CWE-617— Reachable Assertion
The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.— MITRE CWE catalog
880 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-617page 15 of 18
- CVE-2023-28856MEDIUMCVSS 5.5EG 5.52023-04-18
Redis is an open source, in-memory database that persists on disk. Authenticated users can use the `HINCRBYFLOAT` command to create an invalid hash field that will crash Redis on access in affected versions. This issue has been addressed i…
- CVE-2022-25675MEDIUMCVSS 5.5EG 5.52022-12-13
Denial of service due to reachable assertion in modem while processing filter rule from application client in Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile
- CVE-2022-40755MEDIUMCVSS 5.5EG 5.52022-09-16
JasPer 3.0.6 allows denial of service via a reachable assertion in the function inttobits in libjasper/base/jas_image.c.
- CVE-2022-38496MEDIUMCVSS 5.5EG 5.52022-09-13
LIEF commit 365a16a was discovered to contain a reachable assertion abort via the component BinaryStream.hpp.
- CVE-2022-2719MEDIUMCVSS 5.5EG 5.52022-08-10
In ImageMagick, a crafted file could trigger an assertion failure when a call to WriteImages was made in MagickWand/operation.c, due to a NULL image list. This could potentially cause a denial of service. This was fixed in upstream ImageMa…
- CVE-2022-33069MEDIUMCVSS 5.5EG 5.52022-06-23
Ethereum Solidity v0.8.14 contains an assertion failure via SMTEncoder::indexOrMemberAssignment() at SMTEncoder.cpp.
- CVE-2022-29213MEDIUMCVSS 5.5EG 5.52022-05-21
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the `tf.compat.v1.signal.rfft2d` and `tf.compat.v1.signal.rfft3d` lack input validation and under certain condition can result in…
- CVE-2022-27939MEDIUMCVSS 5.5EG 5.52022-03-26
tcprewrite in Tcpreplay 4.4.1 has a reachable assertion in get_layer4_v6 in common/get.c.
- CVE-2022-27938MEDIUMCVSS 5.5EG 5.52022-03-26
stb_image.h (aka the stb image loader) 2.19, as used in libsixel and other products, has a reachable assertion in stbi__create_png_image_raw.
- CVE-2022-25484MEDIUMCVSS 5.5EG 5.52022-03-22
tcpprep v4.4.1 has a reachable assertion (assert(l2len > 0)) in packet2tree() at tree.c in tcpprep v4.4.1.
- CVE-2021-45861MEDIUMCVSS 5.5EG 5.52022-03-02
There is an Assertion `num <= INT_BIT' failed at BitStreamReader::skipBits in /bitStream.h:132 of tsMuxer git-c6a0277.
- CVE-2022-22901MEDIUMCVSS 5.5EG 5.52022-02-17
There is an Assertion in 'context_p->next_scanner_info_p->type == SCANNER_TYPE_FUNCTION' failed at parser_parse_function_arguments in /js/js-parser.c of JerryScript commit a6ab5e9.
- CVE-2021-45387MEDIUMCVSS 5.5EG 5.52022-02-11
tcpreplay 4.3.4 has a Reachable Assertion in add_tree_ipv4() at tree.c.
- CVE-2021-45386MEDIUMCVSS 5.5EG 5.52022-02-11
tcpreplay 4.3.4 has a Reachable Assertion in add_tree_ipv6() at tree.c
- CVE-2021-46666MEDIUMCVSS 5.5EG 5.52022-02-01
MariaDB before 10.6.2 allows an application crash because of mishandling of a pushdown from a HAVING clause to a WHERE clause.
- CVE-2021-46517MEDIUMCVSS 5.5EG 5.52022-01-27
There is an Assertion `mjs_stack_size(&mjs->scopes) > 0' failed at src/mjs_exec.c in Cesanta MJS v2.20.0.
- CVE-2021-46515MEDIUMCVSS 5.5EG 5.52022-01-27
There is an Assertion `mjs_stack_size(&mjs->scopes) >= scopes_len' failed at src/mjs_exec.c in Cesanta MJS v2.20.0.
- CVE-2021-46514MEDIUMCVSS 5.5EG 5.52022-01-27
There is an Assertion 'ppos != NULL && mjs_is_number(*ppos)' failed at src/mjs_core.c in Cesanta MJS v2.20.0.
- CVE-2021-46511MEDIUMCVSS 5.5EG 5.52022-01-27
There is an Assertion `m->len >= sizeof(v)' failed at src/mjs_core.c in Cesanta MJS v2.20.0.
- CVE-2021-46510MEDIUMCVSS 5.5EG 5.52022-01-27
There is an Assertion `s < mjs->owned_strings.buf + mjs->owned_strings.len' failed at src/mjs_gc.c in Cesanta MJS v2.20.0.
- CVE-2021-46508MEDIUMCVSS 5.5EG 5.52022-01-27
There is an Assertion `i < parts_cnt' failed at src/mjs_bcode.c in Cesanta MJS v2.20.0.
- CVE-2021-46506MEDIUMCVSS 5.5EG 5.52022-01-27
There is an Assertion 'v->d.lval != v' failed at src/jsiValue.c in Jsish v3.5.0.
- CVE-2021-46504MEDIUMCVSS 5.5EG 5.52022-01-27
There is an Assertion 'vp != resPtr' failed at jsiEval.c in Jsish v3.5.0.
- CVE-2021-44994MEDIUMCVSS 5.5EG 5.52022-01-25
There is an Assertion ''JERRY_CONTEXT (jmem_heap_allocated_size) == 0'' failed at /jerry-core/jmem/jmem-heap.c in Jerryscript 3.0.0.
- CVE-2021-44993MEDIUMCVSS 5.5EG 5.52022-01-25
There is an Assertion ''ecma_is_value_boolean (base_value)'' failed at /jerry-core/ecma/operations/ecma-get-put-value.c in Jerryscript 3.0.0.
- CVE-2022-22892MEDIUMCVSS 5.5EG 5.52022-01-21
There is an Assertion 'ecma_is_value_undefined (value) || ecma_is_value_null (value) || ecma_is_value_boolean (value) || ecma_is_value_number (value) || ecma_is_value_string (value) || ecma_is_value_bigint (value) || ecma_is_value_symbol (…
- CVE-2022-22890MEDIUMCVSS 5.5EG 5.52022-01-20
There is an Assertion 'arguments_type != SCANNER_ARGUMENTS_PRESENT && arguments_type != SCANNER_ARGUMENTS_PRESENT_NO_REG' failed at /jerry-core/parser/js/js-scanner-util.c in Jerryscript 3.0.0.
- CVE-2021-46351MEDIUMCVSS 5.5EG 5.52022-01-20
There is an Assertion 'local_tza == ecma_date_local_time_zone_adjustment (date_value)' failed at /jerry-core/ecma/builtin-objects/ecma-builtin-date-prototype.c(ecma_builtin_date_prototype_dispatch_set):421 in JerryScript 3.0.0.
- CVE-2021-46350MEDIUMCVSS 5.5EG 5.52022-01-20
There is an Assertion 'ecma_is_value_object (value)' failed at jerryscript/jerry-core/ecma/base/ecma-helpers-value.c in JerryScript 3.0.0.
- CVE-2021-46349MEDIUMCVSS 5.5EG 5.52022-01-20
There is an Assertion 'type == ECMA_OBJECT_TYPE_GENERAL || type == ECMA_OBJECT_TYPE_PROXY' failed at /jerry-core/ecma/operations/ecma-objects.c in JerryScript 3.0.0.
- CVE-2021-46348MEDIUMCVSS 5.5EG 5.52022-01-20
There is an Assertion 'ECMA_STRING_IS_REF_EQUALS_TO_ONE (string_p)' failed at /jerry-core/ecma/base/ecma-literal-storage.c in JerryScript 3.0.0.
- CVE-2021-46347MEDIUMCVSS 5.5EG 5.52022-01-20
There is an Assertion 'ecma_object_check_class_name_is_object (obj_p)' failed at /jerry-core/ecma/operations/ecma-objects.c in JerryScript 3.0.0.
- CVE-2021-46346MEDIUMCVSS 5.5EG 5.52022-01-20
There is an Assertion 'local_tza == ecma_date_local_time_zone_adjustment (date_value)' failed at /jerry-core/ecma/builtin-objects/ecma-builtin-date-prototype.c(ecma_builtin_date_prototype_dispatch_set):421 in JerryScript 3.0.0.
- CVE-2021-46345MEDIUMCVSS 5.5EG 5.52022-01-20
There is an Assertion 'cesu8_cursor_p == cesu8_end_p' failed at /jerry-core/lit/lit-strings.c in JerryScript 3.0.0.
- CVE-2021-46344MEDIUMCVSS 5.5EG 5.52022-01-20
There is an Assertion 'flags & PARSER_PATTERN_HAS_REST_ELEMENT' failed at /jerry-core/parser/js/js-parser-expr.c in JerryScript 3.0.0.
- CVE-2021-46343MEDIUMCVSS 5.5EG 5.52022-01-20
There is an Assertion 'context_p->token.type == LEXER_LITERAL' failed at /jerry-core/parser/js/js-parser-expr.c in JerryScript 3.0.0.
- CVE-2021-46342MEDIUMCVSS 5.5EG 5.52022-01-20
There is an Assertion 'ecma_is_lexical_environment (obj_p) || !ecma_op_object_is_fast_array (obj_p)' failed at /jerry-core/ecma/base/ecma-helpers.c in JerryScript 3.0.0.
- CVE-2021-46340MEDIUMCVSS 5.5EG 5.52022-01-20
There is an Assertion 'context_p->stack_top_uint8 == SCAN_STACK_TRY_STATEMENT || context_p->stack_top_uint8 == SCAN_STACK_CATCH_STATEMENT' failed at /parser/js/js-scanner.c(scanner_scan_statement_end) in JerryScript 3.0.0.
- CVE-2021-46339MEDIUMCVSS 5.5EG 5.52022-01-20
There is an Assertion 'lit_is_valid_cesu8_string (string_p, string_size)' failed at /base/ecma-helpers-string.c(ecma_new_ecma_string_from_utf8) in JerryScript 3.0.0.
- CVE-2021-46338MEDIUMCVSS 5.5EG 5.52022-01-20
There is an Assertion 'ecma_is_lexical_environment (object_p)' failed at /base/ecma-helpers.c(ecma_get_lex_env_type) in JerryScript 3.0.0.
- CVE-2021-46337MEDIUMCVSS 5.5EG 5.52022-01-20
There is an Assertion 'page_p != NULL' failed at /parser/js/js-parser-mem.c(parser_list_get) in JerryScript 3.0.0.
- CVE-2021-46336MEDIUMCVSS 5.5EG 5.52022-01-20
There is an Assertion 'opts & PARSER_CLASS_LITERAL_CTOR_PRESENT' failed at /parser/js/js-parser-expr.c(parser_parse_class_body) in JerryScript 3.0.0.
- CVE-2021-46055MEDIUMCVSS 5.5EG 5.52022-01-10
A Denial of Service vulnerability exists in Binaryen 104 due to an assertion abort in wasm::WasmBinaryBuilder::visitRethrow(wasm::Rethrow*).
- CVE-2021-46054MEDIUMCVSS 5.5EG 5.52022-01-10
A Denial of Service vulnerability exists in Binaryen 104 due to an assertion abort in wasm::WasmBinaryBuilder::visitRethrow(wasm::Rethrow*).
- CVE-2021-46052MEDIUMCVSS 5.5EG 5.52022-01-10
A Denial of Service vulnerability exists in Binaryen 104 due to an assertion abort in wasm::Tuple::validate.
- CVE-2021-46048MEDIUMCVSS 5.5EG 5.52022-01-10
A Denial of Service vulnerability exists in Binaryen 104 due to an assertion abort in wasm::WasmBinaryBuilder::readFunctions.
- CVE-2021-44022MEDIUMCVSS 5.5EG 5.52021-12-03
A reachable assertion vulnerability in Trend Micro Apex One could allow an attacker to crash the program on affected installations, leading to a denial-of-service (DoS). Please note: an attacker must first obtain the ability to execute low…
- CVE-2021-41200MEDIUMCVSS 5.5EG 5.52021-11-05
TensorFlow is an open source platform for machine learning. In affected versions if `tf.summary.create_file_writer` is called with non-scalar arguments code crashes due to a `CHECK`-fail. The fix will be included in TensorFlow 2.7.0. We wi…
- CVE-2021-39283MEDIUMCVSS 5.5EG 5.52021-08-18
liveMedia/FramedSource.cpp in Live555 through 1.08 allows an assertion failure and application exit via multiple SETUP and PLAY commands.
- CVE-2021-37644MEDIUMCVSS 5.5EG 5.52021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions providing a negative element to `num_elements` list argument of `tf.raw_ops.TensorListReserve` causes the runtime to abort the process due to reall…
Map vulnerabilities like CWE-617 to your infrastructure
EchelonGraph correlates every CVE — across CWE-617 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →