The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.
Volume of CVEs assigned to CWE-617 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
789 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-8617MEDIUM Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the attacker knows (or successfully guesses) the name of a TSIG | May 19, 2020 | 5.9 | 85 | NO | YES |
CVE-2020-36222HIGH A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial of service. | Jan 26, 2021 | 7.5 | 67 | NO | NO |
CVE-2006-5779HIGH OpenLDAP before 2.3.29 allows remote attackers to cause a denial of service (daemon crash) via LDAP BIND requests with long authcid names, which triggers an assertion failure. | Nov 7, 2006 | 7.5 | 61 | NO | NO |
CVE-2021-27212HIGH In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function via a crafted packet, resulting in a denia | Feb 14, 2021 | 7.5 | 58 | NO | NO |
CVE-2018-5740HIGH "deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the | Jan 16, 2019 | 7.5 | 58 | NO | NO |
CVE-2023-28425MEDIUM Redis is an in-memory database that persists on disk. Starting in version 7.0.8 and prior to version 7.0.10, authenticated users can use the MSETNX command to trigger a runtime ass | Mar 20, 2023 | 5.5 | 49 | NO | NO |
CVE-2017-7478HIGH OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue is fixed in 2.3.15 and 2.4.2. | May 15, 2017 | 7.5 | 44 | NO | YES |
CVE-2018-12543HIGH In Eclipse Mosquitto versions 1.5 to 1.5.2 inclusive, if a message is published to Mosquitto that has a topic starting with $, but that is not $SYS, e.g. $test/test, then an assert | Nov 15, 2018 | 7.5 | 43 | NO | NO |
CVE-2011-3596HIGH Polipo before 1.0.4.1 suffers from a DoD vulnerability via specially-crafted HTTP POST / PUT request. | Nov 26, 2019 | 7.5 | 40 | NO | YES |
CVE-2026-5946HIGH Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that s | May 20, 2026 | 7.5 | 37 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.