Vulnerabilities > Reachable Assertion

DATE CVE VULNERABILITY TITLE RISK
2017-08-29 CVE-2017-13745 Reachable Assertion vulnerability in Jasper Project Jasper 2.0.12
There is a reachable assertion abort in the function jpc_dec_process_sot() in jpc/jpc_dec.c in JasPer 2.0.12 that will lead to a remote denial of service attack by triggering an unexpected jpc_ppmstabtostreams return value, a different vulnerability than CVE-2018-9154.
network
low complexity
jasper-project CWE-617
7.5
2017-08-29 CVE-2017-13727 Reachable Assertion vulnerability in Libtiff 4.0.8
There is a reachable assertion abort in the function TIFFWriteDirectoryTagSubifd() in LibTIFF 4.0.8, related to tif_dirwrite.c and a SubIFD tag.
network
low complexity
libtiff CWE-617
6.5
2017-08-29 CVE-2017-13726 Reachable Assertion vulnerability in Libtiff 4.0.8
There is a reachable assertion abort in the function TIFFWriteDirectorySec() in LibTIFF 4.0.8, related to tif_dirwrite.c and a SubIFD tag.
network
low complexity
libtiff CWE-617
6.5
2017-08-24 CVE-2017-13658 Reachable Assertion vulnerability in Imagemagick
In ImageMagick before 6.9.9-3 and 7.x before 7.0.6-3, there is a missing NULL check in the ReadMATImage function in coders/mat.c, leading to a denial of service (assertion failure and application exit) in the DestroyImageInfo function in MagickCore/image.c.
network
low complexity
imagemagick CWE-617
6.5
2017-08-23 CVE-2017-13132 Reachable Assertion vulnerability in Imagemagick 7.0.68
In ImageMagick 7.0.6-8, the WritePDFImage function in coders/pdf.c operates on an incorrect data structure in the "dump uncompressed PseudoColor packets" step, which allows attackers to cause a denial of service (assertion failure in WriteBlobStream in MagickCore/blob.c) via a crafted file.
network
low complexity
imagemagick CWE-617
6.5
2017-08-18 CVE-2017-12960 Reachable Assertion vulnerability in GNU Pspp 0.11.0
There is a reachable assertion abort in the function dict_rename_var() in data/dictionary.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to remote denial of service.
network
low complexity
gnu CWE-617
7.5
2017-08-18 CVE-2017-12959 Reachable Assertion vulnerability in GNU Pspp 0.11.0
There is a reachable assertion abort in the function dict_add_mrset() in data/dictionary.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to a remote denial of service attack.
network
low complexity
gnu CWE-617
7.5
2017-08-09 CVE-2017-11368 Reachable Assertion vulnerability in multiple products
In MIT Kerberos 5 (aka krb5) 1.7 and later, an authenticated attacker can cause a KDC assertion failure by sending invalid S4U2Self or S4U2Proxy requests.
network
low complexity
fedoraproject mit CWE-617
6.5
2017-08-07 CVE-2017-12670 Reachable Assertion vulnerability in Imagemagick 7.0.63
In ImageMagick 7.0.6-3, missing validation was found in coders/mat.c, leading to an assertion failure in the function DestroyImage in MagickCore/image.c, which allows attackers to cause a denial of service.
network
low complexity
imagemagick CWE-617
6.5
2017-08-04 CVE-2017-12434 Reachable Assertion vulnerability in Imagemagick 7.0.61
In ImageMagick 7.0.6-1, a missing NULL check vulnerability was found in the function ReadMATImage in coders/mat.c, which allows attackers to cause a denial of service (assertion failure) in DestroyImageInfo in image.c.
network
low complexity
imagemagick CWE-617
6.5