Vulnerabilities > Improper Handling of Exceptional Conditions

DATE CVE VULNERABILITY TITLE RISK
2018-01-12 CVE-2017-13199 Improper Handling of Exceptional Conditions vulnerability in Google Android 8.0/8.1
In Bitmap.ccp if Bitmap.nativeCreate fails an out of memory exception is not thrown leading to a java.io.IOException later on.
network
low complexity
google CWE-755
7.8
2017-11-13 CVE-2017-0904 Improper Handling of Exceptional Conditions vulnerability in Private Address Check Project Private Address Check 0.1.0/0.2.0/0.3.0
The private_address_check ruby gem before 0.4.0 is vulnerable to a bypass due to use of Ruby's Resolv.getaddresses method, which is OS-dependent and should not be relied upon for security measures, such as when used to blacklist private network addresses to prevent server-side request forgery.
6.8
2017-09-08 CVE-2017-0762 Improper Handling of Exceptional Conditions vulnerability in Google Android
A remote code execution vulnerability in the Android media framework (libhevc).
network
google CWE-755
critical
9.3
2017-09-08 CVE-2017-0760 Improper Handling of Exceptional Conditions vulnerability in Google Android
A remote code execution vulnerability in the Android media framework (libstagefright).
network
google CWE-755
critical
9.3
2017-09-08 CVE-2017-0759 Improper Handling of Exceptional Conditions vulnerability in Google Android
A remote code execution vulnerability in the Android media framework (libstagefright).
network
google CWE-755
critical
9.3
2017-07-20 CVE-2017-11472 Improper Handling of Exceptional Conditions vulnerability in Linux Kernel
The acpi_ns_terminate() function in drivers/acpi/acpica/nsutils.c in the Linux kernel before 4.12 does not flush the operand cache and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism (in the kernel through 4.9) via a crafted ACPI table.
local
low complexity
linux CWE-755
3.6
2017-06-26 CVE-2017-7496 Improper Handling of Exceptional Conditions vulnerability in Fedoraproject ARM Installer
fedora-arm-installer up to and including 1.99.16 is vulnerable to local privilege escalation due to lack of checking the error condition of mount operation failure on unsafely created temporary directories.
4.4
2017-06-26 CVE-2017-6678 Improper Handling of Exceptional Conditions vulnerability in Cisco Virtualized Packet Core
A vulnerability in the ingress UDP packet processing functionality of Cisco Virtualized Packet Core-Distributed Instance (VPC-DI) Software 19.2 through 21.0 could allow an unauthenticated, remote attacker to cause both control function (CF) instances on an affected system to reload, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-755
7.8
2017-06-15 CVE-2017-0193 Improper Handling of Exceptional Conditions vulnerability in Microsoft products
Windows Hyper-V in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to gain elevated privileges on a target guest operating system when Windows Hyper-V instruction emulation fails to properly enforce privilege levels, aka "Hypervisor Code Integrity Elevation of Privilege Vulnerability".
local
low complexity
microsoft CWE-755
4.6
2017-06-06 CVE-2017-5664 Improper Handling of Exceptional Conditions vulnerability in Apache Tomcat
The error page mechanism of the Java Servlet Specification requires that, when an error occurs and an error page is configured for the error that occurred, the original request and response are forwarded to the error page.
network
low complexity
apache CWE-755
7.5