CWE-755— Improper Handling of Exceptional Conditions
The product does not handle or incorrectly handles an exceptional condition.— MITRE CWE catalog
610 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-755page 10 of 13
- CVE-2023-34348HIGHCVSS 7.5EG 7.52024-01-18
AVEVA PI Server versions 2023 and 2018 SP3 P05 and prior contain a vulnerability that could allow an unauthenticated user to remotely crash the PI Message Subsystem of a PI Server, resulting in a denial-of-service condition.
- CVE-2023-36832HIGHCVSS 7.5EG 7.52023-07-14
An Improper Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS on MX Series allows an unauthenticated network-based attacker to send specific packets to an Aggregated Multiservices (AMS) inte…
- CVE-2023-36842MEDIUMCVSS 6.5EG 6.52024-01-12
An Improper Check for Unusual or Exceptional Conditions vulnerability in Juniper DHCP Daemon (jdhcpd) of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker to cause the jdhcpd to consume all the CPU cycles resulting in…
- CVE-2023-36933HIGHCVSS 7.5EG 8.72023-07-05
In Progress MOVEit Transfer before 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), it is possible for an attacker to invoke a method that results in an unhandled exception. Triggering this…
- CVE-2023-37605HIGHCVSS 5.5EG 7.82023-10-02
Weak Exception Handling vulnerability in baramundi software GmbH EMM Agent 23.1.50 and before allows an attacker to cause a denial of service via a crafted request to the password parameter.
- CVE-2023-3774MEDIUMCVSS 4.9EG 4.92023-07-28
An unhandled error in Vault Enterprise's namespace creation may cause the Vault process to crash, potentially resulting in denial of service. Fixed in 1.14.1, 1.13.5, and 1.12.9.
- CVE-2023-38406CRITICALCVSS 9.8EG 9.82023-11-06
bgpd/bgp_flowspec.c in FRRouting (FRR) before 8.4.3 mishandles an nlri length of zero, aka a "flowspec overflow."
- CVE-2023-38419MEDIUMCVSS 4.3EG 4.32023-08-02
An authenticated attacker with guest privileges or higher can cause the iControl SOAP process to terminate by sending undisclosed requests. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- CVE-2023-39341LOWCVSS 3.3EG 3.32023-08-09
"FFRI yarai", "FFRI yarai Home and Business Edition" and their OEM products handle exceptional conditions improperly, which may lead to denial-of-service (DoS) condition. Affected products and versions are as follows: FFRI yarai versions…
- CVE-2023-39801MEDIUMCVSS 4.6EG 4.62023-08-24
A lack of exception handling in the Renault Easy Link Multimedia System Software Version 283C35519R allows attackers to cause a Denial of Service (DoS) via supplying crafted WMA files when connecting a device to the vehicle's USB plug and …
- CVE-2023-40184LOWCVSS 2.6EG 2.62023-08-30
xrdp is an open source remote desktop protocol (RDP) server. In versions prior to 0.9.23 improper handling of session establishment errors allows bypassing OS-level session restrictions. The `auth_start_session` function can return non-zer…
- CVE-2023-41085HIGHCVSS 7.5EG 7.52023-10-10
When IPSec is configured on a Virtual Server, undisclosed traffic can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- CVE-2023-41151HIGHCVSS 7.5EG 7.52023-12-14
An uncaught exception issue discovered in Softing OPC UA C++ SDK before 6.30 for Windows operating system may cause the application to crash when the server wants to send an error packet, while socket is blocked on writing.
- CVE-2023-41317MEDIUMCVSS 5.9EG 5.92023-09-05
The Apollo Router is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Affected versions are subject to a Denial-of-Service (DoS) type vulnerability which causes the …
- CVE-2023-41332LOWCVSS 3.5EG 3.52023-09-27
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In Cilium clusters where Cilium's Layer 7 proxy has been disabled, creating workloads with `policy.cilium.io/proxy-visibility` annotations (in Ciliu…
- CVE-2023-41378HIGHCVSS 7.5EG 7.52023-11-06
In certain conditions for Calico Typha (v3.26.2, v3.25.1 and below), and Calico Enterprise Typha (v3.17.1, v3.16.3, v3.15.3 and below), a client TLS handshake can block the Calico Typha server indefinitely, resulting in denial of service. …
- CVE-2023-42509MEDIUMCVSS 6.6EG 6.62024-03-07
JFrog Artifactory later than version 7.17.4 but prior to version 7.77.0 is vulnerable to an issue whereby a sequence of improperly handled exceptions in repository configuration initialization steps may lead to exposure of sensitive data.
- CVE-2023-42559MEDIUMCVSS 5.2EG 5.22023-12-05
Improper exception management vulnerability in Knox Guard prior to SMR Dec-2023 Release 1 allows Knox Guard lock bypass via changing system time.
- CVE-2023-42578HIGHCVSS 7.5EG 7.52023-12-05
Improper handling of insufficient permissions or privileges vulnerability in Samsung Data Store prior to version 5.2.00.7 allows remote attackers to access location information without permission.
- CVE-2023-43087MEDIUMCVSS 6.5EG 6.52023-11-02
Dell PowerScale OneFS 8.2.x, 9.0.0.x-9.5.0.x contains an improper handling of insufficient permissions. A low privileged remote attacker could potentially exploit this vulnerability to cause information disclosure.
- CVE-2023-43251HIGHCVSS 7.8EG 7.82023-10-19
XNSoft Nconvert 7.136 has an Exception Handler Chain Corrupted via a crafted image file. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to achieve code execution.
- CVE-2023-43686MEDIUMCVSS 6.2EG 6.22026-06-09
An issue was discovered in Malwarebytes 4.x and 5.x (and Nebula 2020-10-21 and later). A large number of Firefox preference files can cause the parser to ignore other browser configuration files, leading to a denial of service.
- CVE-2023-44186HIGHCVSS 7.5EG 7.52023-10-11
An Improper Handling of Exceptional Conditions vulnerability in AS PATH processing of Juniper Networks Junos OS and Junos OS Evolved allows an attacker to send a BGP update message with an AS PATH containing a large number of 4-byte ASes,…
- CVE-2023-44488HIGHCVSS 7.5EG 7.52023-09-30
VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding.
- CVE-2023-4537HIGHCVSS 7.4EG 7.42024-02-15
Comarch ERP XL client is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and modification. This issue affects ERP XL: from 2020.2.2 throug…
- CVE-2023-4540HIGHCVSS 7.5EG 7.52023-09-05
Improper Handling of Exceptional Conditions vulnerability in Daurnimator lua-http library allows Excessive Allocation and a denial of service (DoS) attack to be executed by sending a properly crafted request to the server. Such a request …
- CVE-2023-45820MEDIUMCVSS 6.5EG 6.52023-10-19
Directus is a real-time API and App dashboard for managing SQL database content. In affected versions any Directus installation that has websockets enabled can be crashed if the websocket server receives an invalid frame. A malicious user …
- CVE-2023-46297MEDIUMCVSS 5.1EG 5.12024-05-29
An issue was discovered on Mercusys MW325R EU V3 MW325R(EU)_V3_1.11.0 221019 devices. A WAN attacker can make the admin interface unreachable/invisible via an unauthenticated HTTP request. Verification of the data sent by the user does not…
- CVE-2023-46673HIGHCVSS 7.5EG 7.52023-11-22
It was identified that malformed scripts used in the script processor of an Ingest Pipeline could cause an Elasticsearch node to crash when calling the Simulate Pipeline API.
- CVE-2023-48232MEDIUMCVSS 4.3EG 4.32023-11-16
Vim is an open source command line text editor. A floating point exception may occur when calculating the line offset for overlong lines and smooth scrolling is enabled and the cpo-settings include the 'n' flag. This may happen when a wind…
- CVE-2023-50019MEDIUMCVSS 5.9EG 5.92024-01-02
An issue was discovered in open5gs v2.6.6. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handling of Nudm_UECM_Registration response.
- CVE-2023-50212MEDIUMCVSS 6.5EG 6.52024-05-03
D-Link G416 httpd Improper Handling of Exceptional Conditions Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Link G416 routers. Au…
- CVE-2023-50728HIGHCVSS 7.5EG 7.52023-12-15
octokit/webhooks is a GitHub webhook events toolset for Node.js. Starting in 9.26.0 and prior to 9.26.3, 10.9.2, 11.1.2, and 12.0.4, there is a problem caused by an issue with error handling in the @octokit/webhooks library because the err…
- CVE-2023-5090MEDIUMCVSS 5.5EG 6.02023-11-06
A flaw was found in KVM. An improper check in svm_set_x2apic_msr_interception() may allow direct access to host x2apic msrs when the guest resets its apic, potentially leading to a denial of service condition.
- CVE-2023-52075HIGHCVSS 7.5EG 7.52023-12-27
ReVanced API proxies requests needed to feed the ReVanced Manager and website with data. Up to and including commit 71f81f7f20cd26fd707335bca9838fa3e7df20d2, ReVanced API lacks error caching causing rate limit to be triggered thus increasi…
- CVE-2023-5824HIGHCVSS 7.5EG 7.52023-11-03
A flaw was found in Squid. The limits applied for validation of HTTP response headers are applied before caching. However, Squid may grow a cached HTTP response header beyond the configured maximum size, causing a stall or crash of the wor…
- CVE-2023-6267HIGHCVSS 8.6EG 8.62024-01-25
A flaw was found in the json payload. If annotation based security is used to secure a REST resource, the JSON body that the resource may consume is being processed (deserialized) prior to the security constraints being evaluated and appli…
- CVE-2023-6599MEDIUMCVSS 4.3EG 4.32023-12-08
Missing Standardized Error Handling Mechanism in GitHub repository microweber/microweber prior to 2.0.
- CVE-2023-6866HIGHCVSS 8.8EG 8.82023-12-19
TypedArrays can be fallible and lacked proper exception handling. This could lead to abuse in other APIs which expect TypedArrays to always succeed. This vulnerability affects Firefox < 121.
- CVE-2024-0108HIGHCVSS 8.7EG 8.72024-08-08
NVIDIA Jetson Linux contains a vulnerability in NvGPU where error handling paths in GPU MMU mapping code fail to clean up a failed mapping attempt. A successful exploit of this vulnerability may lead to denial of service, code execution, a…
- CVE-2024-11863MEDIUMCVSS 5.3EG 5.32025-01-14
Specifically crafted SCMI messages sent to an SCP running SCP-Firmware release versions up to and including 2.15.0 may lead to a Usage Fault and crash the SCP
- CVE-2024-11864HIGHCVSS 7.5EG 7.52025-01-14
Specifically crafted SCMI messages sent to an SCP running SCP-Firmware release versions up to and including 2.15.0 may lead to a Usage Fault and crash the SCP
- CVE-2024-12236MEDIUMCVSS 5.5EG 5.52024-12-10
A security issue exists in Vertex Gemini API for customers using VPC-SC. By utilizing a custom crafted file URI for image input, data exfiltration is possible due to requests being routed outside the VPC-SC security perimeter, circumventin…
- CVE-2024-20699MEDIUMCVSS 5.5EG 5.52024-01-09
Windows Hyper-V Denial of Service Vulnerability
- CVE-2024-20894MEDIUMCVSS 4.3EG 4.32024-07-02
Improper handling of exceptional conditions in Secure Folder prior to SMR Jul-2024 Release 1 allows physical attackers to bypass authentication under certain condition. User interaction is required for triggering this vulnerability.
- CVE-2024-21585MEDIUMCVSS 5.9EG 5.92024-01-12
An Improper Handling of Exceptional Conditions vulnerability in BGP session processing of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker, using specific timing outside the attacker's contro…
- CVE-2024-21587MEDIUMCVSS 6.5EG 6.52024-01-12
An Improper Handling of Exceptional Conditions vulnerability in the broadband edge subscriber management daemon (bbe-smgd) of Juniper Networks Junos OS on MX Series allows an attacker directly connected to the vulnerable system who repeat…
- CVE-2024-21610MEDIUMCVSS 4.3EG 5.32024-04-12
An Improper Handling of Exceptional Conditions vulnerability in the Class of Service daemon (cosd) of Juniper Networks Junos OS allows an authenticated, network-based attacker with low privileges to cause a limited Denial of Service (DoS).…
- CVE-2024-21907HIGHCVSS 7.5EG 7.62024-01-03
Newtonsoft.Json before version 13.0.1 is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the JsonConvert.DeserializeObject method may trigger a StackOverflow exception resulting in denial o…
- CVE-2024-23325HIGHCVSS 7.5EG 7.52024-02-09
Envoy is a high-performance edge/middle/service proxy. Envoy crashes in Proxy protocol when using an address type that isn’t supported by the OS. Envoy is susceptible to crashing on a host with IPv6 disabled and a listener config with pr…
Map vulnerabilities like CWE-755 to your infrastructure
EchelonGraph correlates every CVE — across CWE-755 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →