CWE-755— Improper Handling of Exceptional Conditions
The product does not handle or incorrectly handles an exceptional condition.— MITRE CWE catalog
610 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-755page 8 of 13
- CVE-2022-23161HIGHCVSS 7.5EG 7.52022-04-12
Dell PowerScale OneFS versions 8.2.x - 9.3.0.x contain a denial-of-service vulnerability in SmartConnect. An unprivileged network attacker may potentially exploit this vulnerability, leading to denial-of-service.
- CVE-2022-23495HIGHCVSS 7.5EG 7.52022-12-08
go-merkledag implements the 'DAGService' interface and adds two ipld node types, Protobuf and Raw for the ipfs project. A `ProtoNode` may be modified in such a way as to cause various encode errors which will trigger a panic on common meth…
- CVE-2022-23496HIGHCVSS 7.5EG 7.52022-12-08
Yet Another UserAgent Analyzer (Yauaa) is a java library that tries to parse and analyze the useragent string and extract as many relevant attributes as possible. Applications using the Client Hints analysis feature introduced with 7.0.0 …
- CVE-2022-23625MEDIUMCVSS 6.5EG 6.52022-03-11
Wire-ios is a messaging application using the wire protocol on apple's ios platform. In versions prior to 3.95 malformed resource identifiers may render the iOS Wire Client completely unusable by causing it to repeatedly crash on launch. T…
- CVE-2022-24448LOWCVSS 3.3EG 3.32022-02-04
An issue was discovered in fs/nfs/dir.c in the Linux kernel before 5.16.5. If an application sets the O_DIRECTORY flag, and tries to open a regular file, nfs_atomic_open() performs a regular lookup. If a regular file is found, ENOTDIR shou…
- CVE-2022-24613MEDIUMCVSS 5.5EG 5.52022-02-24
metadata-extractor up to 2.16.0 can throw various uncaught exceptions while parsing a specially crafted JPEG file, which could result in an application crash. This could be used to mount a denial of service attack against services that use…
- CVE-2022-24615MEDIUMCVSS 5.5EG 5.52022-02-24
zip4j up to v2.10.0 can throw various uncaught exceptions while parsing a specially crafted ZIP file, which could result in an application crash. This could be used to mount a denial of service attack against services that use zip4j librar…
- CVE-2022-24863HIGHCVSS 7.5EG 7.52022-04-18
http-swagger is an open source wrapper to automatically generate RESTful API documentation with Swagger 2.0. In versions of http-swagger prior to 1.2.6 an attacker may perform a denial of service attack consisting of memory exhaustion on t…
- CVE-2022-25795HIGHCVSS 7.8EG 7.82022-04-13
A Memory Corruption Vulnerability in Autodesk TrueView 2022 and 2021 may lead to remote code execution through maliciously crafted DWG files.
- CVE-2022-25917MEDIUMCVSS 6.0EG 6.02022-11-11
Uncaught exception in the firmware for some Intel(R) Server Board M50CYP Family before version R01.01.0005 may allow a privileged user to potentially enable a denial of service via local access.
- CVE-2022-26509MEDIUMCVSS 2.5EG 5.52023-02-16
Improper conditions check in the Intel(R) SGX SDK software may allow a privileged user to potentially enable information disclosure via local access.
- CVE-2022-27167HIGHCVSS 7.1EG 7.12022-05-10
Privilege escalation vulnerability in Windows products of ESET, spol. s r.o. allows attacker to exploit "Repair" and "Uninstall" features what may lead to arbitrary file deletion. This issue affects: ESET, spol. s r.o. ESET NOD32 Antivirus…
- CVE-2022-27841MEDIUMCVSS 4.3EG 4.32022-04-11
Improper exception handling in Samsung Pass prior to version 3.7.07.5 allows physical attacker to view the screen that is previously running without authentication
- CVE-2022-27872HIGHCVSS 7.8EG 7.82022-06-21
A maliciously crafted PDF file may be used to dereference a pointer for read or write operation while parsing PDF files in Autodesk Navisworks 2022. The vulnerability exists because the application fails to handle a crafted PDF file, which…
- CVE-2022-27978HIGHCVSS 7.5EG 7.52023-04-26
Tooljet v1.6 does not properly handle missing values in the API, allowing attackers to arbitrarily reset passwords via a crafted HTTP request.
- CVE-2022-29017MEDIUMCVSS 5.5EG 5.52022-05-16
Bento4 v1.6.0.0 was discovered to contain a segmentation fault via the component /x86_64/multiarch/strlen-avx2.S.
- CVE-2022-29493MEDIUMCVSS 4.5EG 4.92023-02-16
Uncaught exception in webserver for the Integrated BMC in some Intel(R) platforms before versions 2.86, 2.09 and 2.78 may allow a privileged user to potentially enable denial of service via network access.
- CVE-2022-29617MEDIUMCVSS 6.5EG 6.52022-06-06
Due to improper error handling an authenticated user can crash CLA assistant instance. This could impact the availability of the application.
- CVE-2022-30716MEDIUMCVSS 4.0EG 5.32022-06-07
Unprotected broadcast in sendIntentForToastDumpLog in DisplayToast prior to SMR Jun-2022 Release 1 allows untrusted applications to access toast message information from device.
- CVE-2022-30723MEDIUMCVSS 4.0EG 4.32022-06-07
Broadcasting Intent including the BluetoothDevice object without proper restriction of receivers in activateVoiceRecognitionWithDevice function of Bluetooth prior to SMR Jun-2022 Release 1 leaks MAC address of the connected Bluetooth devic…
- CVE-2022-30724MEDIUMCVSS 4.0EG 4.32022-06-07
Broadcasting Intent including the BluetoothDevice object without proper restriction of receivers in sendIntentSessionCompleted function of Bluetooth prior to SMR Jun-2022 Release 1 leaks MAC address of the connected Bluetooth device.
- CVE-2022-30725MEDIUMCVSS 4.0EG 4.32022-06-07
Broadcasting Intent including the BluetoothDevice object without proper restriction of receivers in sendIntentSessionError function of Bluetooth prior to SMR Jun-2022 Release 1 leaks MAC address of the connected Bluetooth device.
- CVE-2022-30727MEDIUMCVSS 6.2EG 6.22022-06-07
Improper handling of insufficient permissions vulnerability in addAppPackageNameToAllowList in PersonaManagerService prior to SMR Jun-2022 Release 1 allows local attackers to set some setting value in work space.
- CVE-2022-31152MEDIUMCVSS 6.4EG 6.42022-09-02
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. The Matrix specification specifies a list of [event authorization rules](https://spec.matrix.org/v1.2/rooms/v9/#authorization-rules) which mus…
- CVE-2022-3175MEDIUMCVSS 5.3EG 5.32022-09-13
Missing Custom Error Page in GitHub repository ikus060/rdiffweb prior to 2.4.2.
- CVE-2022-31799CRITICALCVSS 9.8EG 9.82022-06-02
Bottle before 0.12.20 mishandles errors during early request binding.
- CVE-2022-32264HIGHCVSS 7.5EG 7.52022-09-06
sys/netinet/tcp_timer.h in FreeBSD before 7.0 contains a denial-of-service (DoS) vulnerability due to improper handling of TSopt on TCP connections. NOTE: This vulnerability only affects products that are no longer supported by the maintai…
- CVE-2022-32590MEDIUMCVSS 6.7EG 6.72022-10-07
In wlan, there is a possible use after free due to an incorrect status check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07299425…
- CVE-2022-32655MEDIUMCVSS 6.7EG 6.72023-02-06
In Wi-Fi driver, there is a possible undefined behavior due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: G…
- CVE-2022-32657MEDIUMCVSS 6.7EG 6.72023-01-03
In Wi-Fi driver, there is a possible undefined behavior due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: G…
- CVE-2022-32658MEDIUMCVSS 6.7EG 6.72023-01-03
In Wi-Fi driver, there is a possible undefined behavior due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: G…
- CVE-2022-32659MEDIUMCVSS 6.7EG 6.72023-01-03
In Wi-Fi driver, there is a possible undefined behavior due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: G…
- CVE-2022-3279MEDIUMCVSS 2.7EG 6.52022-10-17
An unhandled exception in job log parsing in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to prevent access to job logs
- CVE-2022-32990MEDIUMCVSS 5.5EG 5.52022-06-24
An issue in gimp_layer_invalidate_boundary of GNOME GIMP 2.10.30 allows attackers to trigger an unhandled exception via a crafted XCF file, causing a Denial of Service (DoS).
- CVE-2022-33748MEDIUMCVSS 5.6EG 5.62022-10-11
lock order inversion in transitive grant copy handling As part of XSA-226 a missing cleanup call was inserted on an error handling path. While doing so, locking requirements were not paid attention to. As a result two cooperating guests gr…
- CVE-2022-33886HIGHCVSS 7.8EG 7.82022-10-03
A maliciously crafted MODEL and SLDPRT file can be used to write beyond the allocated buffer while parsing through Autodesk AutoCAD 2023, 2022, 2021, 2020, and Maya 2023 and 2022. The vulnerability exists because the application fails to h…
- CVE-2022-33887HIGHCVSS 7.8EG 7.82022-10-03
A maliciously crafted PDF file when parsed through Autodesk AutoCAD 2023 causes an unhandled exception. An attacker can leverage this vulnerability to cause a crash or read sensitive data or execute arbitrary code in the context of the cur…
- CVE-2022-34368MEDIUMCVSS 6.1EG 6.52022-08-30
Dell EMC NetWorker 19.2.1.x 19.3.x, 19.4.x, 19.5.x, 19.6.x and 19.7.0.0 contain an Improper Handling of Insufficient Permissions or Privileges vulnerability. Authenticated non admin user could exploit this vulnerability and gain access to …
- CVE-2022-34633MEDIUMCVSS 5.5EG 5.52022-07-18
CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a executes crafted or incorrectly formatted sfence.vma instructions rather create an exception.
- CVE-2022-34634MEDIUMCVSS 5.5EG 5.52022-07-18
CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a executes crafted or incorrectly formatted det instructions rather create an exception.
- CVE-2022-34636MEDIUMCVSS 5.5EG 5.52022-07-18
CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a and RISCV-Boom commit ad64c5419151e5e886daee7084d8399713b46b4b implements the incorrect exception type when a PMA violation occurs during address translation.
- CVE-2022-34637MEDIUMCVSS 5.5EG 5.52022-07-18
CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a implements an incorrect exception type when an illegal virtual address is loaded.
- CVE-2022-34639MEDIUMCVSS 5.5EG 5.52022-07-18
CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a treats non-standard fence instructions as illegal which can affect the function of the application.
- CVE-2022-34641MEDIUMCVSS 5.5EG 5.52022-07-18
CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a and RISCV-Boom commit ad64c5419151e5e886daee7084d8399713b46b4b implements the incorrect exception type when a PMP violation occurs during address translation.
- CVE-2022-34643MEDIUMCVSS 5.5EG 5.52022-07-18
RISCV ISA Sim commit ac466a21df442c59962589ba296c702631e041b5 implements the incorrect exception priotrity when accessing memory.
- CVE-2022-34849MEDIUMCVSS 4.4EG 4.42023-02-16
Uncaught exception in the Intel(R) Iris(R) Xe MAX drivers for Windows before version 100.0.5.1436(v2) may allow a privileged user to potentially enable denial of service via local access.
- CVE-2022-35268HIGHCVSS 7.5EG 7.52022-10-25
A denial of service vulnerability exists in the web_server hashFirst functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network request can lead to denial of service. An attacker can send a sequence of requests to trigge…
- CVE-2022-35295MEDIUMCVSS 4.9EG 4.92022-09-13
In SAP Host Agent (SAPOSCOL) - version 7.22, an attacker may use files created by saposcol to escalate privileges for themselves.
- CVE-2022-36031MEDIUMCVSS 6.5EG 6.52022-08-19
Directus is a free and open-source data platform for headless content management. The Directus process can be aborted by having an authorized user update the `filename_disk` value to a folder and accessing that file through the `/assets` e…
- CVE-2022-36287MEDIUMCVSS 4.0EG 4.32023-02-16
Uncaught exception in the FCS Server software maintained by Intel before version 1.1.79.3 may allow a privileged user to potentially enable denial of service via physical access.
Map vulnerabilities like CWE-755 to your infrastructure
EchelonGraph correlates every CVE — across CWE-755 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →