CWE-755— Improper Handling of Exceptional Conditions
The product does not handle or incorrectly handles an exceptional condition.— MITRE CWE catalog
634 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-755page 8 of 13
- CVE-2026-0203MEDIUMCVSS 6.5EG 6.52026-01-15
An Improper Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS allows an unauthenticated, network-adjacent attacker sending a specifically malformed ICMP packet to cause an FPC to crash and r…
- CVE-2025-53702MEDIUMCVSS 6.5EG 6.52025-10-23
Vilar VS-IPC1002 IP cameras are vulnerable to DoS (Denial-of-Service) attacks. An unauthenticated attacker on the same local network might send a crafted request to /cgi-bin/action endpoint and render the device completely unresponsive. A…
- CVE-2025-8008MEDIUMCVSS 6.5EG 6.52025-09-09
A security issue exists in the protected mode of EN4TR devices, where sending specifically crafted messages during a Forward Close operation can cause the device to crash.
- CVE-2025-52947MEDIUMCVSS 6.5EG 6.52025-07-11
An Improper Handling of Exceptional Conditions vulnerability in route processing of Juniper Networks Junos OS on specific end-of-life (EOL) ACX Series platforms allows an attacker to crash the Forwarding Engine Board (FEB) by flapping an i…
- CVE-2025-21602MEDIUMCVSS 6.5EG 6.52025-01-09
An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker sending a specific BGP update packet to cause r…
- CVE-2024-51766MEDIUMCVSS 6.5EG 6.52024-11-22
A potential security vulnerability has been identified in the HPE NonStop DISK UTIL (T9208) product. This vulnerability could be exploited to cause a denial of service (DoS) to NonStop server. It exists in all prior DISK UTIL product versi…
- CVE-2024-39526MEDIUMCVSS 6.5EG 6.52024-10-11
An Improper Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS on MX Series with MPC10/MPC11/LC9600 line cards, EX9200 with EX9200-15C lines cards, MX304 devices, and Juniper Networks Junos O…
- CVE-2024-39541MEDIUMCVSS 6.5EG 6.52024-07-11
An Improper Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS). When conf…
- CVE-2024-39560MEDIUMCVSS 6.5EG 6.52024-07-10
An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a logically adjacent downstream RSVP neighbor to cause kernel memory exhaustion, lea…
- CVE-2023-50212MEDIUMCVSS 6.5EG 6.52024-05-03
D-Link G416 httpd Improper Handling of Exceptional Conditions Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Link G416 routers. Au…
- CVE-2024-30380MEDIUMCVSS 6.5EG 6.52024-04-16
An Improper Handling of Exceptional Conditions vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an adjacent unauthenticated attacker to cause a Denial of Service (DoS), which causes the l2cpd process to crash by sendi…
- CVE-2024-27662MEDIUMCVSS 6.5EG 6.52024-02-29
D-Link DIR-823G A1V1.0.2B05 was discovered to contain a Null-pointer dereferences in sub_4110f4(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
- CVE-2024-21587MEDIUMCVSS 6.5EG 6.52024-01-12
An Improper Handling of Exceptional Conditions vulnerability in the broadband edge subscriber management daemon (bbe-smgd) of Juniper Networks Junos OS on MX Series allows an attacker directly connected to the vulnerable system who repeat…
- CVE-2023-36842MEDIUMCVSS 6.5EG 6.52024-01-12
An Improper Check for Unusual or Exceptional Conditions vulnerability in Juniper DHCP Daemon (jdhcpd) of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker to cause the jdhcpd to consume all the CPU cycles resulting in…
- CVE-2023-25644MEDIUMCVSS 6.5EG 6.52023-12-14
There is a denial of service vulnerability in some ZTE mobile internet products. Due to insufficient validation of Web interface parameter, an attacker could use the vulnerability to perform a denial of service attack.
- CVE-2023-43087MEDIUMCVSS 6.5EG 6.52023-11-02
Dell PowerScale OneFS 8.2.x, 9.0.0.x-9.5.0.x contains an improper handling of insufficient permissions. A low privileged remote attacker could potentially exploit this vulnerability to cause information disclosure.
- CVE-2023-45820MEDIUMCVSS 6.5EG 6.52023-10-19
Directus is a real-time API and App dashboard for managing SQL database content. In affected versions any Directus installation that has websockets enabled can be crashed if the websocket server receives an invalid frame. A malicious user …
- CVE-2023-28768MEDIUMCVSS 6.5EG 6.52023-08-14
Improper frame handling in the Zyxel XGS2220-30 firmware version V4.80(ABXN.1), XMG1930-30 firmware version V4.80(ACAR.1), and XS1930-10 firmware version V4.80(ABQE.1) could allow an unauthenticated LAN-based attacker to cause denial-of-s…
- CVE-2023-0204MEDIUMCVSS 6.5EG 6.52023-04-22
NVIDIA ConnectX-5, ConnectX-6, and ConnectX6-DX contain a vulnerability in the NIC firmware, where an unprivileged user can cause improper handling of exceptional conditions, which may lead to denial of service.
- CVE-2023-28970MEDIUMCVSS 6.5EG 6.52023-04-17
An Improper Check or Handling of Exceptional Conditions vulnerability in packet processing on the network interfaces of Juniper Networks Junos OS on JRR200 route reflector appliances allows an adjacent, network-based attacker sending a spe…
- CVE-2023-27595MEDIUMCVSS 6.5EG 6.52023-03-17
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In version 1.13.0, when Cilium is started, there is a short period when Cilium eBPF programs are not attached to the host. During this period, the h…
- CVE-2023-26479MEDIUMCVSS 6.5EG 6.52023-03-02
XWiki Platform is a generic wiki platform. Starting in version 6.0, users with write rights can insert well-formed content that is not handled well by the parser. As a consequence, some pages becomes unusable, including the user index (if …
- CVE-2022-47933MEDIUMCVSS 6.5EG 6.52022-12-24
Brave Browser before 1.42.51 allowed a remote attacker to cause a denial of service via a crafted HTML file that references the IPFS scheme. This vulnerability is caused by an uncaught exception in the function ipfs::OnBeforeURLRequest_IPF…
- CVE-2022-36031MEDIUMCVSS 6.5EG 6.52022-08-19
Directus is a free and open-source data platform for headless content management. The Directus process can be aborted by having an authorized user update the `filename_disk` value to a folder and accessing that file through the `/assets` e…
- CVE-2022-20253MEDIUMCVSS 6.5EG 6.52022-08-12
In Bluetooth, there is a possible cleanup failure due to an uncaught exception. This could lead to remote denial of service in Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Produc…
- CVE-2022-22202MEDIUMCVSS 6.5EG 6.52022-07-20
An Improper Handling of Exceptional Conditions vulnerability on specific PTX Series devices, including the PTX1000, PTX3000 (NextGen), PTX5000, PTX10002-60C, PTX10008, and PTX10016 Series, in Juniper Networks Junos OS allows an unauthentic…
- CVE-2022-29617MEDIUMCVSS 6.5EG 6.52022-06-06
Due to improper error handling an authenticated user can crash CLA assistant instance. This could impact the availability of the application.
- CVE-2022-23625MEDIUMCVSS 6.5EG 6.52022-03-11
Wire-ios is a messaging application using the wire protocol on apple's ios platform. In versions prior to 3.95 malformed resource identifiers may render the iOS Wire Client completely unusable by causing it to repeatedly crash on launch. T…
- CVE-2022-20057MEDIUMCVSS 6.5EG 6.52022-03-10
In btif, there is a possible memory corruption due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06271186; …
- CVE-2022-22290MEDIUMCVSS 6.5EG 6.52022-01-14
Incorrect download source UI in Downloads in Samsung Internet prior to 16.0.6.23 allows attackers to perform domain spoofing via a crafted HTML page.
- CVE-2021-0969MEDIUMCVSS 6.5EG 6.52021-12-15
In getTitle of AccessPoint.java, there is a possible unhandled exception due to a missing null check. This could lead to remote denial of service if a proximal Wi-Fi AP provides invalid information with no additional execution privileges n…
- CVE-2021-0297MEDIUMCVSS 6.5EG 6.52021-10-19
A vulnerability in the processing of TCP MD5 authentication in Juniper Networks Junos OS Evolved may allow a BGP or LDP session configured with MD5 authentication to succeed, even if the peer does not have TCP MD5 authentication enabled. T…
- CVE-2021-23429MEDIUMCVSS 6.5EG 6.52021-08-24
All versions of package transpile are vulnerable to Denial of Service (DoS) due to a lack of input sanitization or whitelisting, coupled with improper exception handling in the .to() function.
- CVE-2021-22922MEDIUMCVSS 6.5EG 6.52021-08-05
When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided in the metalink XML file.The metalink XML file points out to the client how to get the same contentfrom a set of differ…
- CVE-2021-0290MEDIUMCVSS 6.5EG 6.52021-07-15
Improper Handling of Exceptional Conditions in Ethernet interface frame processing of Juniper Networks Junos OS allows an attacker to send specially crafted frames over the local Ethernet segment, causing the interface to go into a down st…
- CVE-2021-21439MEDIUMCVSS 6.5EG 6.52021-06-14
DoS attack can be performed when an email contains specially designed URL in the body. It can lead to the high CPU usage and cause low quality of service, or in extreme case bring the system to a halt. This issue affects: OTRS AG ((OTRS)) …
- CVE-2021-30046MEDIUMCVSS 6.5EG 6.52021-04-06
VIGRA Computer Vision Library Version-1-11-1 contains a segmentation fault vulnerability in the impex.hxx read_image_band() function, in which a crafted file can cause a denial of service.
- CVE-2021-20642MEDIUMCVSS 6.5EG 6.52021-02-12
Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/RS allows a remote attacker to cause a denial-of-service (DoS) condition by sending a specially crafted URL.
- CVE-2021-20637MEDIUMCVSS 6.5EG 6.52021-02-12
Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/PR5B allows a remote attacker to cause a denial-of-service (DoS) condition by sending a specially crafted URL.
- CVE-2020-7926MEDIUMCVSS 6.5EG 6.52020-11-23
A user authorized to perform database queries may cause denial of service by issuing a specially crafted query which violates an invariant in the server selection subsystem. This issue affects MongoDB Server v4.4 versions prior to 4.4.1. V…
- CVE-2020-1681MEDIUMCVSS 6.5EG 6.52020-10-16
Receipt of a specifically malformed NDP packet sent from the local area network (LAN) to a device running Juniper Networks Junos OS Evolved can cause the ndp process to crash, resulting in a Denial of Service (DoS). The process automatical…
- CVE-2020-25597MEDIUMCVSS 6.5EG 6.52020-09-23
An issue was discovered in Xen through 4.14.x. There is mishandling of the constraint that once-valid event channels may not turn invalid. Logic in the handling of event channel operations in Xen assumes that an event channel, once valid, …
- CVE-2020-7923MEDIUMCVSS 6.5EG 6.52020-08-21
A user authorized to perform database queries may cause denial of service by issuing specially crafted queries, which violate an invariant in the query subsystem's support for geoNear. This issue affects MongoDB Server v4.4 versions prior …
- CVE-2020-15117MEDIUMCVSS 6.5EG 6.52020-07-15
In Synergy before version 1.12.0, a Synergy server can be crashed by receiving a kMsgHelloBack packet with a client name length set to 0xffffffff (4294967295) if the servers memory is less than 4 GB. It was verified that this issue does no…
- CVE-2020-15566MEDIUMCVSS 6.5EG 6.52020-07-07
An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a host OS crash because of incorrect error handling in event-channel port allocation. The allocation of an event-channel port may fail for multiple reasons: (1…
- CVE-2016-11034MEDIUMCVSS 6.5EG 6.52020-04-07
An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) software. The decode function in Qjpeg in Qt 5.7 allows attackers to trigger a system crash via a malformed image. The Samsung ID is SVE-2016-6560 (October 2016).
- CVE-2019-13683MEDIUMCVSS 6.5EG 6.52019-11-25
Insufficient policy enforcement in developer tools in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- CVE-2019-0144MEDIUMCVSS 6.5EG 6.52019-11-14
Unhandled exception in firmware for Intel(R) Ethernet 700 Series Controllers before version 7.0 may allow an authenticated user to potentially enable a denial of service via local access.
- CVE-2011-2336MEDIUMCVSS 6.5EG 6.52019-11-07
An issue exists in WebKit in Google Chrome before Blink M12. when clearing lists in AnimationControllerPrivate that signal when a hardware animation starts.
- CVE-2011-2807MEDIUMCVSS 6.5EG 6.52019-11-07
Incorrect handling of timer information in Timer.cpp in WebKit in Google Chrome before Blink M13.
Map vulnerabilities like CWE-755 to your infrastructure
EchelonGraph correlates every CVE — across CWE-755 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →