CWE-755— Improper Handling of Exceptional Conditions
533 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-755page 3 of 11
- CVE-2019-6828HIGHCVSS 7.5EG 7.52019-09-17
A CWE-248: Uncaught Exception vulnerability exists Modicon M580 (firmware version prior to V2.90), Modicon M340 (firmware version prior to V3.10), Modicon Premium (all versions), and Modicon Quantum (all versions), which could cause a poss…
- CVE-2019-6829HIGHCVSS 7.5EG 7.52019-09-17
A CWE-248: Uncaught Exception vulnerability exists in Modicon M580 (firmware version prior to V2.90) and Modicon M340 (firmware version prior to V3.10), which could cause a possible denial of service when writing to specific memory address…
- CVE-2019-6830MEDIUMCVSS 5.9EG 5.92019-09-17
A CWE-248: Uncaught Exception vulnerability exists IN Modicon M580 all versions prior to V2.80, which could cause a possible denial of service when sending an appropriately timed HTTP request to the controller.
- CVE-2019-6841MEDIUMCVSS 4.9EG 4.92019-10-29
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 with firmware (version prior to V3.10), Modicon M340 (all firmware versions), and Modicon BMxCRA and 140CRA modules (all firmware versions), which …
- CVE-2019-6842MEDIUMCVSS 4.9EG 4.92019-10-29
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause a Denial of Service attack on the PLC when upgrading th…
- CVE-2019-6843MEDIUMCVSS 4.9EG 4.92019-10-29
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 with firmware (version prior to V3.10), Modicon M340 (all firmware versions), and Modicon BMxCRA and 140CRA modules (all firmware versions), which …
- CVE-2019-6844MEDIUMCVSS 4.9EG 4.92019-10-29
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause a Denial of Service atack on the PLC when upgrading the…
- CVE-2019-6847MEDIUMCVSS 4.9EG 4.92019-10-29
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause a Denial of Service attack on the FTP service when upgr…
- CVE-2019-6848HIGHCVSS 8.6EG 8.62019-10-29
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 CPU (BMEx58*) and Modicon M580 communication module (BMENOC0311, BMENOC0321) (see notification for version info), which could cause a Denial of Ser…
- CVE-2019-7474MEDIUMCVSS 6.5EG 6.52019-04-02
A vulnerability in SonicWall SonicOS and SonicOSv, allow authenticated read-only admin to leave the firewall in an unstable state by downloading certificate with specific extension. This vulnerability affected SonicOS Gen 5 version 5.9.1.1…
- CVE-2019-7846HIGHCVSS 7.5EG 7.52019-07-18
Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Improper error handling vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user.
- CVE-2019-8462HIGHCVSS 7.5EG 7.52019-10-02
In a rare scenario, Check Point R80.30 Security Gateway before JHF Take 50 managed by Check Point R80.30 Management crashes with a unique configuration of enhanced logging.
- CVE-2019-9009HIGHCVSS 7.5EG 7.52019-09-17
An issue was discovered in 3S-Smart CODESYS before 3.5.15.0 . Crafted network packets cause the Control Runtime to crash.
- CVE-2019-9510MEDIUMCVSS 5.3EG 5.32020-01-15
A vulnerability in Microsoft Windows 10 1803 and Windows Server 2019 and later systems can allow authenticated RDP-connected clients to gain access to user sessions without needing to interact with the Windows lock screen. Should a network…
- CVE-2019-9536MEDIUMCVSS 6.1EG 6.12019-11-22
Apple iPhone 3GS bootrom malloc implementation returns a non-NULL pointer when unable to allocate memory, aka 'alloc8'. An attacker with physical access to the device can install arbitrary firmware.
- CVE-2019-9628HIGHCVSS 7.5EG 7.52019-04-11
The XMLTooling library all versions prior to V3.0.4, provided with the OpenSAML and Shibboleth Service Provider software, contains an XML parsing class. Invalid data in the XML declaration causes an exception of a type that was not handled…
- CVE-2019-9735MEDIUMCVSS 6.5EG 6.52019-03-13
An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By setting a destination port in a security group rule along with a protocol that d…
- CVE-2020-0004MEDIUMCVSS 5.5EG 5.52020-01-08
In generateCrop of WallpaperManagerService.java, there is a possible sysui crash due to image exceeding maximum texture size. This could lead to local denial of service with no additional execution privileges needed. User interaction is no…
- CVE-2020-0108HIGHCVSS 7.8EG 7.82020-08-11
In postNotification of ServiceRecord.java, there is a possible bypass of foreground process restrictions due to an uncaught exception. This could lead to local escalation of privilege with no additional execution privileges needed. User in…
- CVE-2020-0247MEDIUMCVSS 5.5EG 5.52020-08-11
In Threshold::getHistogram of ImageProcessHelper.java, there is a possible crash loop due to an uncaught exception. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitati…
- CVE-2020-0318MEDIUMCVSS 5.5EG 5.52020-09-18
In the System UI, there is a possible system crash due to an uncaught exception. This could lead to local permanent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: …
- CVE-2020-0382LOWCVSS 2.3EG 2.32020-09-17
In RunInternal of dumpstate.cpp, there is a possible user consent bypass due to an uncaught exception. This could lead to local information disclosure of bug report data with System execution privileges needed. User interaction is not need…
- CVE-2020-0421HIGHCVSS 7.8EG 7.82020-10-14
In appendFormatV of String8.cpp, there is a possible out of bounds write due to incorrect error handling. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for e…
- CVE-2020-0443MEDIUMCVSS 5.5EG 5.52020-11-10
In LocaleList of LocaleList.java, there is a possible forced reboot due to an uncaught exception. This could lead to local denial of service requiring factory reset to restore with User execution privileges needed. User interaction is not …
- CVE-2020-0511MEDIUMCVSS 5.5EG 5.52020-03-12
Uncaught exception in system driver for Intel(R) Graphics Drivers before version 15.40.44.5107 may allow an authenticated user to potentially enable a denial of service via local access.
- CVE-2020-0512MEDIUMCVSS 5.5EG 5.52020-08-13
Uncaught exception in the system driver for some Intel(R) Graphics Drivers before version 15.33.50.5129 may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2020-10101HIGHCVSS 7.5EG 7.52020-03-05
An issue was discovered in Zammad 3.0 through 3.2. The WebSocket server crashes when messages in non-JSON format are sent by an attacker. The message format is not properly checked and parsing errors not handled. This leads to a crash of t…
- CVE-2020-10292HIGHCVSS 8.2EG 8.22020-11-06
Visual Components (owned by KUKA) is a robotic simulator that allows simulating factories and robots in order toimprove planning and decision-making processes. Visual Components software requires a special license which can beobtained from…
- CVE-2020-10604HIGHCVSS 7.5EG 7.52020-07-25
In OSIsoft PI System multiple products and versions, a remote, unauthenticated attacker could crash PI Network Manager service through specially crafted requests. This can result in blocking connections and queries to PI Data Archive.
- CVE-2020-1071MEDIUMCVSS 6.8EG 6.82020-05-21
An elevation of privilege vulnerability exists when Windows improperly handles errors tied to Remote Access Common Dialog, aka 'Windows Remote Access Common Dialog Elevation of Privilege Vulnerability'.
- CVE-2020-11012CRITICALCVSS 9.3EG 7.12020-04-23
MinIO versions before RELEASE.2020-04-23T00-58-49Z have an authentication bypass issue in the MinIO admin API. Given an admin access key, it is possible to perform admin API operations i.e. creating new service accounts for existing access…
- CVE-2020-11243HIGHCVSS 7.5EG 7.52021-04-07
RRC sends a connection establishment success to NAS even though connection setup validation returns failure and leads to denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile
- CVE-2020-11743MEDIUMCVSS 5.5EG 5.52020-04-14
An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a denial of service because of a bad error path in GNTTABOP_map_grant. Grant table operations are expected to return 0 for success, and a negative number for e…
- CVE-2020-11875HIGHCVSS 7.8EG 7.82020-04-17
An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10.0 (MTK chipsets) software. The MTK kernel does not properly implement exception handling, allowing an attacker to gain privileges. The LG ID is LVE-SMP-2000…
- CVE-2020-12105MEDIUMCVSS 5.9EG 5.92020-04-23
OpenConnect through 8.08 mishandles negative return values from X509_check_ function calls, which might assist attackers in performing man-in-the-middle attacks.
- CVE-2020-12888MEDIUMCVSS 5.3EG 5.32020-05-15
The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory space.
- CVE-2020-13410HIGHCVSS 7.5EG 7.52020-08-26
An issue was discovered in MoscaJS Aedes 0.42.0. lib/write.js does not properly consider exceptions during the writing of an invalid packet to a stream.
- CVE-2020-13463MEDIUMCVSS 4.6EG 4.62020-08-31
The flash memory readout protection in Apex Microelectronics APM32F103 devices allows physical attackers to extract firmware via the debug interface and exception handling.
- CVE-2020-13467MEDIUMCVSS 4.6EG 4.62020-08-31
The flash memory readout protection in China Key Systems & Integrated Circuit CKS32F103 devices allows physical attackers to extract firmware via the debug interface and exception handling.
- CVE-2020-13859CRITICALCVSS 9.8EG 9.82021-02-01
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. A format error in /etc/shadow, coupled with a logic bug in the LuCI - OpenWrt Configuration Interface framework, allows the undocumented system account mofidev to …
- CVE-2020-14270MEDIUMCVSS 5.3EG 5.32020-12-22
HCL Domino v9, v10, v11 is susceptible to an Information Disclosure vulnerability in XPages due to improper error handling of user input. An unauthenticated attacker could exploit this vulnerability to obtain information about the XPages s…
- CVE-2020-14304MEDIUMCVSS 4.4EG 4.42020-09-15
A memory disclosure flaw was found in the Linux kernel's ethernet drivers, in the way it read data from the EEPROM of the device. This flaw allows a local user to read uninitialized values from the kernel memory. The highest threat from th…
- CVE-2020-15117MEDIUMCVSS 6.5EG 6.52020-07-15
In Synergy before version 1.12.0, a Synergy server can be crashed by receiving a kMsgHelloBack packet with a client name length set to 0xffffffff (4294967295) if the servers memory is less than 4 GB. It was verified that this issue does no…
- CVE-2020-15223HIGHCVSS 8.0EG 8.02020-09-24
In ORY Fosite (the security first OAuth2 & OpenID Connect framework for Go) before version 0.34.0, the `TokenRevocationHandler` ignores errors coming from the storage. This can lead to unexpected 200 status codes indicating successful revo…
- CVE-2020-15566MEDIUMCVSS 6.5EG 6.52020-07-07
An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a host OS crash because of incorrect error handling in event-channel port allocation. The allocation of an event-channel port may fail for multiple reasons: (1…
- CVE-2020-15701MEDIUMCVSS 5.5EG 5.52020-08-06
An unhandled exception in check_ignored() in apport/report.py can be exploited by a local attacker to cause a denial of service. If the mtime attribute is a string value in apport-ignore.xml, it will trigger an unhandled exception, resulti…
- CVE-2020-16005HIGHCVSS 8.8EG 8.82020-11-03
Insufficient policy enforcement in ANGLE in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2020-1632HIGHCVSS 8.6EG 8.62020-04-15
In a certain condition, receipt of a specific BGP UPDATE message might cause Juniper Networks Junos OS and Junos OS Evolved devices to advertise an invalid BGP UPDATE message to other peers, causing the other peers to terminate the establi…
- CVE-2020-1639HIGHCVSS 7.5EG 7.52020-04-08
When an attacker sends a specific crafted Ethernet Operation, Administration, and Maintenance (Ethernet OAM) packet to a target device, it may improperly handle the incoming malformed data and fail to sanitize this incoming data resulting …
- CVE-2020-1643MEDIUMCVSS 5.5EG 5.52020-07-17
Execution of the "show ospf interface extensive" or "show ospf interface detail" CLI commands on a Juniper Networks device running Junos OS may cause the routing protocols process (RPD) to crash and restart if OSPF interface authentication…
Map vulnerabilities like CWE-755 to your infrastructure
EchelonGraph correlates every CVE — across CWE-755 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →