Skip to main content

CWE archive

CWE-617 CVEs

Programmatic archive

789 CVEs tagged with CWE-6174 Critical, 327 High, 428 Medium, 30 Low, 0 Unrated.

CVE-2018-5740

Published Jan 16, 2019

"deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2017-3137

Published Jan 16, 2019

Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resource records could lead to a situation in which named would ex…

CVSS 7.5 · High
evidence mentions
3
Buzz score
21.9

CVE-2017-3136

Published Jan 16, 2019

A query with a specific set of characteristics could cause a server using DNS64 to encounter an assertion failure and terminate. An attacker could deliberately construct a query,…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2019-6461

Published Jan 16, 2019

An issue was discovered in cairo 1.16.0. There is an assertion problem in the function _cairo_arc_in_direction in the file cairo-arc.c.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20217

Published Dec 26, 2018

A Reachable Assertion issue was discovered in the KDC in MIT Kerberos 5 (aka krb5) before 1.17. If an attacker can obtain a krbtgt ticket using an older encryption type (single-DE…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-19963

Published Dec 8, 2018

An issue was discovered in Xen 4.11 allowing HVM guest OS users to cause a denial of service (host OS crash) or possibly gain host OS privileges because x86 IOREQ server resource…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-12543

Published Nov 15, 2018

In Eclipse Mosquitto versions 1.5 to 1.5.2 inclusive, if a message is published to Mosquitto that has a topic starting with $, but that is not $SYS, e.g. $test/test, then an asser…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-17231

Published Sep 19, 2018

Telegram Desktop (aka tdesktop) 1.3.14 might allow attackers to cause a denial of service (assertion failure and application exit) via an "Edit color palette" search that triggers…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-17096

Published Sep 16, 2018

The BPMDetect class in BPMDetect.cpp in libSoundTouch.a in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (assertion failure and application e…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-14045

Published Jul 13, 2018

The FIRFilter::evaluateFilterMulti function in FIRFilter.cpp in libSoundTouch.a in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (assertion f…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-14044

Published Jul 13, 2018

The RateTransposer::setChannels function in RateTransposer.cpp in libSoundTouch.a in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (assertion…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-13304

Published Jul 5, 2018

In libavcodec in FFmpeg 4.0.1, improper maintenance of the consistency between the context profile field and studio_profile in libavcodec may trigger an assertion failure while co…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18169

Published Jun 15, 2018

User process can perform the kernel DOS in ashmem when doing cache maintenance operation in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using t…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 701-725 of 789 CVEsPage 29 of 32