CWE-617: CWE-617

193
Total CVEs
0
Critical
108
High
6.8
Avg CVSS

Yearly Trend

2026
24
2025
82
2024
28
2023
21
2022
13

Top Affected Vendors

1 Open5gs 35
2 Linux 34
3 Qualcomm 29
4 Debian 18
5 Mediatek 15
6 Netapp 7
7 Fedoraproject 7
8 Linuxfoundation 7
9 Pexip 6
10 Isc 6

All CWE-617 CVEs (193)

CVE-2021-25215
7.5

This vulnerability in BIND DNS servers allows remote attackers to cause denial of service by sending specially crafted DNS queries that trigger an ass...

Apr 29, 2021
CVE-2019-25036
7.5

CVE-2019-25036 is an assertion failure vulnerability in Unbound DNS resolver's synth_cname function that can cause denial of service. The vendor dispu...

Apr 27, 2021
CVE-2021-20217
7.5

This vulnerability in Privoxy allows attackers to trigger an assertion failure via a crafted CGI request, causing a denial of service. Systems running...

Mar 25, 2021
CVE-2020-11218
7.5

This CVE describes a denial-of-service vulnerability in Qualcomm baseband processors when LTE betaOffset-RI-Index configuration is processed without p...

Mar 17, 2021
CVE-2021-24029
7.5

This CVE describes a denial-of-service vulnerability in mvfst and proxygen QUIC implementations where a specially crafted QUIC message triggers a fail...

Mar 15, 2021
CVE-2021-20272
7.5

This vulnerability in Privoxy allows remote attackers to crash the proxy server by sending a specially crafted CGI request that triggers an assertion ...

Mar 9, 2021
CVE-2023-37013
7.3

CVE-2023-37013 is a denial-of-service vulnerability in Open5GS MME where attackers can send oversized ASN.1 packets over S1AP to trigger an assertion ...

Jan 22, 2025
CVE-2024-33601
7.3

A memory allocation failure in nscd's netgroup cache can cause the daemon to terminate, resulting in denial of service for clients relying on name ser...

May 6, 2024
CVE-2025-47384
6.5

This vulnerability allows a denial-of-service (DoS) condition in Qualcomm MAC (Media Access Control) components when an attacker configures a MAC conf...

Mar 2, 2026
CVE-2025-47371
6.5

This vulnerability allows a denial-of-service (DoS) attack against LTE user equipment (UE) when it receives an RLC packet with an invalid transport bl...

Mar 2, 2026
CVE-2026-27015
6.5

A missing bounds check in FreeRDP's smartcard handling allows a malicious RDP server to crash the FreeRDP client via an assertion failure. This affect...

Feb 25, 2026
CVE-2025-48023
6.5

A vulnerability in Yokogawa's Vnet/IP Interface Package allows remote attackers to cause denial of service by sending maliciously crafted packets. Thi...

Feb 13, 2026
CVE-2025-48019
6.5

A vulnerability in Yokogawa's Vnet/IP Interface Package allows remote attackers to cause denial of service by sending maliciously crafted packets, whi...

Feb 13, 2026
CVE-2025-48020
6.5

A vulnerability in Yokogawa's Vnet/IP Interface Package allows remote attackers to cause denial of service by sending maliciously crafted packets, whi...

Feb 13, 2026
CVE-2026-20422
6.5

This vulnerability in MediaTek modems allows remote denial of service through improper input validation. An attacker can crash the system by connectin...

Feb 2, 2026
CVE-2026-20405
6.5

This vulnerability in MediaTek modems allows remote denial of service through system crashes when devices connect to rogue base stations. Attackers ca...

Feb 2, 2026
CVE-2025-68468
6.5

This vulnerability allows remote attackers to crash the Avahi daemon by sending malicious mDNS announcements containing CNAME records with short TTLs....

Jan 12, 2026
CVE-2025-68471
6.5

This vulnerability allows remote attackers to crash the Avahi daemon by sending two specially crafted mDNS announcements with CNAME records two second...

Jan 12, 2026
CVE-2025-20760
6.5

This vulnerability in MediaTek modems allows reading uninitialized heap data when a device connects to a malicious base station. It can cause remote d...

Jan 6, 2026
CVE-2025-20762
6.5

This vulnerability in MediaTek modems allows remote denial of service through system crashes when devices connect to rogue base stations. Attackers ca...

Jan 6, 2026
CVE-2025-20757
6.5

This vulnerability in MediaTek modems allows remote denial of service through improper input validation. An attacker can crash the system by connectin...

Dec 2, 2025
CVE-2025-20752
6.5

A missing bounds check vulnerability in MediaTek modems could allow remote denial of service attacks. When a user equipment (UE) connects to a rogue b...

Dec 2, 2025
CVE-2025-13644
6.5

MongoDB Server may crash due to an invariant failure during batched delete operations when handling documents. The server incorrectly assumes multiple...

Nov 25, 2025
CVE-2025-60632
6.5

This vulnerability in Free5GC allows attackers to cause denial of service by sending specially crafted POST requests to the Npcf_BDTPolicyControl API....

Nov 24, 2025
CVE-2025-47370
6.5

This vulnerability allows a remote attacker to cause a denial of service (DoS) by sending invalid Bluetooth Low Energy (LE) connection requests during...

Nov 4, 2025
CVE-2025-52964
6.5

An unauthenticated network attacker can cause a denial of service by sending a specific BGP UPDATE packet to Juniper devices running vulnerable Junos ...

Jul 11, 2025
CVE-2025-22919
6.5

This CVE describes a reachable assertion vulnerability in FFmpeg that allows attackers to cause a Denial of Service (DoS) by opening a specially craft...

Feb 18, 2025
CVE-2024-7138
6.5

CVE-2024-7138 is a Bluetooth L2CAP protocol vulnerability that allows a remote attacker to trigger an assertion failure by sending a specially crafted...

Dec 19, 2024
CVE-2024-20139
6.5

This CVE describes a Bluetooth firmware vulnerability in MediaTek chipsets where improper handling of exceptional conditions can cause a firmware asse...

Dec 2, 2024
CVE-2024-50613
6.5

libsndfile versions through 1.2.2 contain a reachable assertion in the MPEG L3 encoder close function that can cause applications using this library t...

Oct 27, 2024
CVE-2024-50615
6.5

TinyXML2 versions through 10.0.0 contain a reachable assertion vulnerability in XMLUtil::GetCharacterRef that can cause applications to crash when pro...

Oct 27, 2024
CVE-2024-23350
6.5

This vulnerability allows attackers to cause a permanent denial-of-service condition in Qualcomm cellular modems by sending specially crafted NAS tran...

Aug 5, 2024
CVE-2023-37010
6.3

This vulnerability allows remote attackers to cause denial of service by sending specially crafted ASN.1 packets to Open5GS MME servers. Attackers can...

Jan 22, 2025
CVE-2026-23991
5.9

A denial-of-service vulnerability in go-tuf allows a compromised repository, mirror, or cache to crash client applications by sending malformed TUF me...

Jan 22, 2026
CVE-2025-49088
5.9

This vulnerability in Pexip Infinity's OTJ service allows remote attackers to cause denial of service by sending specially crafted calendar invites. S...

Dec 25, 2025
CVE-2024-34034
5.7

CVE-2024-34034 is a denial-of-service vulnerability in FlexRIC 2.0.0 where sending a high volume of E42 Subscription Requests causes the Near-RT RIC c...

Feb 25, 2025
CVE-2026-22990
5.5

A vulnerability in the Linux kernel's libceph component where a BUG_ON assertion in osdmap_apply_incremental() could be triggered by a maliciously cor...

Jan 23, 2026
CVE-2025-68276
5.5

This vulnerability allows unprivileged local users to crash the Avahi daemon by creating record browsers with the AVAHI_LOOKUP_USE_WIDE_AREA flag set ...

Jan 12, 2026
CVE-2023-53683
5.5

This vulnerability in the Linux kernel's HFS+ filesystem driver could allow an attacker to cause a kernel panic (system crash) by mounting a specially...

Oct 7, 2025
CVE-2023-53607
5.5

This CVE-2023-53607 is a Linux kernel vulnerability in the YMFPCI sound card driver where a BUG_ON assertion triggers a kernel warning during device p...

Oct 4, 2025
CVE-2023-53584
5.5

This CVE describes a race condition in the UBIFS filesystem implementation in the Linux kernel where an assertion failure can trigger a read-only mode...

Oct 4, 2025
CVE-2023-53448
5.5

This CVE involves a double-release of memory regions in the Linux kernel's imxfb framebuffer driver, which could lead to resource leaks or unexpected ...

Oct 1, 2025
CVE-2023-53450
5.5

This vulnerability in the Linux kernel's ext4 filesystem allows a malicious actor to trigger a kernel panic (denial of service) by manipulating the su...

Oct 1, 2025
CVE-2023-53247
5.5

A race condition vulnerability in the Linux kernel's Btrfs filesystem can cause kernel panics during file expansion operations. This affects Linux sys...

Sep 15, 2025
CVE-2022-50293
5.5

A memory handling vulnerability in the Linux kernel's Btrfs filesystem could cause a kernel panic when the system runs out of memory during certain fi...

Sep 15, 2025
CVE-2025-39801
5.5

This CVE addresses a kernel panic vulnerability in the Linux kernel's USB DWC3 driver. When 'panic_on_warn' is enabled, endpoint command timeouts duri...

Sep 15, 2025
CVE-2025-39768
5.5

This CVE addresses an error handling flaw in the Linux kernel's mlx5 network driver when rehashing complex rules. If moving rules between matchers fai...

Sep 11, 2025
CVE-2025-38712
5.5

A vulnerability in the Linux kernel's HFS+ filesystem driver where erroneous volume header values cause the system to incorrectly assume the attribute...

Sep 4, 2025
CVE-2025-38701
5.5

A Linux kernel vulnerability in the ext4 filesystem where a maliciously crafted filesystem image triggers a kernel panic (BUG_ON) when an inode has th...

Sep 4, 2025
CVE-2025-38690
5.5

A stack overflow vulnerability in the Linux kernel's Xe graphics driver migration code allows local attackers to trigger infinite recursion, potential...

Sep 4, 2025

About CWE-617 (CWE-617)

Our database tracks 193 CVEs classified as CWE-617, with 0 rated critical and 108 rated high severity. The average CVSS score for CWE-617 vulnerabilities is 6.8.

External reference: View CWE-617 on MITRE CWE →

Monitor CWE-617 Vulnerabilities

Get alerted when new CWE-617 CVEs affect your infrastructure.

Start Monitoring Free