Vulnerabilities > Incorrect Comparison

DATE CVE VULNERABILITY TITLE RISK
2022-01-25 CVE-2022-23027 Incorrect Comparison vulnerability in F5 products
On BIG-IP versions 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, 13.1.x beginning in 13.1.3.6, 12.1.5.3-12.1.6, and 11.6.5.2, when a FastL4 profile and an HTTP, FIX, and/or hash persistence profile are configured on the same virtual server, undisclosed requests can cause the virtual server to stop processing new client connections.
network
low complexity
f5 CWE-697
5.3
2022-01-25 CVE-2021-34865 Incorrect Comparison vulnerability in Netgear products
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of multiple NETGEAR routers.
low complexity
netgear CWE-697
8.8
2022-01-13 CVE-2022-22990 Incorrect Comparison vulnerability in Westerndigital MY Cloud OS
A limited authentication bypass vulnerability was discovered that could allow an attacker to achieve remote code execution and escalate privileges on the My Cloud devices.
low complexity
westerndigital CWE-697
8.8
2022-01-12 CVE-2021-40562 Incorrect Comparison vulnerability in Gpac
A Segmentation fault caused by a floating point exception exists in Gpac through 1.0.1 using mp4box via the naludmx_enqueue_or_dispatch function in reframe_nalu.c, which causes a denial of service.
local
low complexity
gpac CWE-697
5.5
2021-12-26 CVE-2021-44078 Incorrect Comparison vulnerability in Unicorn-Engine Unicorn Engine
An issue was discovered in split_region in uc.c in Unicorn Engine before 2.0.0-rc5.
local
high complexity
unicorn-engine CWE-697
8.1
2021-12-17 CVE-2021-41500 Incorrect Comparison vulnerability in multiple products
Incomplete string comparison vulnerability exits in cvxopt.org cvxop <= 1.2.6 in APIs (cvxopt.cholmod.diag, cvxopt.cholmod.getfactor, cvxopt.cholmod.solve, cvxopt.cholmod.spsolve), which allows attackers to conduct Denial of Service attacks by construct fake Capsule objects.
network
low complexity
cvxopt-project fedoraproject CWE-697
7.5
2021-12-17 CVE-2021-34141 Incorrect Comparison vulnerability in multiple products
An incomplete string comparison in the numpy.core component in NumPy before 1.22.0 allows attackers to trigger slightly incorrect copying by constructing specific string objects.
network
low complexity
numpy oracle CWE-697
5.3
2021-12-13 CVE-2021-39917 Incorrect Comparison vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2.
network
low complexity
gitlab CWE-697
6.5
2021-11-18 CVE-2021-23146 Incorrect Comparison vulnerability in Gallagher Command Centre
An Incomplete Comparison with Missing Factors vulnerability in the Gallagher Controller allows an attacker to bypass PIV verification.
network
low complexity
gallagher CWE-697
7.5
2021-10-07 CVE-2021-3833 Incorrect Comparison vulnerability in Artica Integria IMS 5.0.92
Integria IMS login check uses a loose comparator ("==") to compare the MD5 hash of the password provided by the user and the MD5 hash stored in the database.
network
low complexity
artica CWE-697
critical
9.8