has the effect of causing rules to fail to match even when they should …
- CVE-2020-25696HIGHCVSS 7.5EG 7.52020-11-23
A flaw was found in the psql interactive terminal of PostgreSQL in versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. If an interactive psql session uses \gset when querying a compromised server…
- CVE-2020-28200MEDIUMCVSS 4.3EG 4.32021-06-28
The Sieve engine in Dovecot before 2.3.15 allows Uncontrolled Resource Consumption, as demonstrated by a situation with a complex regular expression for the regex extension.
- CVE-2020-5849HIGHCVSS 7.5EG 9.0⚠ KEV2020-03-16
Unraid 6.8.0 allows authentication bypass.
- CVE-2020-8862HIGHCVSS 8.8EG 8.82020-02-22
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-2610 Firmware v2.01RC067 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists …
- CVE-2020-8864HIGHCVSS 8.8EG 8.82020-03-23
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 routers with firmware 1.10B04. Authentication is not required to exploit this vulnerability. Th…
- CVE-2021-0295MEDIUMCVSS 6.1EG 6.12021-07-15
A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) of Juniper Networks Junos OS on the QFX10K Series switches allows an attacker to trigger a packet forwarding loop, leading to a partial Denial of Service (DoS). The …
- CVE-2021-1904MEDIUMCVSS 6.2EG 5.52021-09-08
Child process can leak information from parent process due to numeric pids are getting compared and these pid can be reused in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT…
- CVE-2021-20219MEDIUMCVSS 5.5EG 5.52021-03-23
A denial of service vulnerability was found in n_tty_receive_char_special in drivers/tty/n_tty.c of the Linux kernel. In this flaw a local attacker with a normal user privilege could delay the loop (due to a changing ldata->read_head, and …
- CVE-2021-23146HIGHCVSS 7.1EG 7.52021-11-18
An Incomplete Comparison with Missing Factors vulnerability in the Gallagher Controller allows an attacker to bypass PIV verification. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.40.1888 (MR3); 8.30 versions prior…
- CVE-2021-23999HIGHCVSS 8.8EG 8.82021-06-24
If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and granted additional privileges that should not be granted to web content. This vulnerability affects Firefox ESR < 78.10, …
- CVE-2021-27293HIGHCVSS 7.5EG 7.52021-07-12
RestSharp < 106.11.8-alpha.0.13 uses a regular expression which is vulnerable to Regular Expression Denial of Service (ReDoS) when converting strings into DateTimes. If a server responds with a malicious string, the client using RestSharp …
- CVE-2021-27786MEDIUMCVSS 4.6EG 9.82022-06-09
Cross-origin resource sharing (CORS) enables browsers to perform cross domain requests in a controlled manner. This request has an Origin header that identifies the domain that is making the initial request and defines the protocol between…
- CVE-2021-3116HIGHCVSS 7.5EG 7.52021-01-11
before_upstream_connection in AuthPlugin in http/proxy/auth.py in proxy.py before 2.3.1 accepts incorrect Proxy-Authorization header data because of a boolean confusion (and versus or).
- CVE-2021-32779HIGHCVSS 8.6EG 8.62021-08-24
Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions envoy incorrectly handled a URI '#fragment' element as part of the path element. Envoy is configured with…
- CVE-2021-34141MEDIUMCVSS 5.3EG 5.32021-12-17
An incomplete string comparison in the numpy.core component in NumPy before 1.22.0 allows attackers to trigger slightly incorrect copying by constructing specific string objects. NOTE: the vendor states that this reported code behavior is …
- CVE-2021-34865HIGHCVSS 8.8EG 8.82022-01-25
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of multiple NETGEAR routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the mini_htt…
- CVE-2021-35970HIGHCVSS 7.5EG 7.52021-06-30
Talk 4 in Coral before 4.12.1 allows remote attackers to discover e-mail addresses and other sensitive information via GraphQL because permission checks use an incorrect data type.
- CVE-2021-35973CRITICALCVSS 9.8EG 9.82021-06-30
NETGEAR WAC104 devices before 1.0.4.15 are affected by an authentication bypass vulnerability in /usr/sbin/mini_httpd, allowing an unauthenticated attacker to invoke any action by adding the ¤tsetting.htm substring to the HTTP query,…
- CVE-2021-3649HIGHCVSS 7.5EG 7.52021-07-16
chatwoot is vulnerable to Inefficient Regular Expression Complexity
- CVE-2021-37550HIGHCVSS 7.5EG 7.52021-08-06
In JetBrains YouTrack before 2021.2.16363, time-unsafe comparisons were used.
- CVE-2021-3828HIGHCVSS 7.5EG 7.52021-09-27
nltk is vulnerable to Inefficient Regular Expression Complexity
- CVE-2021-3833CRITICALCVSS 9.8EG 9.82021-10-07
Integria IMS login check uses a loose comparator ("==") to compare the MD5 hash of the password provided by the user and the MD5 hash stored in the database. An attacker with a specific formatted password could exploit this vulnerability i…
- CVE-2021-38364MEDIUMCVSS 6.5EG 6.52023-04-20
An issue was discovered in ONOS 2.5.1. There is an incorrect comparison of flow rules installed by intents. A remote attacker can install or remove a new intent, and consequently modify or delete the existing flow rules related to other in…
- CVE-2021-39514MEDIUMCVSS 6.5EG 6.52021-09-20
An issue was discovered in libjpeg through 2020021. An uncaught floating point exception in the function ACLosslessScan::ParseMCU() located in aclosslessscan.cpp. It allows an attacker to cause Denial of Service.
Map vulnerabilities like CWE-697 to your infrastructure
EchelonGraph correlates every CVE — across CWE-697 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →