CWE-754— Improper Check for Unusual or Exceptional Conditions
The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.— MITRE CWE catalog
616 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-754page 5 of 13
- CVE-2022-22217MEDIUMCVSS 6.1EG 6.52022-07-20
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an adjacent unauthenticated attacker to cause a Denial of Service (DoS). The issue is caused by…
- CVE-2022-22218HIGHCVSS 7.5EG 7.52022-10-18
On SRX Series devices, an Improper Check for Unusual or Exceptional Conditions when using Certificate Management Protocol Version 2 (CMPv2) auto re-enrollment, allows a network-based, unauthenticated attacker to cause a Denial of Service (…
- CVE-2022-22227MEDIUMCVSS 5.3EG 5.32022-10-18
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on ACX7000 Series allows an unauthenticated network-based attacker to cause a partial Denial o…
- CVE-2022-22235MEDIUMCVSS 5.9EG 5.92022-10-18
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based, attacker to cause Denial of Service (DoS). A P…
- CVE-2022-22238MEDIUMCVSS 5.3EG 5.32022-10-18
An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). W…
- CVE-2022-23572MEDIUMCVSS 6.5EG 6.52022-02-04
Tensorflow is an Open Source Machine Learning Framework. Under certain scenarios, TensorFlow can fail to specialize a type during shape inference. This case is covered by the `DCHECK` function however, `DCHECK` is a no-op in production bui…
- CVE-2022-23590MEDIUMCVSS 5.9EG 5.92022-02-04
Tensorflow is an Open Source Machine Learning Framework. A `GraphDef` from a TensorFlow `SavedModel` can be maliciously altered to cause a TensorFlow process to crash due to encountering a `StatusOr` value that is an error and forcibly ext…
- CVE-2022-23593MEDIUMCVSS 5.9EG 5.92022-02-04
Tensorflow is an Open Source Machine Learning Framework. The `simplifyBroadcast` function in the MLIR-TFRT infrastructure in TensorFlow is vulnerable to a segfault (hence, denial of service), if called with scalar shapes. If all shapes are…
- CVE-2022-23712HIGHCVSS 7.5EG 7.52022-06-06
A Denial of Service flaw was discovered in Elasticsearch. Using this vulnerability, an unauthenticated attacker could forcibly shut down an Elasticsearch node with a specifically formatted network request.
- CVE-2022-24321HIGHCVSS 7.5EG 7.52022-02-09
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause Denial of Service against the Geo SCADA server when receiving a malformed HTTP request. Affected Product: ClearSCADA (All Versions), EcoS…
- CVE-2022-24323MEDIUMCVSS 5.3EG 5.92022-03-09
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause a disruption of communication between the Modicon controller and the engineering software, when an attacker is able to intercept and mani…
- CVE-2022-24880MEDIUMCVSS 5.3EG 5.32022-04-25
flask-session-captcha is a package which allows users to extend Flask by adding an image based captcha stored in a server side session. In versions prior to 1.2.1, he `captcha.validate()` function would return `None` if passed no value (e.…
- CVE-2022-25024HIGHCVSS 7.5EG 7.52023-08-22
The json2xml package through 3.12.0 for Python allows an error in typecode decoding enabling a remote attack that can lead to an exception, causing a denial of service.
- CVE-2022-25252HIGHCVSS 7.5EG 7.52022-03-16
When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) when receiving certain input throws an exception. Services using said function do not handle the exception. Successful exploit…
- CVE-2022-26078HIGHCVSS 7.5EG 7.52022-07-06
Gallagher Controller 6000 is vulnerable to a Denial of Service attack via conflicting ARP packets with a duplicate IP address. This issue affects: Gallagher Gallagher Controller 6000 vCR8.60 versions prior to 220303a; vCR8.50 versions prio…
- CVE-2022-26079HIGHCVSS 6.0EG 8.22022-11-11
Improper conditions check in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2022-26130MEDIUMCVSS 5.3EG 5.32022-05-05
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, when an Active mode-enabled FTP profile is configured on a virtual server, undisclos…
- CVE-2022-27563HIGHCVSS 7.5EG 7.52022-08-30
An unauthenticated user can overload a part of HCL VersionVault Express and cause a denial of service.
- CVE-2022-28706HIGHCVSS 5.9EG 7.52022-05-05
On F5 BIG-IP 16.1.x versions prior to 16.1.2 and 15.1.x versions prior to 15.1.5.1, when the DNS resolver configuration is used, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions …
- CVE-2022-28793MEDIUMCVSS 4.4EG 4.42022-05-03
Given the TEE is compromised and controlled by the attacker, improper state maintenance in StrongBox allows attackers to change Android ROT during device boot cycle after compromising TEE. The patch is applied in Galaxy S22 to prevent chan…
- CVE-2022-29278HIGHCVSS 8.2EG 8.22022-11-15
Incorrect pointer checks within the NvmExpressDxe driver can allow tampering with SMRAM and OS memory Incorrect pointer checks within the NvmExpressDxe driver can allow tampering with SMRAM and OS memory. This issue was discovered by Insyd…
- CVE-2022-29369HIGHCVSS 7.5EG 7.52022-05-12
Nginx NJS v0.7.2 was discovered to contain a segmentation violation via njs_lvlhsh_bucket_find at njs_lvlhsh.c.
- CVE-2022-29473HIGHCVSS 5.9EG 7.52022-05-05
On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, when an IPSec ALG profile is configured on a virtual server, undisclosed responses can cause Traffic Management Microke…
- CVE-2022-29523MEDIUMCVSS 3.3EG 5.52023-02-16
Improper conditions check in the Open CAS software maintained by Intel(R) before version 22.3.1 may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2022-30692HIGHCVSS 5.9EG 7.52023-02-16
Improper conditions check in the Intel(R) SUR software before version 2.4.8902 may allow an unauthenticated user to potentially enable denial of service via network access.
- CVE-2022-30738MEDIUMCVSS 4.3EG 4.32022-06-07
Improper check in Loader in Samsung Internet prior to 17.0.1.69 allows attackers to spoof address bar via executing script.
- CVE-2022-31093HIGHCVSS 7.5EG 7.52022-06-27
NextAuth.js is a complete open source authentication solution for Next.js applications. In affected versions an attacker can send a request to an app using NextAuth.js with an invalid `callbackUrl` query parameter, which internally is conv…
- CVE-2022-31103HIGHCVSS 7.5EG 7.52022-06-27
lettersanitizer is a DOM-based HTML email sanitizer for in-browser email rendering. All versions of lettersanitizer below 1.0.2 are affected by a denial of service issue when processing a CSS at-rule `@keyframes`. This package is depended …
- CVE-2022-3192MEDIUMCVSS 5.3EG 5.32023-03-31
Improper Input Validation vulnerability in ABB AC500 V2 PM5xx allows Client-Server Protocol Manipulation.This issue affects AC500 V2: from 2.0.0 before 2.8.6.
- CVE-2022-32590MEDIUMCVSS 6.7EG 6.72022-10-07
In wlan, there is a possible use after free due to an incorrect status check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07299425…
- CVE-2022-32749HIGHCVSS 7.5EG 7.52022-12-19
Improper Check for Unusual or Exceptional Conditions vulnerability handling requests in Apache Traffic Server allows an attacker to crash the server under certain conditions. This issue affects Apache Traffic Server: from 8.0.0 through 9…
- CVE-2022-35173HIGHCVSS 7.5EG 7.52022-08-18
An issue was discovered in Nginx NJS v0.7.5. The JUMP offset for a break instruction was not set to a correct offset during code generation, leading to a segmentation violation.
- CVE-2022-35469MEDIUMCVSS 6.5EG 6.52022-08-16
OTFCC v0.10.4 was discovered to contain a segmentation violation via /x86_64-linux-gnu/libc.so.6+0xbb384.
- CVE-2022-35473MEDIUMCVSS 6.5EG 6.52022-08-16
OTFCC v0.10.4 was discovered to contain a segmentation violation via /release-x64/otfccdump+0x4fe9a7.
- CVE-2022-36046MEDIUMCVSS 5.3EG 5.32022-08-31
Next.js is a React framework that can provide building blocks to create web applications. All of the following must be true to be affected by this CVE: Next.js version 12.2.3, Node.js version above v15.0.0 being used with strict `unhandled…
- CVE-2022-36140MEDIUMCVSS 5.5EG 5.52022-08-16
SWFMill commit 53d7690 was discovered to contain a segmentation violation via SWF::DeclareFunction2::write(SWF::Writer*, SWF::Context*).
- CVE-2022-36141MEDIUMCVSS 5.5EG 5.52022-08-16
SWFMill commit 53d7690 was discovered to contain a segmentation violation via SWF::MethodBody::write(SWF::Writer*, SWF::Context*).
- CVE-2022-36145MEDIUMCVSS 5.5EG 5.52022-08-16
SWFMill commit 53d7690 was discovered to contain a segmentation violation via SWF::Reader::getWord().
- CVE-2022-3616MEDIUMCVSS 5.4EG 5.42022-10-28
Attackers can create long chains of CAs that would lead to OctoRPKI exceeding its max iterations parameter. In consequence it would cause the program to crash, preventing it from finishing the validation and leading to a denial of service.…
- CVE-2022-36794MEDIUMCVSS 6.0EG 6.02023-02-16
Improper condition check in some Intel(R) SPS firmware before version SPS_E3_06.00.03.300.0 may allow a privileged user to potentially enable denial of service via local access.
- CVE-2022-37392MEDIUMCVSS 5.3EG 5.32022-12-19
Improper Check for Unusual or Exceptional Conditions vulnerability in handling the requests to Apache Traffic Server. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.
- CVE-2022-38152HIGHCVSS 7.5EG 7.52022-08-31
An issue was discovered in wolfSSL before 5.5.0. When a TLS 1.3 client connects to a wolfSSL server and SSL_clear is called on its session, the server crashes with a segmentation fault. This occurs in the second session, which is created t…
- CVE-2022-38233MEDIUMCVSS 5.5EG 5.52022-08-16
XPDF commit ffaf11c was discovered to contain a segmentation violation via DCTStream::readMCURow() at /xpdf/Stream.cc.
- CVE-2022-38234MEDIUMCVSS 5.5EG 5.52022-08-16
XPDF commit ffaf11c was discovered to contain a segmentation violation via Lexer::getObj(Object*) at /xpdf/Lexer.cc.
- CVE-2022-38235MEDIUMCVSS 5.5EG 5.52022-08-16
XPDF commit ffaf11c was discovered to contain a segmentation violation via DCTStream::getChar() at /xpdf/Stream.cc.
- CVE-2022-39288HIGHCVSS 7.5EG 8.32022-10-10
fastify is a fast and low overhead web framework, for Node.js. Affected versions of fastify are subject to a denial of service via malicious use of the Content-Type header. An attacker can send an invalid Content-Type header that can cause…
- CVE-2022-41587MEDIUMCVSS 5.3EG 5.32022-10-14
Uncaptured exceptions in the home screen module. Successful exploitation of this vulnerability may affect stability.
- CVE-2022-43393HIGHCVSS 8.2EG 8.22023-01-11
An improper check for unusual or exceptional conditions in the HTTP request processing function of Zyxel GS1920-24v2 firmware prior to V4.70(ABMH.8)C0, which could allow an unauthenticated attacker to corrupt the contents of the memory and…
- CVE-2022-45788CRITICALCVSS 7.5EG 9.82023-01-30
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when a malicious project file is loaded onto the cont…
- CVE-2022-45854MEDIUMCVSS 4.3EG 4.32023-02-07
An improper check for unusual conditions in Zyxel NWA110AX firmware verisons prior to 6.50(ABTG.0)C0, which could allow a LAN attacker to cause a temporary denial-of-service (DoS) by sending crafted VLAN frames if the MAC address of the vu…
Map vulnerabilities like CWE-754 to your infrastructure
EchelonGraph correlates every CVE — across CWE-754 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →