A reachable assertion vulnerability in the /nsmf-pdusession/v1/sm-contexts component of Open5GS v2.7.6 allows attackers
Any guest issuing a Xenstore command accessing a node using the (illegal) node path "/local/domain/", will crash xenstor
bt_sdp_parse_attribute() in subsys/bluetooth/host/classic/sdp.c validated only that the SDP record buffer held the type-
In the Linux kernel, the following vulnerability has been resolved: KVM: Replace guest-triggerable BUG_ON() in ioeventf
In Modem, there is a possible read of uninitialized heap data due to an uncaught exception. This could lead to remote de
In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service,
Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2
Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, i
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service
A truncated 802.15.4 packet can lead to an assert, resulting in a denial of service.
An authorized user may trigger a server crash by running a $geoNear pipeline with certain invalid index hints.
A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ
A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ
A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a missing bounds check in `sma
Transient DOS when an LTE RLC packet with invalid TB is received by UE.
Transient DOS when MAC configures config id greater than supported maximum value.
A crafted JavaScript input can trigger an internal assertion failure in QuickJS release 2025-09-13, fixed in commit 1dbb
Under certain conditions, `named` may crash when processing a correctly signed query containing a TKEY record. The affec
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, an unvalidated auth_length fie
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, a malicious RDP server can cra
In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service,
ZEBRA is a Zcash node written entirely in Rust. From zebrad versions 2.2.0 to before 4.3.1 and from zebra-rpc versions 1
Creating a "2dsphere_bucket" index on a non-timeseries bucket collection will succeed, but any subsequent attempt to ins
Any guest can cause xenstored to crash by issuing a XS_RESET_WATCHES command within a transaction due to an assert() tri
Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 t
When using $changestreams and $_requestReshardingResumeToken with the exchange option the server hits an invariant which
Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server.
The $_internalConvertBucketIndexStats stage used PauseExecution as a way to signal "skip this document" when an index st
This issue can occur when running an aggregation pipeline that uses the internal $exchange stage configured with key-ran
An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfe
A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse
In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These
In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These
CWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to trigger a denial-of-servi
vLLM is a library for LLM inference and serving. From 0.12.0 to before 0.24.0, sending a pure prompt embeds payload in a
Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A
If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequ
The `$_internalIndexKey` aggregation expression can be used by any authenticated user to crash a MongoDB server (mongod)
An authenticated user with basic write privileges can cause the mongod process to terminate abnormally by sending a craf
During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the m
An issue in MongoDB Server's handling of certain query predicates against time-series collections with a metaField could
A reachable assertion was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.1
IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_fastcgi module.
NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API where an attacker could trigger a re
node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.25.1, the WrappedRE2::Replace function
Out-of-bounds read, Reachable assertion vulnerability in Samsung Open Source Escargot allows Overread Buffers, Input Dat
go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, if th
libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to version 0.49.4, the Ru
Frequently Asked Questions
What is CWE-617?
CWE-617 (CWE-617) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-617?
There are 926 CVE records associated with CWE-617 in our database. Of these, 4 are critical severity, 323 are high severity, and 439 are medium severity.
How can I protect against CWE-617 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-617 using AI-powered security agents.
Detect CWE-617 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-617 vulnerabilities across your infrastructure.
Get Started