CWE-755— Improper Handling of Exceptional Conditions
The product does not handle or incorrectly handles an exceptional condition.— MITRE CWE catalog
634 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-755page 4 of 13
- CVE-2025-66622HIGHCVSS 7.5EG 7.52025-12-09
matrix-sdk-base is the base component to build a Matrix client library. Versions 0.14.1 and prior are unable to handle responses that include custom m.room.join_rules values due to a serialization bug. This can be exploited to cause a deni…
- CVE-2025-59530HIGHCVSS 7.5EG 7.52025-10-10
quic-go is an implementation of the QUIC protocol in Go. In versions prior to 0.49.0, 0.54.1, and 0.55.0, a misbehaving or malicious server can cause a denial-of-service (DoS) attack on the quic-go client by triggering an assertion failure…
- CVE-2025-58047HIGHCVSS 7.5EG 7.52025-08-28
Volto is a React based frontend for the Plone Content Management System. In versions from 19.0.0-alpha.1 to before 19.0.0-alpha.4, 18.0.0 to before 18.24.0, 17.0.0 to before 17.22.1, and prior to 16.34.0, an anonymous user could cause the …
- CVE-2025-43864HIGHCVSS 7.5EG 7.52025-04-25
React Router is a router for React. Starting in version 7.2.0 and prior to version 7.5.2, it is possible to force an application to switch to SPA mode by adding a header to the request. If the application uses SSR and is forced to switch t…
- CVE-2024-11864HIGHCVSS 7.5EG 7.52025-01-14
Specifically crafted SCMI messages sent to an SCP running SCP-Firmware release versions up to and including 2.15.0 may lead to a Usage Fault and crash the SCP
- CVE-2024-8376HIGHCVSS 7.5EG 7.52024-10-11
In Eclipse Mosquitto up to version 2.0.18a, an attacker can achieve memory leaking, segmentation fault or heap-use-after-free by sending specific sequences of "CONNECT", "DISCONNECT", "SUBSCRIBE", "UNSUBSCRIBE" and "PUBLISH" packets.
- CVE-2024-39547HIGHCVSS 7.5EG 7.52024-10-11
An Improper Handling of Exceptional Conditions vulnerability in the rpd-server of Juniper Networks Junos OS and Junos OS Evolved within cRPD allows an unauthenticated network-based attacker sending crafted TCP traffic to the routing engin…
- CVE-2024-39525HIGHCVSS 7.5EG 7.52024-10-09
An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker sending a specific BGP packet to cause rp…
- CVE-2024-6594HIGHCVSS 7.5EG 7.52024-09-25
Improper Handling of Exceptional Conditions vulnerability in the WatchGuard Single Sign-On Client on Windows causes the client to crash while handling malformed commands. An attacker with network access to the client could create a denial …
- CVE-2024-45038HIGHCVSS 7.5EG 7.52024-08-27
Meshtastic device firmware is a firmware for meshtastic devices to run an open source, off-grid, decentralized, mesh network built to run on affordable, low-power devices. Meshtastic device firmware is subject to a denial of serivce vulner…
- CVE-2024-39552HIGHCVSS 7.5EG 7.52024-07-11
An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows a network based, unauthenticated attacker to cause the RPD process to crash leading …
- CVE-2024-39555HIGHCVSS 7.5EG 7.52024-07-10
An Improper Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker sending a specific malformed BGP update message to cause the session to …
- CVE-2024-34750HIGHCVSS 7.5EG 7.52024-07-03
Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive HTTP headers correctly. This led to a miscountin…
- CVE-2024-36730HIGHCVSS 7.5EG 7.52024-06-06
Improper input validation in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputting negative values into the oneflow.zeros/ones parameter.
- CVE-2024-32652HIGHCVSS 7.5EG 7.52024-04-19
The adapter @hono/node-server allows you to run your Hono application on Node.js. Prior to 1.10.1, the application hangs when receiving a Host header with a value that `@hono/node-server` can't handle well. Invalid values are those that ca…
- CVE-2024-28869HIGHCVSS 7.5EG 7.52024-04-12
Traefik is an HTTP reverse proxy and load balancer. In affected versions sending a GET request to any Traefik endpoint with the "Content-length" request header results in an indefinite hang with the default configuration. This vulnerabilit…
- CVE-2024-30382HIGHCVSS 7.5EG 7.52024-04-12
An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated attacker to send a specific routing update, causing…
- CVE-2024-23325HIGHCVSS 7.5EG 7.52024-02-09
Envoy is a high-performance edge/middle/service proxy. Envoy crashes in Proxy protocol when using an address type that isn’t supported by the OS. Envoy is susceptible to crashing on a host with IPv6 disabled and a listener config with pr…
- CVE-2021-42146HIGHCVSS 7.5EG 7.52024-01-24
An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. DTLS servers allow remote attackers to reuse the same epoch number within two times the TCP maximum segment lifetime, which is prohibited in RFC6347. This vulner…
- CVE-2021-42145HIGHCVSS 7.5EG 7.52024-01-24
An assertion failure discovered in in check_certificate_request() in Contiki-NG tinyDTLS through master branch 53a0d97 allows attackers to cause a denial of service.
- CVE-2023-34348HIGHCVSS 7.5EG 7.52024-01-18
AVEVA PI Server versions 2023 and 2018 SP3 P05 and prior contain a vulnerability that could allow an unauthenticated user to remotely crash the PI Message Subsystem of a PI Server, resulting in a denial-of-service condition.
- CVE-2023-52075HIGHCVSS 7.5EG 7.52023-12-27
ReVanced API proxies requests needed to feed the ReVanced Manager and website with data. Up to and including commit 71f81f7f20cd26fd707335bca9838fa3e7df20d2, ReVanced API lacks error caching causing rate limit to be triggered thus increasi…
- CVE-2023-50728HIGHCVSS 7.5EG 7.52023-12-15
octokit/webhooks is a GitHub webhook events toolset for Node.js. Starting in 9.26.0 and prior to 9.26.3, 10.9.2, 11.1.2, and 12.0.4, there is a problem caused by an issue with error handling in the @octokit/webhooks library because the err…
- CVE-2023-41151HIGHCVSS 7.5EG 7.52023-12-14
An uncaught exception issue discovered in Softing OPC UA C++ SDK before 6.30 for Windows operating system may cause the application to crash when the server wants to send an error packet, while socket is blocked on writing.
- CVE-2023-42578HIGHCVSS 7.5EG 7.52023-12-05
Improper handling of insufficient permissions or privileges vulnerability in Samsung Data Store prior to version 5.2.00.7 allows remote attackers to access location information without permission.
- CVE-2023-46673HIGHCVSS 7.5EG 7.52023-11-22
It was identified that malformed scripts used in the script processor of an Ingest Pipeline could cause an Elasticsearch node to crash when calling the Simulate Pipeline API.
- CVE-2023-41378HIGHCVSS 7.5EG 7.52023-11-06
In certain conditions for Calico Typha (v3.26.2, v3.25.1 and below), and Calico Enterprise Typha (v3.17.1, v3.16.3, v3.15.3 and below), a client TLS handshake can block the Calico Typha server indefinitely, resulting in denial of service. …
- CVE-2023-5824HIGHCVSS 7.5EG 7.52023-11-03
A flaw was found in Squid. The limits applied for validation of HTTP response headers are applied before caching. However, Squid may grow a cached HTTP response header beyond the configured maximum size, causing a stall or crash of the wor…
- CVE-2023-44186HIGHCVSS 7.5EG 7.52023-10-11
An Improper Handling of Exceptional Conditions vulnerability in AS PATH processing of Juniper Networks Junos OS and Junos OS Evolved allows an attacker to send a BGP update message with an AS PATH containing a large number of 4-byte ASes,…
- CVE-2023-41085HIGHCVSS 7.5EG 7.52023-10-10
When IPSec is configured on a Virtual Server, undisclosed traffic can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- CVE-2023-44488HIGHCVSS 7.5EG 7.52023-09-30
VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding.
- CVE-2023-4540HIGHCVSS 7.5EG 7.52023-09-05
Improper Handling of Exceptional Conditions vulnerability in Daurnimator lua-http library allows Excessive Allocation and a denial of service (DoS) attack to be executed by sending a properly crafted request to the server. Such a request …
- CVE-2023-33370HIGHCVSS 7.5EG 7.52023-08-03
An uncaught exception vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing attackers to cause the main web server of IDSecure to fault and crash, causing a denial of service.
- CVE-2023-36832HIGHCVSS 7.5EG 7.52023-07-14
An Improper Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS on MX Series allows an unauthenticated network-based attacker to send specific packets to an Aggregated Multiservices (AMS) inte…
- CVE-2023-1695HIGHCVSS 7.5EG 7.52023-07-06
Vulnerability of failures to capture exceptions in the communication framework. Successful exploitation of this vulnerability may cause features to perform abnormally.
- CVE-2023-20692HIGHCVSS 7.5EG 7.52023-07-04
In wlan firmware, there is possible system crash due to an uncaught exception. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07664…
- CVE-2023-24510HIGHCVSS 7.5EG 7.52023-06-05
On the affected platforms running EOS, a malformed DHCP packet might cause the DHCP relay agent to restart.
- CVE-2022-27978HIGHCVSS 7.5EG 7.52023-04-26
Tooljet v1.6 does not properly handle missing values in the API, allowing attackers to arbitrarily reset passwords via a crafted HTTP request.
- CVE-2023-23837HIGHCVSS 7.5EG 7.52023-04-25
No exception handling vulnerability which revealed sensitive or excessive information to users.
- CVE-2021-38363HIGHCVSS 7.5EG 7.52023-04-20
An issue was discovered in ONOS 2.5.1. In IntentManager, the install-requested intent (which causes an exception) remains in pendingMap (in memory) forever. Deletion is possible neither by a user nor by the intermittent Intent Cleanup proc…
- CVE-2023-28840HIGHCVSS 7.5EG 7.52023-04-04
Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (`dockerd`), which is developed as mob…
- CVE-2023-22391HIGHCVSS 7.5EG 7.52023-01-13
A vulnerability in class-of-service (CoS) queue management in Juniper Networks Junos OS on the ACX2K Series devices allows an unauthenticated network-based attacker to cause a Denial of Service (DoS). Specific packets are being incorrectly…
- CVE-2022-23496HIGHCVSS 7.5EG 7.52022-12-08
Yet Another UserAgent Analyzer (Yauaa) is a java library that tries to parse and analyze the useragent string and extract as many relevant attributes as possible. Applications using the Client Hints analysis feature introduced with 7.0.0 …
- CVE-2022-23495HIGHCVSS 7.5EG 7.52022-12-08
go-merkledag implements the 'DAGService' interface and adds two ipld node types, Protobuf and Raw for the ipfs project. A `ProtoNode` may be modified in such a way as to cause various encode errors which will trigger a panic on common meth…
- CVE-2022-44030HIGHCVSS 7.5EG 7.52022-12-06
Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permission checks. Depending on the configuration, this may require login as a registered user.
- CVE-2022-20854HIGHCVSS 7.5EG 7.52022-11-15
A vulnerability in the processing of SSH connections of Cisco Firepower Management Center (FMC) and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition …
- CVE-2022-35268HIGHCVSS 7.5EG 7.52022-10-25
A denial of service vulnerability exists in the web_server hashFirst functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network request can lead to denial of service. An attacker can send a sequence of requests to trigge…
- CVE-2022-39271HIGHCVSS 7.5EG 7.52022-10-11
Traefik (pronounced traffic) is a modern HTTP reverse proxy and load balancer that assists in deploying microservices. There is a potential vulnerability in Traefik managing HTTP/2 connections. A closing HTTP/2 server connection could hang…
- CVE-2022-32264HIGHCVSS 7.5EG 7.52022-09-06
sys/netinet/tcp_timer.h in FreeBSD before 7.0 contains a denial-of-service (DoS) vulnerability due to improper handling of TSopt on TCP connections. NOTE: This vulnerability only affects products that are no longer supported by the maintai…
- CVE-2022-36923HIGHCVSS 7.5EG 7.52022-08-10
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 2022-07-27 through 2022-07-28 (125657, 126002, 126104, and 126118) allow unauthenticated att…
Map vulnerabilities like CWE-755 to your infrastructure
EchelonGraph correlates every CVE — across CWE-755 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →