Vulnerabilities > Improper Handling of Exceptional Conditions

DATE CVE VULNERABILITY TITLE RISK
2019-05-22 CVE-2018-7849 Improper Handling of Exceptional Conditions vulnerability in Schneider-Electric products
A CWE-248: Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum and Modicon Premium which could cause a possible Denial of Service due to improper data integrity check when sending files the controller over Modbus.
network
low complexity
schneider-electric CWE-755
5.0
2019-05-16 CVE-2019-1858 Improper Handling of Exceptional Conditions vulnerability in Cisco Nx-Os
A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause the SNMP application to leak system memory, which could cause an affected device to restart unexpectedly.
network
low complexity
cisco CWE-755
8.6
2019-05-14 CVE-2019-10917 Improper Handling of Exceptional Conditions vulnerability in Siemens products
A vulnerability has been identified in SIMATIC PCS 7 V8.0 and earlier (All versions), SIMATIC PCS 7 V8.1 (All versions < V8.1 with WinCC V7.3 Upd 19), SIMATIC PCS 7 V8.2 (All versions < V8.2 SP1 with WinCC V7.4 SP1 Upd11), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP2 with WinCC V7.4 SP1 Upd11), SIMATIC WinCC (TIA Portal) V13 (All versions), SIMATIC WinCC (TIA Portal) V14 (All versions < V14 SP1 Upd 9), SIMATIC WinCC (TIA Portal) V15 (All versions < V15.1 Upd 3), SIMATIC WinCC Runtime Professional V13 (All versions), SIMATIC WinCC Runtime Professional V14 (All versions < V14.1 Upd 8), SIMATIC WinCC Runtime Professional V15 (All versions < V15.1 Upd 3), SIMATIC WinCC V7.2 and earlier (All versions), SIMATIC WinCC V7.3 (All versions < V7.3 Upd 19), SIMATIC WinCC V7.4 (All versions < V7.4 SP1 Upd 11), SIMATIC WinCC V7.5 (All versions < V7.5 Upd 3).
local
low complexity
siemens CWE-755
2.1
2019-05-06 CVE-2019-3565 Improper Handling of Exceptional Conditions vulnerability in Facebook Thrift
Legacy C++ Facebook Thrift servers (using cpp instead of cpp2) would not error upon receiving messages with containers of fields of unknown type.
network
low complexity
facebook CWE-755
7.5
2019-05-06 CVE-2019-3564 Improper Handling of Exceptional Conditions vulnerability in Facebook Thrift
Go Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type.
network
low complexity
facebook CWE-755
7.5
2019-05-06 CVE-2019-3559 Improper Handling of Exceptional Conditions vulnerability in Facebook Thrift
Java Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type.
network
low complexity
facebook CWE-755
7.5
2019-05-06 CVE-2019-3558 Improper Handling of Exceptional Conditions vulnerability in Facebook Thrift
Python Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type.
network
low complexity
facebook CWE-755
7.5
2019-05-06 CVE-2019-3552 Improper Handling of Exceptional Conditions vulnerability in Facebook Thrift
C++ Facebook Thrift servers (using cpp2) would not error upon receiving messages with containers of fields of unknown type.
network
low complexity
facebook CWE-755
7.5
2019-05-03 CVE-2019-1635 Improper Handling of Exceptional Conditions vulnerability in Cisco products
A vulnerability in the call-handling functionality of Session Initiation Protocol (SIP) Software for Cisco IP Phone 7800 Series and 8800 Series could allow an unauthenticated, remote attacker to cause an affected phone to reload unexpectedly, resulting in a temporary denial of service (DoS) condition.
network
low complexity
cisco CWE-755
7.8
2019-04-11 CVE-2019-9628 Improper Handling of Exceptional Conditions vulnerability in multiple products
The XMLTooling library all versions prior to V3.0.4, provided with the OpenSAML and Shibboleth Service Provider software, contains an XML parsing class.
network
low complexity
xmltooling-project canonical opensuse CWE-755
5.0