A vulnerability was determined in jqlang jq up to 1.6. Impacted is the function run_jq_tests of the file jq_test.c of th
atop through 2.11.0 allows local users to cause a denial of service (e.g., assertion failure and application exit) or po
libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a denial of service (var_set_leave_quiet assertion fa
Cairo through 1.18.4, as used in Poppler through 25.08.0, has an "unscaled->face == NULL" assertion failure for _cairo_f
In a Bluetooth device, using RS9116-WiseConnect SDK experiences a Denial of Service, if it receives malformed L2CAP pack
wb2osz/direwolf (Dire Wolf) versions up to and including 1.8, prior to commit 3658a87, contain a reachable assertion vul
In the Linux kernel, the following vulnerability has been resolved: udp: do not accept non-tunnel GSO skbs landing in a
phonenumber is a library for parsing, formatting and validating international phone numbers. Since 0.3.4, the phonenumbe
Improper handling of values in HuginBase::PTools::Transform::transform of Hugin 2022.0.0 leads to an assertion failure.
In the Linux kernel, the following vulnerability has been resolved: bpf: Check rcu_read_lock_trace_held() before callin
In the Linux kernel, the following vulnerability has been resolved: ubifs: Fix races between xattr_{set|get} and listxa
In the Linux kernel, the following vulnerability has been resolved: btrfs: protect folio::private when attaching extent
In the Linux kernel, the following vulnerability has been resolved: sock_map: avoid race between sock_map_close and sk_
Transient DOS while processing 11AZ RTT management action frame received through OTA.
A flaw in query-handling code can cause `named` to exit prematurely with an assertion failure when: - `nxdomain-redir
A bad interaction between DNS64 and serve-stale may cause `named` to crash with an assertion failure during recursive re
Transient DOS while processing multiple payload container type with incorrect container length received in DL NAS transp
Transient DOS while processing DL NAS Transport message, as specified in 3GPP 24.501 v16.
Envoy is a cloud-native, open source edge and service proxy. When an upstream TLS cluster is used with `auto_sni` enable
In Jasper 4.2.2, the jpc_streamlist_remove function in src/libjasper/jpc/jpc_dec.c:2407 has an assertion failure vulnera
Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: gmm_
Transient DOS while processing IKEv2 Informational request messages, when a malformed fragment packet is received.
Client queries that trigger serving stale data and that also require lookups in local authoritative zone data may result
In the Linux kernel, the following vulnerability has been resolved: net: can: j1939: enhanced error handling for tightl
A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface wit
A flaw was found in the vLLM library. A completions API request with an empty prompt will crash the vLLM API server, res
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service wi
Quicly is an IETF QUIC protocol implementation. Quicly up to commtit d720707 is susceptible to a denial-of-service attac
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr
Reachable Assertion in BPv7 parser in µD3TN v0.14.0 allows attacker to disrupt service via malformed Extension Block
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.
Open62541 v1.4.6 is has an assertion failure in fuzz_binary_decode, which leads to a crash.
rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows an attacker to trigger rpgp crashes by provi
nscd: netgroup cache may terminate daemon on memory allocation failure The Name Service Cache Daemon's (nscd) netgroup
In the Linux kernel, the following vulnerability has been resolved: btrfs: don't readahead the relocation inode on RST
A vulnerability in the implementation of the Resource Public Key Infrastructure (RPKI) feature of Cisco IOS XR Soft
Permanent DOS when DL NAS transport receives multiple payloads such that one payload contains SOR container whose integr
libsndfile through 1.2.2 has a reachable assertion, that may lead to application exit, in mpeg_l3_encode.c mpeg_l3_encod
TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/16, that may lead to application exit, in tinyxml2.cpp XM
TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/digit, that may lead to application exit, in tinyxml2.cpp
In Bluetooth firmware, there is a possible firmware asssert due to improper handling of exceptional conditions. This cou
An assert may be triggered, causing a temporary denial of service when a peer device sends a specially crafted malformed
Due to an unchecked buffer length, a specially crafted L2CAP packet can cause a buffer overflow. This buffer overflow tr
Jerryscript commit cefd391 was discovered to contain an Assertion Failure via ECMA_STRING_IS_REF_EQUALS_TO_ONE (string_p
In btrfs_get_root_ref in fs/btrfs/disk-io.c in the Linux kernel through 6.7.1, there can be an assertion failure and cra
In the Linux kernel, the following vulnerability has been resolved: btrfs: remove BUG() after failure to insert delayed
In the Linux kernel, the following vulnerability has been resolved: btrfs: don't drop extent_map for free space inode o
In the Linux kernel, the following vulnerability has been resolved: btrfs: do not ASSERT() if the newly created subvolu
A flaw was found in QEMU. An assertion failure was present in the update_sctp_checksum() function in hw/net/net_tx_pkt.c
Frequently Asked Questions
What is CWE-617?
CWE-617 (CWE-617) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-617?
There are 926 CVE records associated with CWE-617 in our database. Of these, 4 are critical severity, 323 are high severity, and 439 are medium severity.
How can I protect against CWE-617 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-617 using AI-powered security agents.
Detect CWE-617 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-617 vulnerabilities across your infrastructure.
Get Started