TensorFlow is an open source platform for machine learning. In affected versions if `tf.summary.create_file_writer` is c
A reachable assertion vulnerability in Trend Micro Apex One could allow an attacker to crash the program on affected ins
A denial-of-service (DoS) vulnerability was discovered in the web user interface of F-Secure Internet Gatekeeper. The vu
Tor before 0.4.5.7 allows a remote attacker to cause Tor directory authorities to exit with an assertion failure, aka TR
A flaw was found in the Red Hat Ceph Storage RGW in versions before 14.2.21. When processing a GET Request for a swift U
Truncated L2CAP K-frame causes assertion failure. Zephyr versions >= 2.4.0, >= v.2.50 contain Improper Handling of Lengt
Varnish varnish-modules before 0.17.1 allows remote attackers to cause a denial of service (daemon restart) in some conf
A flaw was found in libnbd 1.7.3. An assertion failure in nbd_unlocked_opt_go in ilb/opt.c may lead to denial of service
TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a denial of service via a
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service by cont
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service by expl
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service by expl
TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service by expl
TensorFlow is an end-to-end open source platform for machine learning. Due to lack of validation in `tf.raw_ops.SparseDe
Valid deauth/disassoc frames is dropped in case if RMF is enabled and some rouge peer keep on sending rogue deauth/disas
stb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_int.
stb stb_truetype.h through 1.22 has an assertion failure in stbtt__buf_seek.
stb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_get_index.
Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory
Mozilla developers reported memory safety bugs present in Firefox for Android 79. Some of these bugs showed evidence of
Stage-2 fault will occur while writing to an ION system allocation which has been assigned to non-HLOS memory which is n
lldpd before 0.8.0 allows remote attackers to cause a denial of service (assertion failure and daemon crash) via a malfo
An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occu
Error occurs While extracting the ipv6_header having an invalid length due to lack of length check in Snapdragon Auto, S
Active command timeout since WM status change cmd is not removed from active queue if peer sends multiple deauth frames.
Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the
JerryScript 2.2.0 allows attackers to cause a denial of service (assertion failure) because a property key query for a P
parser/js/js-scanner.c in JerryScript 2.2.0 mishandles errors during certain out-of-memory conditions, as demonstrated b
Firmware will hit assert in WLAN firmware If encrypted data length in FILS IE of reassoc response is more than 528 bytes
In BIND 9.15.6 -> 9.16.5, 9.17.0 -> 9.17.3, An attacker who can establish a TCP connection with the server and send data
In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' t
In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10.5-S1 -> 9.11.21-S1 of the BIND 9 Suppor
u'Reachable assertion when wrong data size is returned by parser for ape clips' in Snapdragon Auto, Snapdragon Consumer
An exploitable denial of service vulnerability exists in the atftpd daemon functionality of atftp 0.7.git20120829-3.1+b1
receive.c in fastd before v21 allows denial of service (assertion failure) when receiving packets with an invalid type c
In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supporte
The Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.0 through 4.2 (for ESP32 devices) return
Receipt of a specifically malformed NDP packet sent from the local area network (LAN) to a device running Juniper Networ
eth_get_gso_type in net/eth.c in QEMU 4.2.1 allows guest OS users to trigger an assertion failure. A guest can crash the
In Tensorflow before version 2.3.1, the `SparseCountSparseOutput` implementation does not validate that the input argume
VMware ESXi (6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), VMware Workstation (15.x before 15.5.
In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `SparseFillEmptyRowsGrad` implementation has in
An assertion failure issue was found in the Network Block Device(NBD) Server in all QEMU versions before QEMU 5.0.1. Thi
An attacker who is permitted to send zone data to a server via zone transfer can exploit this to intentionally trigger t
The iconv function in the GNU C Library (aka glibc or libc6) 2.30 to 2.32, when converting UCS4 text containing an irrev
In QEMU through 5.0.0, an assertion failure can occur in the network packet processing. This issue affects the e1000e an
A reachable assertion issue was found in the USB EHCI emulation code of QEMU. It could occur while processing USB reques
A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially be used by malicious
Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resourc
While handling a particular type of malformed packet BIND erroneously selects a SERVFAIL rcode instead of a FORMERR rcod
Frequently Asked Questions
What is CWE-617?
CWE-617 (CWE-617) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-617?
There are 926 CVE records associated with CWE-617 in our database. Of these, 4 are critical severity, 323 are high severity, and 439 are medium severity.
How can I protect against CWE-617 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-617 using AI-powered security agents.
Detect CWE-617 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-617 vulnerabilities across your infrastructure.
Get Started