CWE-617— Reachable Assertion
The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.— MITRE CWE catalog
878 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-617page 11 of 18
- CVE-2017-16818MEDIUMCVSS 6.5EG 6.52017-12-20
RADOS Gateway in Ceph 12.1.0 through 12.2.1 allows remote authenticated users to cause a denial of service (assertion failure and application exit) by leveraging "full" (not necessarily admin) privileges to post an invalid profile to the a…
- CVE-2017-13673MEDIUMCVSS 6.5EG 6.52017-08-29
The vga display update in mis-calculated the region for the dirty bitmap snapshot in case split screen mode is used causing a denial of service (assertion failure) in the cpu_physical_memory_snapshot_get_dirty function.
- CVE-2017-13727MEDIUMCVSS 6.5EG 6.52017-08-29
There is a reachable assertion abort in the function TIFFWriteDirectoryTagSubifd() in LibTIFF 4.0.8, related to tif_dirwrite.c and a SubIFD tag. A crafted input will lead to a remote denial of service attack.
- CVE-2017-13726MEDIUMCVSS 6.5EG 6.52017-08-29
There is a reachable assertion abort in the function TIFFWriteDirectorySec() in LibTIFF 4.0.8, related to tif_dirwrite.c and a SubIFD tag. A crafted input will lead to a remote denial of service attack.
- CVE-2017-13658MEDIUMCVSS 6.5EG 6.52017-08-24
In ImageMagick before 6.9.9-3 and 7.x before 7.0.6-3, there is a missing NULL check in the ReadMATImage function in coders/mat.c, leading to a denial of service (assertion failure and application exit) in the DestroyImageInfo function in M…
- CVE-2017-13132MEDIUMCVSS 6.5EG 6.52017-08-23
In ImageMagick 7.0.6-8, the WritePDFImage function in coders/pdf.c operates on an incorrect data structure in the "dump uncompressed PseudoColor packets" step, which allows attackers to cause a denial of service (assertion failure in Write…
- CVE-2017-11368MEDIUMCVSS 6.5EG 6.52017-08-09
In MIT Kerberos 5 (aka krb5) 1.7 and later, an authenticated attacker can cause a KDC assertion failure by sending invalid S4U2Self or S4U2Proxy requests.
- CVE-2017-12670MEDIUMCVSS 6.5EG 6.52017-08-07
In ImageMagick 7.0.6-3, missing validation was found in coders/mat.c, leading to an assertion failure in the function DestroyImage in MagickCore/image.c, which allows attackers to cause a denial of service.
- CVE-2017-12434MEDIUMCVSS 6.5EG 6.52017-08-04
In ImageMagick 7.0.6-1, a missing NULL check vulnerability was found in the function ReadMATImage in coders/mat.c, which allows attackers to cause a denial of service (assertion failure) in DestroyImageInfo in image.c.
- CVE-2017-11683MEDIUMCVSS 6.5EG 6.52017-07-27
There is a reachable assertion in the Internal::TiffReader::visitDirectory function in tiffvisitor.cpp of Exiv2 0.26 that will lead to a remote denial of service attack via crafted input.
- CVE-2017-11524MEDIUMCVSS 6.5EG 6.52017-07-23
The WriteBlob function in MagickCore/blob.c in ImageMagick before 6.9.8-10 and 7.x before 7.6.0-0 allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted file.
- CVE-2017-9501MEDIUMCVSS 6.5EG 6.52017-06-07
In ImageMagick 7.0.5-7 Q16, an assertion failure was found in the function LockSemaphoreInfo, which allows attackers to cause a denial of service via a crafted file.
- CVE-2017-9500MEDIUMCVSS 6.5EG 6.52017-06-07
In ImageMagick 7.0.5-8 Q16, an assertion failure was found in the function ResetImageProfileIterator, which allows attackers to cause a denial of service via a crafted file.
- CVE-2017-9499MEDIUMCVSS 6.5EG 6.52017-06-07
In ImageMagick 7.0.5-7 Q16, an assertion failure was found in the function SetPixelChannelAttributes, which allows attackers to cause a denial of service via a crafted file.
- CVE-2017-9142MEDIUMCVSS 6.5EG 6.52017-05-22
In ImageMagick 7.0.5-7 Q16, a crafted file could trigger an assertion failure in the WriteBlob function in MagickCore/blob.c because of missing checks in the ReadOneJNGImage function in coders/png.c.
- CVE-2017-9141MEDIUMCVSS 6.5EG 6.52017-05-22
In ImageMagick 7.0.5-7 Q16, a crafted file could trigger an assertion failure in the ResetImageProfileIterator function in MagickCore/profile.c because of missing checks in the ReadDDSImage function in coders/dds.c.
- CVE-2017-7479MEDIUMCVSS 6.5EG 6.52017-05-15
OpenVPN versions before 2.3.15 and before 2.4.2 are vulnerable to reachable assertion when packet-ID counter rolls over resulting into Denial of Service of server by authenticated attacker.
- CVE-2006-6811MEDIUMCVSS 6.5EG 6.52006-12-29
KsIRC 1.3.12 allows remote attackers to cause a denial of service (crash) via a long PRIVMSG string when connecting to an Internet Relay Chat (IRC) server, which causes an assertion failure and results in a NULL pointer dereference. NOTE:…
- CVE-2022-0865MEDIUMCVSS 5.5EG 6.52022-03-10
Reachable Assertion in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 5e180045.
- CVE-2025-50422MEDIUMCVSS 2.9EG 6.52025-08-04
Cairo through 1.18.4, as used in Poppler through 25.08.0, has an "unscaled->face == NULL" assertion failure for _cairo_ft_unscaled_font_fini in cairo-ft-font.c.
- CVE-2023-37011MEDIUMCVSS 6.3EG 6.32025-01-22
Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `Handover Required` message missing a required `MME_UE_S1AP_ID` field to repeate…
- CVE-2023-37010MEDIUMCVSS 6.3EG 6.32025-01-22
Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `eNB Status Transfer` message missing a required `MME_UE_S1AP_ID` field to repe…
- CVE-2023-37009MEDIUMCVSS 6.3EG 6.32025-01-22
Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `Handover Notification` message missing a required `MME_UE_S1AP_ID` field to rep…
- CVE-2020-15197MEDIUMCVSS 6.3EG 6.32020-09-25
In Tensorflow before version 2.3.1, the `SparseCountSparseOutput` implementation does not validate that the input arguments form a valid sparse tensor. In particular, there is no validation that the `indices` tensor has rank 2. This tensor…
- CVE-2026-71430MEDIUMCVSS 6.2EG 6.22026-08-06
node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.25.1, the WrappedRE2::Replace function built its replacement result and passed it to V8 using ToLocalChecked without checking for the empty MaybeLocal that V…
- CVE-2026-47475MEDIUMCVSS 6.2EG 6.22026-07-14
NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API where an attacker could trigger a reachable assertion in the sampler thread. A successful exploit of this vulnerability might lead to denial of service.
- CVE-2025-30034MEDIUMCVSS 6.2EG 6.22025-08-12
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.3). Affected devices do not properly validate input sent to its listening port on the local loopback interface. This could allow an unauthenticated loc…
- CVE-2024-33255MEDIUMCVSS 6.2EG 6.22024-04-26
Jerryscript commit cefd391 was discovered to contain an Assertion Failure via ECMA_STRING_IS_REF_EQUALS_TO_ONE (string_p) in ecma_free_string_list.
- CVE-2023-38473MEDIUMCVSS 6.2EG 6.22023-11-02
A vulnerability was found in Avahi. A reachable assertion exists in the avahi_alternative_host_name() function.
- CVE-2023-38472MEDIUMCVSS 6.2EG 6.22023-11-02
A vulnerability was found in Avahi. A reachable assertion exists in the avahi_rdata_parse() function.
- CVE-2023-38471MEDIUMCVSS 6.2EG 6.22023-11-02
A vulnerability was found in Avahi. A reachable assertion exists in the dbus_set_host_name function.
- CVE-2023-38470MEDIUMCVSS 6.2EG 6.22023-11-02
A vulnerability was found in Avahi. A reachable assertion exists in the avahi_escape_label() function.
- CVE-2023-38469MEDIUMCVSS 6.2EG 6.22023-11-02
A vulnerability was found in Avahi, where a reachable assertion exists in avahi_dns_packet_append_record.
- CVE-2021-43849MEDIUMCVSS 6.2EG 6.22021-12-23
cordova-plugin-fingerprint-aio is a plugin provides a single and simple interface for accessing fingerprint APIs on both Android 6+ and iOS. In versions prior to 5.0.1 The exported activity `de.niklasmerz.cordova.biometric.BiometricActivit…
- CVE-2026-58307MEDIUMCVSS 6.1EG 6.12026-07-09
Out-of-bounds read, Reachable assertion vulnerability in Samsung Open Source Escargot allows Overread Buffers, Input Data Manipulation. This issue affects Escargot: before 2dee22f5c7b8bf31cb7252d7731fae8c07f2842c.
- CVE-2017-12168MEDIUMCVSS 6.0EG 6.02017-09-20
The access_pmu_evcntr function in arch/arm64/kvm/sys_regs.c in the Linux kernel before 4.8.11 allows privileged KVM guest OS users to cause a denial of service (assertion failure and host OS crash) by accessing the Performance Monitors Cyc…
- CVE-2026-108105MEDIUMCVSS 5.9EG 5.92026-10-09
Open5GS through 2.8.0 contains a reachable assertion vulnerability in mme_gn_handle_sgsn_context_request() that allows remote unauthenticated attackers to crash the MME via malformed SGSN Address IEs. Attackers sending GTPv1-C traffic from…
- CVE-2026-91147MEDIUMCVSS 5.9EG 5.92026-09-18
A flaw was found in `cockpit-ws`. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a specially crafted request. When the `WebService.UrlRoot` is configured and a request is made to …
- CVE-2026-85534MEDIUMCVSS 5.9EG 5.92026-09-04
A flaw was found in libsoup. When a client sends an HTTP/2 request body from a non-pollable input stream, the library can buffer more data than the current flow-control window later allows. A malicious HTTP/2 server can shrink SETTINGS_INI…
- CVE-2026-66754MEDIUMCVSS 5.9EG 5.92026-07-28
Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the Request::remove_prefix function that allows remote unauthenticated attackers to crash the server by sending a crafted percent-encoded URL. Attackers can send a…
- CVE-2026-14586MEDIUMCVSS 5.9EG 5.92026-07-22
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, in DNS-over-QUIC environments, with high concurrency and under pressure, an assertion in libngtcp2 about monotonic timestamps could trigger and result in server termination and thus …
- CVE-2026-34219MEDIUMCVSS 5.9EG 5.92026-03-31
libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to version 0.49.4, the Rust libp2p Gossipsub implementation contains a remotely reachable panic in backoff expiry handling. After a peer sends a…
- CVE-2025-49088MEDIUMCVSS 5.9EG 5.92025-12-25
Pexip Infinity 32.0 through 37.1 before 37.2, in certain configurations of OTJ (One Touch Join) for Teams SIP Guest Join, has Improper Input Validation in the OTJ service, allowing a remote attacker to trigger a software abort via a crafte…
- CVE-2025-8537MEDIUMCVSS 5.9EG 5.92025-08-05
A vulnerability, which was classified as problematic, was found in Axiomatic Bento4 up to 1.6.0-641. Affected is the function AP4_DataBuffer::SetDataSize of the file Mp4Decrypt.cpp of the component mp4decrypt. The manipulation leads to all…
- CVE-2022-36016MEDIUMCVSS 5.9EG 5.92022-09-16
TensorFlow is an open source platform for machine learning. When `tensorflow::full_type::SubstituteFromAttrs` receives a `FullTypeDef& t` that is not exactly three args, it triggers a `CHECK`-fail instead of returning a status. We have pat…
- CVE-2022-36012MEDIUMCVSS 5.9EG 5.92022-09-16
TensorFlow is an open source platform for machine learning. When `mlir::tfg::ConvertGenericFunctionToFunctionDef` is given empty function attributes, it crashes. We have patched the issue in GitHub commit ad069af92392efee1418c48ff561fd3070…
- CVE-2022-36005MEDIUMCVSS 5.9EG 5.92022-09-16
TensorFlow is an open source platform for machine learning. When `tf.quantization.fake_quant_with_min_max_vars_gradient` receives input `min` or `max` that is nonscalar, it gives a `CHECK` fail that can trigger a denial of service attack. …
- CVE-2022-36004MEDIUMCVSS 5.9EG 5.92022-09-16
TensorFlow is an open source platform for machine learning. When `tf.random.gamma` receives large input shape and rates, it gives a `CHECK` fail that can trigger a denial of service attack. We have patched the issue in GitHub commit 552bfc…
- CVE-2022-36003MEDIUMCVSS 5.9EG 5.92022-09-16
TensorFlow is an open source platform for machine learning. When `RandomPoissonV2` receives large input shape and rates, it gives a `CHECK` fail that can trigger a denial of service attack. We have patched the issue in GitHub commit 552bfc…
- CVE-2022-36002MEDIUMCVSS 5.9EG 5.92022-09-16
TensorFlow is an open source platform for machine learning. When `Unbatch` receives a nonscalar input `id`, it gives a `CHECK` fail that can trigger a denial of service attack. We have patched the issue in GitHub commit 4419d10d576adefa36b…
Map vulnerabilities like CWE-617 to your infrastructure
EchelonGraph correlates every CVE — across CWE-617 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →