CWE-755— Improper Handling of Exceptional Conditions
The product does not handle or incorrectly handles an exceptional condition.— MITRE CWE catalog
634 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-755page 9 of 13
- CVE-2019-18668MEDIUMCVSS 6.5EG 6.52019-11-02
An issue was discovered in the Currency Switcher addon before 2.11.2 for WooCommerce if a user provides a currency that was not added by the administrator. In this case, even though the currency does not exist, it will be selected, but a p…
- CVE-2019-1376MEDIUMCVSS 6.5EG 6.52019-10-10
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when it improperly enforces permissions, aka 'SQL Server Management Studio Information Disclosure Vulnerability'. This CVE ID is unique from CV…
- CVE-2019-1313MEDIUMCVSS 6.5EG 6.52019-10-10
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when it improperly enforces permissions, aka 'SQL Server Management Studio Information Disclosure Vulnerability'. This CVE ID is unique from CV…
- CVE-2019-0051MEDIUMCVSS 6.5EG 6.52019-10-09
SSL-Proxy feature on SRX devices fails to handle a hardware resource limitation which can be exploited by remote SSL/TLS servers to crash the flowd daemon. Repeated crashes of the flowd daemon can result in an extended denial of service co…
- CVE-2019-12677MEDIUMCVSS 6.5EG 6.52019-10-02
A vulnerability in the Secure Sockets Layer (SSL) VPN feature of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition that prevents the creation of new …
- CVE-2019-7474MEDIUMCVSS 6.5EG 6.52019-04-02
A vulnerability in SonicWall SonicOS and SonicOSv, allow authenticated read-only admin to leave the firewall in an unstable state by downloading certificate with specific extension. This vulnerability affected SonicOS Gen 5 version 5.9.1.1…
- CVE-2019-9735MEDIUMCVSS 6.5EG 6.52019-03-13
An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By setting a destination port in a security group rule along with a protocol that d…
- CVE-2018-16781MEDIUMCVSS 6.5EG 6.52018-09-10
ffjpeg.dll in ffjpeg before 2018-08-22 allows remote attackers to cause a denial of service (FPE signal) via a progressive JPEG file that lacks an AC Huffman table.
- CVE-2018-1269MEDIUMCVSS 6.5EG 6.52018-06-06
Cloud Foundry Loggregator, versions 89.x prior to 89.5 or 96.x prior to 96.1 or 99.x prior to 99.1 or 101.x prior to 101.9 or 102.x prior to 102.2, does not handle errors thrown while constructing certain http requests. A remote authentica…
- CVE-2017-9658MEDIUMCVSS 6.5EG 6.52018-04-30
Certain 802.11 network management messages have been determined to invoke wireless access point blacklisting security defenses when not required, which can necessitate intervention by hospital staff to reset the device and reestablish a ne…
- CVE-2017-9657MEDIUMCVSS 6.5EG 6.52018-04-30
Under specific 802.11 network conditions, a partial re-association of the Philips IntelliVue MX40 Version B.06.18 WLAN monitor to the central monitoring station is possible. In this state, the central monitoring station can indicate the MX…
- CVE-2017-17044MEDIUMCVSS 6.5EG 6.52017-11-28
An issue was discovered in Xen through 4.9.x allowing HVM guest OS users to cause a denial of service (infinite loop and host OS hang) by leveraging the mishandling of Populate on Demand (PoD) errors.
- CVE-2022-34368MEDIUMCVSS 6.1EG 6.52022-08-30
Dell EMC NetWorker 19.2.1.x 19.3.x, 19.4.x, 19.5.x, 19.6.x and 19.7.0.0 contain an Improper Handling of Insufficient Permissions or Privileges vulnerability. Authenticated non admin user could exploit this vulnerability and gain access to …
- CVE-2025-27465MEDIUMCVSS 4.3EG 6.52025-07-16
Certain instructions need intercepting and emulating by Xen. In some cases Xen emulates the instruction by replaying it, using an executable stub. Some instructions may raise an exception, which is supposed to be handled gracefully. Cer…
- CVE-2022-3279MEDIUMCVSS 2.7EG 6.52022-10-17
An unhandled exception in job log parsing in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to prevent access to job logs
- CVE-2022-31152MEDIUMCVSS 6.4EG 6.42022-09-02
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. The Matrix specification specifies a list of [event authorization rules](https://spec.matrix.org/v1.2/rooms/v9/#authorization-rules) which mus…
- CVE-2021-25516MEDIUMCVSS 6.4EG 6.42021-12-08
An improper check or handling of exceptional conditions in Exynos baseband prior to SMR Dec-2021 Release 1 allows attackers to track locations.
- CVE-2024-36112MEDIUMCVSS 6.3EG 6.32024-05-28
Nautobot is a Network Source of Truth and Network Automation Platform. A user with permissions to view Dynamic Group records (`extras.view_dynamicgroup` permission) can use the Dynamic Group detail UI view (`/extras/dynamic-groups/<uuid>/`…
- CVE-2022-21820MEDIUMCVSS 6.3EG 6.32022-03-24
NVIDIA DCGM contains a vulnerability in nvhostengine, where a network user can cause detection of error conditions without action, which may lead to limited code execution, some denial of service, escalation of privileges, and limited impa…
- CVE-2026-49305MEDIUMCVSS 6.2EG 6.22026-08-17
Permission control vulnerability in the Wi-Fi enhancement module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2023-43686MEDIUMCVSS 6.2EG 6.22026-06-09
An issue was discovered in Malwarebytes 4.x and 5.x (and Nebula 2020-10-21 and later). A large number of Firefox preference files can cause the parser to ignore other browser configuration files, leading to a denial of service.
- CVE-2022-39912MEDIUMCVSS 6.2EG 6.22022-12-08
Improper handling of insufficient permissions vulnerability in setSecureFolderPolicy in PersonaManagerService prior to Android T(13) allows local attackers to set some setting value in Secure folder.
- CVE-2022-30727MEDIUMCVSS 6.2EG 6.22022-06-07
Improper handling of insufficient permissions vulnerability in addAppPackageNameToAllowList in PersonaManagerService prior to SMR Jun-2022 Release 1 allows local attackers to set some setting value in work space.
- CVE-2022-36874MEDIUMCVSS 5.9EG 6.22022-09-09
Improper Handling of Insufficient Permissions or Privileges vulnerability in Waterplugin prior to 2.2.11.22040751 allows attacker to access device IMEI and Serial number.
- CVE-2022-21814MEDIUMCVSS 6.1EG 6.12022-02-07
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel driver package, where improper handling of insufficient permissions or privileges may allow an unprivileged local user limited write access to protected memory, whi…
- CVE-2022-21813MEDIUMCVSS 6.1EG 6.12022-02-07
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel driver, where improper handling of insufficient permissions or privileges may allow an unprivileged local user limited write access to protected memory, which can l…
- CVE-2019-9536MEDIUMCVSS 6.1EG 6.12019-11-22
Apple iPhone 3GS bootrom malloc implementation returns a non-NULL pointer when unable to allocate memory, aka 'alloc8'. An attacker with physical access to the device can install arbitrary firmware.
- CVE-2022-25917MEDIUMCVSS 6.0EG 6.02022-11-11
Uncaught exception in the firmware for some Intel(R) Server Board M50CYP Family before version R01.01.0005 may allow a privileged user to potentially enable a denial of service via local access.
- CVE-2020-25602MEDIUMCVSS 6.0EG 6.02020-09-23
An issue was discovered in Xen through 4.14.x. An x86 PV guest can trigger a host OS crash when handling guest access to MSR_MISC_ENABLE. When a guest accesses certain Model Specific Registers, Xen first reads the value from hardware to us…
- CVE-2023-5090MEDIUMCVSS 5.5EG 6.02023-11-06
A flaw was found in KVM. An improper check in svm_set_x2apic_msr_interception() may allow direct access to host x2apic msrs when the guest resets its apic, potentially leading to a denial of service condition.
- CVE-2026-55577MEDIUMCVSS 5.9EG 5.92026-07-01
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, a heap buffer overflow occurs in the MVG decoder that could result in an out of bounds write when proc…
- CVE-2026-42545MEDIUMCVSS 5.9EG 5.92026-05-12
Granian is a Rust HTTP server for Python applications. From 0.2.0 to 2.7.4, Granian aborts a worker process if a WSGI application returns an invalid HTTP response header name or value. The WSGI response conversion path uses .unwrap() on bo…
- CVE-2025-52948MEDIUMCVSS 5.9EG 5.92025-07-11
An Improper Handling of Exceptional Conditions vulnerability in Berkeley Packet Filter (BPF) processing of Juniper Networks Junos OS allows an attacker, in rare cases, sending specific, unknown traffic patterns to cause the FPC and system …
- CVE-2024-21585MEDIUMCVSS 5.9EG 5.92024-01-12
An Improper Handling of Exceptional Conditions vulnerability in BGP session processing of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker, using specific timing outside the attacker's contro…
- CVE-2023-50019MEDIUMCVSS 5.9EG 5.92024-01-02
An issue was discovered in open5gs v2.6.6. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handling of Nudm_UECM_Registration response.
- CVE-2023-41317MEDIUMCVSS 5.9EG 5.92023-09-05
The Apollo Router is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Affected versions are subject to a Denial-of-Service (DoS) type vulnerability which causes the …
- CVE-2022-39886MEDIUMCVSS 5.9EG 5.92022-11-09
Improper access control vulnerability in IpcRxServiceModeBigDataInfo in RIL prior to SMR Nov-2022 Release 1 allows local attacker to access Device information.
- CVE-2022-39885MEDIUMCVSS 5.9EG 5.92022-11-09
Improper access control vulnerability in BootCompletedReceiver_CMCC in DeviceManagement prior to SMR Nov-2022 Release 1 allows local attacker to access to Device information.
- CVE-2022-39872MEDIUMCVSS 5.9EG 5.92022-10-07
Improper restriction of broadcasting Intent in ShareLive prior to version 13.2.03.5 leaks MAC address of the connected Bluetooth device.
- CVE-2022-0023MEDIUMCVSS 5.9EG 5.92022-04-13
An improper handling of exceptional conditions vulnerability exists in the DNS proxy feature of Palo Alto Networks PAN-OS software that enables a meddler-in-the-middle (MITM) to send specifically crafted traffic to the firewall that causes…
- CVE-2021-0264MEDIUMCVSS 5.9EG 5.92021-04-22
A vulnerability in the processing of traffic matching a firewall filter containing a syslog action in Juniper Networks Junos OS on MX Series with MPC10/MPC11 cards installed, PTX10003 and PTX10008 Series devices, will cause the line card t…
- CVE-2020-12105MEDIUMCVSS 5.9EG 5.92020-04-23
OpenConnect through 8.08 mishandles negative return values from X509_check_ function calls, which might assist attackers in performing man-in-the-middle attacks.
- CVE-2013-4584MEDIUMCVSS 5.9EG 5.92019-11-15
Perdition before 2.2 may have weak security when handling outbound connections, caused by an error in the STARTTLS IMAP and POP server. ssl_outgoing_ciphers not being applied to STARTTLS connections
- CVE-2019-6830MEDIUMCVSS 5.9EG 5.92019-09-17
A CWE-248: Uncaught Exception vulnerability exists IN Modicon M580 all versions prior to V2.80, which could cause a possible denial of service when sending an appropriately timed HTTP request to the controller.
- CVE-2018-0272MEDIUMCVSS 5.9EG 5.92018-04-19
A vulnerability in the Secure Sockets Layer (SSL) Engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper error handling w…
- CVE-2017-3887MEDIUMCVSS 5.9EG 5.92017-04-07
A vulnerability in the detection engine that handles Secure Sockets Layer (SSL) packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition because the Snort proc…
- CVE-2024-52529MEDIUMCVSS 5.8EG 5.82024-11-25
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For users with the following configuration: 1. An allow policy that selects a Layer 3 destination and a port range `AND` 2. A Layer 7 allow policy t…
- CVE-2024-47489MEDIUMCVSS 5.8EG 5.82024-10-11
An Improper Handling of Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of the Juniper Networks Junos OS Evolved on ACX Series devices allows an unauthenticated, network based attacker sending specific transit pr…
- CVE-2019-1691MEDIUMCVSS 5.8EG 5.82019-02-21
A vulnerability in the detection engine of Cisco Firepower Threat Defense Software could allow an unauthenticated, remote attacker to cause the unexpected restart of the SNORT detection engine, resulting in a denial of service (DoS) condit…
- CVE-2023-25561MEDIUMCVSS 5.7EG 5.72023-02-11
DataHub is an open-source metadata platform. In the event a system is using Java Authentication and Authorization Service (JAAS) authentication and that system is given a configuration which contains an error, the authentication for the sy…
Map vulnerabilities like CWE-755 to your infrastructure
EchelonGraph correlates every CVE — across CWE-755 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →