CWE-617— Reachable Assertion
The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.— MITRE CWE catalog
819 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-617page 1 of 17
- CVE-2006-4095HIGHCVSS 7.5EG 7.52006-09-06
BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via certain SIG queries, which cause an assertion failure when multiple RRsets are returned.
- CVE-2006-5779HIGHCVSS 7.5EG 8.72006-11-07
OpenLDAP before 2.3.29 allows remote attackers to cause a denial of service (daemon crash) via LDAP BIND requests with long authcid names, which triggers an assertion failure.
- CVE-2006-6767HIGHCVSS 7.5EG 7.52007-01-16
oftpd before 0.3.7 allows remote attackers to cause a denial of service (daemon abort) via a (1) LPRT or (2) LPASV command with an unsupported address family, which triggers an assertion failure.
- CVE-2006-6811MEDIUMCVSS 6.5EG 6.52006-12-29
KsIRC 1.3.12 allows remote attackers to cause a denial of service (crash) via a long PRIVMSG string when connecting to an Internet Relay Chat (IRC) server, which causes an assertion failure and results in a NULL pointer dereference. NOTE:…
- CVE-2010-3411MEDIUMCVSS v2 5.0EG 5.02010-09-16
Google Chrome before 6.0.472.59 on Linux does not properly handle cursors, which might allow attackers to cause a denial of service (assertion failure) via unspecified vectors.
- CVE-2011-3596HIGHCVSS 7.5EG 7.52019-11-26
Polipo before 1.0.4.1 suffers from a DoD vulnerability via specially-crafted HTTP POST / PUT request.
- CVE-2012-5521MEDIUMCVSS 6.5EG 6.52019-11-25
quagga (ospf6d) 0.99.21 has a DoS flaw in the way the ospf6d daemon performs routes removal
- CVE-2015-8012HIGHCVSS 7.5EG 7.52020-01-28
lldpd before 0.8.0 allows remote attackers to cause a denial of service (assertion failure and daemon crash) via a malformed packet.
- CVE-2015-8745MEDIUMCVSS 5.5EG 5.52016-12-29
QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue. It could occur while reading Interrupt Mask Registers (IMR). A privileged (CAP_SYS_RAWIO) guest user could use this flaw t…
- CVE-2016-8864HIGHCVSS 7.5EG 7.72016-11-02
named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9.11.x before 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNAME record in the answer section of a response to …
- CVE-2016-9388MEDIUMCVSS 5.5EG 5.52017-03-23
The ras_getcmap function in ras_dec.c in JasPer before 1.900.14 allows remote attackers to cause a denial of service (assertion failure) via a crafted image file.
- CVE-2016-9397HIGHCVSS 7.5EG 7.52017-03-23
The jpc_dequantize function in jpc_dec.c in JasPer 1.900.13 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors.
- CVE-2016-9398HIGHCVSS 7.5EG 7.52017-03-23
The jpc_floorlog2 function in jpc_math.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors.
- CVE-2016-9399HIGHCVSS 7.5EG 7.52017-03-23
The calcstepsizes function in jpc_dec.c in JasPer 1.900.22 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors.
- CVE-2017-0375HIGHCVSS 7.5EG 7.52017-06-09
The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the relay_send_end_cell_from_edge_ function via a malformed BEGIN cell.
- CVE-2017-0376HIGHCVSS 7.5EG 7.52017-06-09
The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the connection_edge_process_relay_cell function via a BEGIN_DIR cell on a rendezvous circuit.
- CVE-2017-1000252MEDIUMCVSS 5.5EG 5.52017-09-26
The KVM subsystem in the Linux kernel through 4.13.3 allows guest OS users to cause a denial of service (assertion failure, and hypervisor hang or crash) via an out-of bounds guest_irq value, related to arch/x86/kvm/vmx.c and virt/kvm/even…
- CVE-2017-11368MEDIUMCVSS 6.5EG 6.52017-08-09
In MIT Kerberos 5 (aka krb5) 1.7 and later, an authenticated attacker can cause a KDC assertion failure by sending invalid S4U2Self or S4U2Proxy requests.
- CVE-2017-11524MEDIUMCVSS 6.5EG 6.52017-07-23
The WriteBlob function in MagickCore/blob.c in ImageMagick before 6.9.8-10 and 7.x before 7.6.0-0 allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted file.
- CVE-2017-11683MEDIUMCVSS 6.5EG 6.52017-07-27
There is a reachable assertion in the Internal::TiffReader::visitDirectory function in tiffvisitor.cpp of Exiv2 0.26 that will lead to a remote denial of service attack via crafted input.
- CVE-2017-11692HIGHCVSS 7.5EG 7.52017-07-30
The function "Token& Scanner::peek" in scanner.cpp in yaml-cpp 0.5.3 and earlier allows remote attackers to cause a denial of service (assertion failure and application exit) via a '!2' string.
- CVE-2017-12168MEDIUMCVSS 6.0EG 6.02017-09-20
The access_pmu_evcntr function in arch/arm64/kvm/sys_regs.c in the Linux kernel before 4.8.11 allows privileged KVM guest OS users to cause a denial of service (assertion failure and host OS crash) by accessing the Performance Monitors Cyc…
- CVE-2017-12434MEDIUMCVSS 6.5EG 6.52017-08-04
In ImageMagick 7.0.6-1, a missing NULL check vulnerability was found in the function ReadMATImage in coders/mat.c, which allows attackers to cause a denial of service (assertion failure) in DestroyImageInfo in image.c.
- CVE-2017-12670MEDIUMCVSS 6.5EG 6.52017-08-07
In ImageMagick 7.0.6-3, missing validation was found in coders/mat.c, leading to an assertion failure in the function DestroyImage in MagickCore/image.c, which allows attackers to cause a denial of service.
- CVE-2017-12959HIGHCVSS 7.5EG 7.52017-08-18
There is a reachable assertion abort in the function dict_add_mrset() in data/dictionary.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to a remote denial of service attack.
- CVE-2017-12960HIGHCVSS 7.5EG 7.52017-08-18
There is a reachable assertion abort in the function dict_rename_var() in data/dictionary.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to remote denial of service.
- CVE-2017-13132MEDIUMCVSS 6.5EG 6.52017-08-23
In ImageMagick 7.0.6-8, the WritePDFImage function in coders/pdf.c operates on an incorrect data structure in the "dump uncompressed PseudoColor packets" step, which allows attackers to cause a denial of service (assertion failure in Write…
- CVE-2017-13658MEDIUMCVSS 6.5EG 6.52017-08-24
In ImageMagick before 6.9.9-3 and 7.x before 7.0.6-3, there is a missing NULL check in the ReadMATImage function in coders/mat.c, leading to a denial of service (assertion failure and application exit) in the DestroyImageInfo function in M…
- CVE-2017-13673MEDIUMCVSS 6.5EG 6.52017-08-29
The vga display update in mis-calculated the region for the dirty bitmap snapshot in case split screen mode is used causing a denial of service (assertion failure) in the cpu_physical_memory_snapshot_get_dirty function.
- CVE-2017-13726MEDIUMCVSS 6.5EG 6.52017-08-29
There is a reachable assertion abort in the function TIFFWriteDirectorySec() in LibTIFF 4.0.8, related to tif_dirwrite.c and a SubIFD tag. A crafted input will lead to a remote denial of service attack.
- CVE-2017-13727MEDIUMCVSS 6.5EG 6.52017-08-29
There is a reachable assertion abort in the function TIFFWriteDirectoryTagSubifd() in LibTIFF 4.0.8, related to tif_dirwrite.c and a SubIFD tag. A crafted input will lead to a remote denial of service attack.
- CVE-2017-13745HIGHCVSS 7.5EG 7.52017-08-29
There is a reachable assertion abort in the function jpc_dec_process_sot() in jpc/jpc_dec.c in JasPer 2.0.12 that will lead to a remote denial of service attack by triggering an unexpected jpc_ppmstabtostreams return value, a different vul…
- CVE-2017-13746HIGHCVSS 7.5EG 7.52017-08-29
There is a reachable assertion abort in the function jpc_dec_process_siz() in jpc/jpc_dec.c:1297 in JasPer 2.0.12 that will lead to a remote denial of service attack.
- CVE-2017-13747HIGHCVSS 7.5EG 7.52017-08-29
There is a reachable assertion abort in the function jpc_floorlog2() in jpc/jpc_math.c in JasPer 2.0.12 that will lead to a remote denial of service attack.
- CVE-2017-13749HIGHCVSS 7.5EG 7.52017-08-29
There is a reachable assertion abort in the function jpc_pi_nextrpcl() in jpc/jpc_t2cod.c in JasPer 2.0.12 that will lead to a remote denial of service attack.
- CVE-2017-13750HIGHCVSS 7.5EG 7.52017-08-29
There is a reachable assertion abort in the function jpc_dec_process_siz() in jpc/jpc_dec.c:1296 in JasPer 2.0.12 that will lead to a remote denial of service attack.
- CVE-2017-13751HIGHCVSS 7.5EG 7.52017-08-29
There is a reachable assertion abort in the function calcstepsizes() in jpc/jpc_dec.c in JasPer 2.0.12 that will lead to a remote denial of service attack.
- CVE-2017-13752HIGHCVSS 7.5EG 7.52017-08-29
There is a reachable assertion abort in the function jpc_dequantize() in jpc/jpc_dec.c in JasPer 2.0.12 that will lead to a remote denial of service attack.
- CVE-2017-14649MEDIUMCVSS 5.5EG 5.52017-09-21
ReadOneJNGImage in coders/png.c in GraphicsMagick version 1.3.26 does not properly validate JNG data, leading to a denial of service (assertion failure in magick/pixel_cache.c, and application crash).
- CVE-2017-15371MEDIUMCVSS 5.5EG 5.52017-10-16
There is a reachable assertion abort in the function sox_append_comment() in formats.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a denial of service attack during conversion of an audio file.
- CVE-2017-16818MEDIUMCVSS 6.5EG 6.52017-12-20
RADOS Gateway in Ceph 12.1.0 through 12.2.1 allows remote authenticated users to cause a denial of service (assertion failure and application exit) by leveraging "full" (not necessarily admin) privileges to post an invalid profile to the a…
- CVE-2017-17432HIGHCVSS 7.5EG 7.52017-12-06
OpenAFS 1.x before 1.6.22 does not properly validate Rx ack packets, which allows remote attackers to cause a denial of service (system crash or application crash) via crafted fields, as demonstrated by an integer underflow and assertion f…
- CVE-2017-17722MEDIUMCVSS 6.5EG 6.52018-02-12
In Exiv2 0.26, there is a reachable assertion in the readHeader function in bigtiffimage.cpp, which will lead to a remote denial of service attack via a crafted TIFF file.
- CVE-2017-18169MEDIUMCVSS 5.5EG 5.52018-06-15
User process can perform the kernel DOS in ashmem when doing cache maintenance operation in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel.
- CVE-2017-18252MEDIUMCVSS 6.5EG 6.52018-03-27
An issue was discovered in ImageMagick 7.0.7. The MogrifyImageList function in MagickWand/mogrify.c allows attackers to cause a denial of service (assertion failure and application exit in ReplaceImageInList) via a crafted file.
- CVE-2017-3136MEDIUMCVSS 5.9EG 5.92019-01-16
A query with a specific set of characteristics could cause a server using DNS64 to encounter an assertion failure and terminate. An attacker could deliberately construct a query, enabling denial-of-service against a server if it was config…
- CVE-2017-3137HIGHCVSS 7.5EG 7.52019-01-16
Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resource records could lead to a situation in which named would exit with an assertion failure when processing a response in w…
- CVE-2017-3138MEDIUMCVSS 6.5EG 6.52019-01-16
named contains a feature which allows operators to issue commands to a running server by communicating with the server process over a control channel, using a utility program such as rndc. A regression introduced in a recent feature change…
- CVE-2017-3139HIGHCVSS 7.5EG 7.52019-04-09
A denial of service flaw was found in the way BIND handled DNSSEC validation. A remote attacker could use this flaw to make named exit unexpectedly with an assertion failure via a specially crafted DNS response.
- CVE-2017-5981MEDIUMCVSS 5.5EG 5.52017-03-01
seeko.c in zziplib 0.13.62 allows remote attackers to cause a denial of service (assertion failure and crash) via a crafted ZIP file.
Map vulnerabilities like CWE-617 to your infrastructure
EchelonGraph correlates every CVE — across CWE-617 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →