CWE-617: CWE-617

189
Total CVEs
0
Critical
104
High
6.8
Avg CVSS

Yearly Trend

2026
24
2025
82
2024
28
2023
21
2022
13

Top Affected Vendors

1 Open5gs 35
2 Linux 34
3 Qualcomm 28
4 Debian 17
5 Mediatek 15
6 Netapp 7
7 Fedoraproject 7
8 Linuxfoundation 7
9 Pexip 6
10 Isc 6

All CWE-617 CVEs (189)

CVE-2024-24429
8.6

This vulnerability in Open5GS allows attackers to trigger a denial of service by sending a specially crafted NGAP packet to the nas_eps_send_emm_to_es...

Jan 22, 2025
CVE-2024-34235
8.6

CVE-2024-34235 is a remotely triggerable assertion vulnerability in Open5GS MME that allows denial of service attacks. Attackers can send malformed S1...

Jan 22, 2025
CVE-2023-37015
8.6

This vulnerability allows remote attackers to cause denial of service by sending malformed ASN.1 packets to Open5GS MME servers. Attackers can repeate...

Jan 22, 2025
CVE-2023-37016
8.6

CVE-2023-37016 is a remotely triggerable assertion vulnerability in Open5GS MME that allows denial of service attacks. Attackers can send malformed AS...

Jan 22, 2025
CVE-2023-37017
8.6

Open5GS MME versions up to 2.6.4 contain a remotely triggerable assertion via malformed ASN.1 packets on the S1AP interface. Attackers can send S1Setu...

Jan 22, 2025
CVE-2023-37018
8.6

Open5GS MME versions up to 2.6.4 contain a remotely triggerable assertion vulnerability via malformed ASN.1 packets on the S1AP interface. Attackers c...

Jan 22, 2025
CVE-2023-37019
8.6

This vulnerability allows remote attackers to cause denial of service by sending specially crafted S1AP packets to Open5GS MME servers. Attackers can ...

Jan 22, 2025
CVE-2023-37020
8.6

Open5GS MME versions up to 2.6.4 contain a remotely triggerable assertion via malformed ASN.1 packets on the S1AP interface. Attackers can send UE Con...

Jan 22, 2025
CVE-2023-37021
8.6

Open5GS MME versions up to 2.6.4 contain a remotely triggerable assertion via malformed S1AP packets. Attackers can send UE Context Modification Failu...

Jan 22, 2025
CVE-2023-37023
8.6

CVE-2023-37023 is a denial-of-service vulnerability in Open5GS MME where specially crafted Uplink NAS Transport packets without the MME_UE_S1AP_ID fie...

Jan 22, 2025
CVE-2024-25445
7.8

This vulnerability in Hugin 2022.0.0 allows an attacker to cause an assertion failure in the Transform::transform function by providing improper value...

Feb 9, 2024
CVE-2021-36409
7.8

CVE-2021-36409 is a vulnerability in libde265 v1.0.8 where a failed assertion during video file decoding causes a denial of service. Attackers can cra...

Jan 10, 2022
CVE-2021-1422
7.7

A logic error in Cisco ASA and FTD software cryptography modules allows authenticated remote attackers or unauthenticated man-in-the-middle attackers ...

Jul 16, 2021
CVE-2026-20401
7.5

This vulnerability allows remote denial of service attacks against mobile devices with affected MediaTek modems. An attacker can crash the system by c...

Feb 2, 2026
CVE-2025-13878
7.5

A denial-of-service vulnerability in BIND DNS servers where malformed BRID/HHIT records cause the named process to crash. This affects BIND 9 installa...

Jan 21, 2026
CVE-2025-66379
7.5

CVE-2025-66379 is an improper input validation vulnerability in Pexip Infinity's media implementation that allows remote attackers to trigger a softwa...

Dec 25, 2025
CVE-2025-66443
7.5

Pexip Infinity versions 35.0 through 38.1 have an improper input validation vulnerability in WebRTC signaling when using non-default Direct Media conf...

Dec 25, 2025
CVE-2025-32096
7.5

Pexip Infinity versions 33.0 through 37.0 have improper input validation in signaling that allows attackers to trigger a software abort, causing denia...

Dec 25, 2025
CVE-2025-48704
7.5

Pexip Infinity versions 35.0 through 37.2 have an improper input validation vulnerability in signalling that allows attackers to trigger a software ab...

Dec 25, 2025
CVE-2025-32095
7.5

CVE-2025-32095 is an improper input validation vulnerability in Pexip Infinity's signaling component that allows remote attackers to trigger a softwar...

Dec 25, 2025
CVE-2025-65559
7.5

A reachable assertion vulnerability in Open5GS UPF component causes denial of service when processing malformed PFCP Session Establishment Requests wi...

Dec 18, 2025
CVE-2025-47913
7.5

This vulnerability affects SSH clients that panic and terminate when receiving SSH_AGENT_SUCCESS messages unexpectedly during authentication. It allow...

Nov 13, 2025
CVE-2025-46705
7.5

A denial of service vulnerability in Entr'ouvert Lasso's g_assert_not_reached function allows attackers to crash applications by sending specially cra...

Nov 5, 2025
CVE-2025-41067
7.5

A reachable assertion vulnerability in Open5GS NRF (Network Repository Function) allows attackers with network connectivity to send a specific SBI req...

Oct 27, 2025
CVE-2025-59530
7.5

A denial-of-service vulnerability in quic-go allows malicious or misbehaving QUIC servers to crash client applications by sending premature HANDSHAKE_...

Oct 10, 2025
CVE-2025-27073
7.5

This vulnerability allows attackers to cause a Denial of Service (DoS) condition by exploiting a flaw in the Neighbor Discovery Protocol (NDP) instanc...

Aug 6, 2025
CVE-2025-21452
7.5

This vulnerability allows attackers to cause a denial-of-service (DoS) condition on LTE networks by sending specially crafted random-access response (...

Aug 6, 2025
CVE-2024-42645
7.5

An assertion failure vulnerability in FlashMQ v1.14.0 allows attackers to cause a Denial of Service (DoS) by sending a specially crafted retain messag...

Jul 29, 2025
CVE-2025-40777
7.5

A denial-of-service vulnerability in BIND 9 DNS servers causes the named daemon to crash when specific configuration settings are enabled and certain ...

Jul 16, 2025
CVE-2025-49630
7.5

This vulnerability allows untrusted clients to trigger a denial of service attack against Apache HTTP Server by causing an assertion failure in the mo...

Jul 10, 2025
CVE-2025-20666
7.5

This vulnerability in MediaTek modems allows remote denial of service through system crashes when devices connect to rogue base stations. Attackers ca...

May 5, 2025
CVE-2024-24430
7.5

This vulnerability in Open5GS allows attackers to trigger a reachable assertion in the mme_ue_find_by_imsi function by sending a specially crafted NAS...

Jan 22, 2025
CVE-2024-24420
7.5

A reachable assertion vulnerability in Magma's decode_linked_ti_ie function allows attackers to cause Denial of Service (DoS) by sending crafted NAS p...

Jan 21, 2025
CVE-2024-24427
7.5

This vulnerability in Open5GS allows attackers to trigger a reachable assertion in the amf_ue_set_suci function via crafted NAS packets, causing a Den...

Jan 21, 2025
CVE-2024-24428
7.5

A reachable assertion vulnerability in Open5GS's 5GMM decoding function allows attackers to cause denial of service by sending specially crafted NGAP ...

Jan 21, 2025
CVE-2023-37029
7.5

CVE-2023-37029 allows attackers to cause denial of service by sending oversized NAS packets to Magma MME, crashing it via assertion failure. This affe...

Jan 21, 2025
CVE-2023-37024
7.5

An unauthenticated remote attacker can crash the Mobile Management Entity (MME) in Magma cellular core networks by sending a specially crafted NAS pac...

Jan 21, 2025
CVE-2024-23385
7.5

This vulnerability allows attackers to cause a denial-of-service (DoS) condition in mobile devices by sending specially crafted MAC RAR messages with ...

Nov 4, 2024
CVE-2024-10455
7.5

A reachable assertion vulnerability in the BPv7 parser of ยตD3TN v0.14.0 allows attackers to cause denial of service by sending malformed Extension Bl...

Oct 28, 2024
CVE-2024-45795
7.5

This vulnerability in Suricata allows an attacker to cause a denial of service by triggering an assertion failure when rules use datasets with the uni...

Oct 16, 2024
CVE-2024-45396
7.5

CVE-2024-45396 is a denial-of-service vulnerability in Quicly, an IETF QUIC protocol implementation. A remote attacker can trigger an assertion failur...

Oct 11, 2024
CVE-2024-20094
7.5

This vulnerability in MediaTek modems allows remote attackers to cause a system crash (denial of service) without authentication or user interaction. ...

Oct 7, 2024
CVE-2024-8768
7.5

A denial-of-service vulnerability exists in vLLM where sending an empty prompt to the completions API causes the API server to crash. This affects any...

Sep 17, 2024
CVE-2024-4076
7.5

This vulnerability in BIND DNS servers causes an assertion failure when specific client queries trigger serving stale data while requiring lookups in ...

Jul 23, 2024
CVE-2023-43529
7.5

This vulnerability allows attackers to cause a denial-of-service condition in IKEv2 implementations by sending malformed fragment packets. It affects ...

May 6, 2024
CVE-2024-34475
7.5

Open5GS versions before 2.7.1 contain a reachable assertion vulnerability in the AMF component that can be triggered by sending specially crafted NAS ...

May 5, 2024
CVE-2024-31744
7.5

This vulnerability in Jasper 4.2.2 allows attackers to cause a denial of service (DoS) by triggering an assertion failure in the jpc_streamlist_remove...

Apr 19, 2024
CVE-2023-33095
7.5

This vulnerability in Qualcomm's NR (New Radio) DL NAS transport OTA processing allows an attacker to cause a denial-of-service (DoS) by sending speci...

Mar 4, 2024
CVE-2023-5679
7.5

A vulnerability in BIND DNS servers where enabling both DNS64 and serve-stale features can cause named to crash during recursive resolution. This affe...

Feb 13, 2024
CVE-2023-34194
7.5

CVE-2023-34194 is a denial-of-service vulnerability in TinyXML's XML parser where a specially crafted XML document containing a null character after w...

Dec 13, 2023

About CWE-617 (CWE-617)

Our database tracks 189 CVEs classified as CWE-617, with 0 rated critical and 104 rated high severity. The average CVSS score for CWE-617 vulnerabilities is 6.8.

External reference: View CWE-617 on MITRE CWE →

Monitor CWE-617 Vulnerabilities

Get alerted when new CWE-617 CVEs affect your infrastructure.

Start Monitoring Free