CWE-617— Reachable Assertion
The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.— MITRE CWE catalog
878 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-617page 5 of 18
- CVE-2022-33244HIGHCVSS 7.5EG 7.52023-03-10
Transient DOS due to reachable assertion in modem during MIB reception and SIB timeout
- CVE-2022-48363HIGHCVSS 7.5EG 7.52023-02-26
In MPD before 0.23.8, as used on Automotive Grade Linux and other platforms, the PipeWire output plugin mishandles a Drain call in certain situations involving truncated files. Eventually there is an assertion failure in libmpdclient becau…
- CVE-2022-3924HIGHCVSS 7.5EG 7.52023-01-26
This issue can affect BIND 9 resolvers with `stale-answer-enable yes;` that also make use of the option `stale-answer-client-timeout`, configured with a value greater than zero. If the resolver receives many queries that require recursion…
- CVE-2022-3488HIGHCVSS 7.5EG 7.52023-01-26
Processing of repeated responses to the same query, where both responses contain ECS pseudo-options, but where the first is broken in some way, can cause BIND to exit with an assertion failure. 'Broken' in this context is anything that wo…
- CVE-2020-36562HIGHCVSS 7.5EG 7.52022-12-28
Due to unchecked type assertions, maliciously crafted messages can cause panics, which may be used as a denial of service vector.
- CVE-2022-47516HIGHCVSS 7.5EG 7.52022-12-18
An issue was discovered in the libsofia-sip fork in drachtio-server before 0.8.20. It allows remote attackers to cause a denial of service (daemon crash) via a crafted UDP message that leads to a failure of the libsofia-sip-ua/tport/tport.…
- CVE-2022-25702HIGHCVSS 7.5EG 7.52022-12-13
Denial of service in modem due to reachable assertion while processing reconfiguration message in Snapdragon Auto, Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
- CVE-2022-25692HIGHCVSS 7.5EG 7.52022-12-13
Denial of service in Modem due to reachable assertion while processing the common config procedure in Snapdragon Auto, Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
- CVE-2022-25691HIGHCVSS 7.5EG 7.52022-12-13
Denial of service in Modem due to reachable assertion while processing SIB1 with invalid SCS and bandwidth settings in Snapdragon Mobile
- CVE-2022-25689HIGHCVSS 7.5EG 7.52022-12-13
Denial of service in Modem due to reachable assertion in Snapdragon Mobile
- CVE-2022-25673HIGHCVSS 7.5EG 7.52022-12-13
Denial of service in MODEM due to reachable assertion while processing configuration from network in Snapdragon Mobile
- CVE-2022-25672HIGHCVSS 7.5EG 7.52022-12-13
Denial of service in MODEM due to reachable assertion while processing SIB1 with invalid Bandwidth in Snapdragon Mobile
- CVE-2022-25671HIGHCVSS 7.5EG 7.52022-11-15
Denial of service in MODEM due to reachable assertion in Snapdragon Mobile
- CVE-2022-26446HIGHCVSS 7.5EG 7.52022-11-08
In Modem 4G RRC, there is a possible system crash due to improper input validation. This could lead to remote denial of service, when concatenating improper SIB12 (CMAS message), with no additional execution privileges needed. User interac…
- CVE-2022-34967HIGHCVSS 7.5EG 7.52022-08-03
The assertion `stmt->Dbc->FirstStmt' failed in MonetDB Database Server v11.43.13.
- CVE-2022-32082HIGHCVSS 7.5EG 7.52022-07-01
MariaDB v10.5 to v10.7 was discovered to contain an assertion failure at table->get_ref_count() == 0 in dict0dict.cc.
- CVE-2022-33024HIGHCVSS 7.5EG 7.52022-06-23
There is an Assertion `int decode_preR13_entities(BITCODE_RL, BITCODE_RL, unsigned int, BITCODE_RL, BITCODE_RL, Bit_Chain *, Dwg_Data *' failed at dwg2dxf: decode.c:5801 in libredwg v0.12.4.4608.
- CVE-2021-35073HIGHCVSS 7.5EG 7.52022-06-14
Possible assertion due to improper validation of rank restriction field in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
- CVE-2021-30340HIGHCVSS 7.5EG 7.52022-06-14
Reachable assertion due to improper validation of coreset in PDCCH configuration in SA mode in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
- CVE-2022-29228HIGHCVSS 7.5EG 7.52022-06-09
Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter would try to invoke the remaining filters in the chain after emitting a local response, which triggers an ASSERT() in newer versions and corrupts …
- CVE-2022-1183HIGHCVSS 7.5EG 7.52022-05-19
On vulnerable configurations, the named daemon may, in some circumstances, terminate with an assertion failure. Vulnerable configurations are those that include a reference to http within the listen-on statements in their named.conf. TLS i…
- CVE-2021-27500HIGHCVSS 7.5EG 7.52022-05-12
A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb 10, 2021 may result in a denial-of-service condition.
- CVE-2021-27498HIGHCVSS 7.5EG 7.52022-05-12
A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb 10, 2021 may result in a denial-of-service condition.
- CVE-2022-29339HIGHCVSS 7.5EG 7.52022-05-05
In GPAC 2.1-DEV-rev87-g053aae8-master, function BS_ReadByte() in utils/bitstream.c has a failed assertion, which causes a Denial of Service. This vulnerability was fixed in commit 9ea93a2.
- CVE-2022-27448HIGHCVSS 7.5EG 7.52022-04-14
There is an Assertion failure in MariaDB Server v10.9 and below via 'node->pcur->rel_pos == BTR_PCUR_ON' at /row/row0mysql.cc.
- CVE-2022-27382HIGHCVSS 7.5EG 7.52022-04-12
MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component Item_field::used_tables/update_depend_map_for_order.
- CVE-2021-30332HIGHCVSS 7.5EG 7.52022-04-01
Possible assertion due to improper validation of OTA configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
- CVE-2021-30329HIGHCVSS 7.5EG 7.52022-04-01
Possible assertion due to improper validation of TCI configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
- CVE-2021-30328HIGHCVSS 7.5EG 7.52022-04-01
Possible assertion due to improper validation of invalid NR CSI-IM resource configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
- CVE-2022-24777HIGHCVSS 7.5EG 7.52022-03-25
grpc-swift is the Swift language implementation of gRPC, a remote procedure call (RPC) framework. Prior to version 1.7.2, a grpc-swift server is vulnerable to a denial of service attack via a reachable assertion. This is due to incorrect l…
- CVE-2022-0635HIGHCVSS 7.5EG 7.52022-03-23
Versions affected: BIND 9.18.0 When a vulnerable version of named receives a series of specific queries, the named process will eventually terminate due to a failed assertion check.
- CVE-2022-0667HIGHCVSS 7.5EG 7.52022-03-22
When the vulnerability is triggered the BIND process will exit. BIND 9.18.0
- CVE-2021-30326HIGHCVSS 7.5EG 7.52022-02-11
Possible assertion due to improper size validation while processing the DownlinkPreemption IE in an RRC Reconfiguration/RRC Setup message in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdrago…
- CVE-2021-30353HIGHCVSS 7.5EG 7.52022-01-13
Improper validation of function pointer type with actual function signature can lead to assertion in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music…
- CVE-2021-30307HIGHCVSS 7.5EG 7.52022-01-13
Possible denial of service due to improper validation of DNS response when DNS client requests with PTR, NAPTR or SRV query type in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industria…
- CVE-2021-30287HIGHCVSS 7.5EG 7.52022-01-13
Possible assertion due to improper validation of symbols configured for PDCCH monitoring in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
- CVE-2021-30293HIGHCVSS 7.5EG 7.52022-01-03
Possible assertion due to lack of input validation in PUSCH configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT
- CVE-2021-30273HIGHCVSS 7.5EG 7.52022-01-03
Possible assertion due to improper handling of IPV6 packet with invalid length in destination options header in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables
- CVE-2021-45290HIGHCVSS 7.5EG 7.52021-12-21
A Denial of Service vulnerability exits in Binaryen 103 due to an assertion abort in wasm::handle_unreachable.
- CVE-2021-1982HIGHCVSS 7.5EG 7.52021-11-12
Possible denial of service scenario due to improper input validation of received NAS OTA message in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile
- CVE-2021-1971HIGHCVSS 7.5EG 7.52021-09-09
Possible assertion due to lack of physical layer state validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired…
- CVE-2021-36691HIGHCVSS 7.5EG 7.52021-08-30
libjxl v0.5.0 is affected by a Assertion failed issue in lib/jxl/image.cc jxl::PlaneBase::PlaneBase(). When encoding a malicous GIF file using cjxl, an attacker can trigger a denial of service.
- CVE-2021-38385HIGHCVSS 7.5EG 7.52021-08-30
Tor before 0.3.5.16, 0.4.5.10, and 0.4.6.7 mishandles the relationship between batch-signature verification and single-signature verification, leading to a remote assertion failure, aka TROVE-2021-007.
- CVE-2021-21778HIGHCVSS 7.5EG 7.52021-08-25
A denial of service vulnerability exists in the ASDU message processing functionality of MZ Automation GmbH lib60870.NET 2.2.0. A specially crafted network request can lead to loss of communications. An attacker can send an unauthenticated…
- CVE-2021-40083HIGHCVSS 7.5EG 7.52021-08-25
Knot Resolver before 5.3.2 is prone to an assertion failure, triggerable by a remote attacker in an edge case (NSEC3 with too many iterations used for a positive wildcard proof).
- CVE-2021-25218HIGHCVSS 7.5EG 7.52021-08-18
In BIND 9.16.19, 9.17.16. Also, version 9.16.19-S1 of BIND Supported Preview Edition When a vulnerable version of named receives a query under the circumstances described above, the named process will terminate due to a failed assertion ch…
- CVE-2021-38291HIGHCVSS 7.5EG 7.52021-08-12
FFmpeg version (git commit de8e6e67e7523e48bb27ac224a0b446df05e1640) suffers from a an assertion failure at src/libavutil/mathematics.c.
- CVE-2020-36420HIGHCVSS 7.5EG 7.52021-07-15
Polipo through 1.1.1, when NDEBUG is omitted, allows denial of service via a reachable assertion during parsing of a malformed Range header. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
- CVE-2021-1955HIGHCVSS 7.5EG 7.52021-07-13
Denial of service in SAP case due to improper handling of connections when association is rejected in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snap…
- CVE-2021-1953HIGHCVSS 7.5EG 7.52021-07-13
Improper handling of received malformed FTMR request frame can lead to reachable assertion while responding with FTM1 frame in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snap…
Map vulnerabilities like CWE-617 to your infrastructure
EchelonGraph correlates every CVE — across CWE-617 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →