285 vulnerabilities classified as CWE-754 (对因果或异常条件的不恰当检查). AI Chinese analysis included.
CWE-754 represents a critical software weakness where applications fail to properly validate or handle unexpected environmental states, such as resource exhaustion, permission denials, or malformed inputs. Developers often exploit this oversight by assuming routine operational conditions will always hold true, leading to crashes, data corruption, or security breaches when rare events occur. Attackers typically trigger these exceptional conditions to cause denial-of-service attacks or to bypass security controls by forcing the application into an undefined state. To mitigate this risk, engineers must implement robust error handling mechanisms that explicitly check for and gracefully manage unusual scenarios. This includes validating resource availability, verifying user permissions, and ensuring inputs meet expected formats before processing, thereby maintaining system stability and security even under adverse or unexpected operating conditions.
char buf[10], cp_buf[10]; fgets(buf, 10, stdin); strcpy(cp_buf, buf);buf = (char*) malloc(req_size); strncpy(buf, xfer, req_size);| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2021-22747 | Triconex Model 3009 MP 代码问题漏洞 — Triconex Model 3009 MP installed on Tricon V11.3.x systems | 3.9 | - | 2021-05-26 |
| CVE-2021-22746 | Triconex Model 3009 MP 代码问题漏洞 — Triconex Model 3009 MP installed on Tricon V11.3.x systems | 3.9 | - | 2021-05-26 |
| CVE-2021-22745 | Triconex Model 3009 MP 代码问题漏洞 — Triconex Model 3009 MP installed on Tricon V11.3.x systems | 3.9 | - | 2021-05-26 |
| CVE-2021-22744 | Triconex Model 3009 MP 代码问题漏洞 — Triconex Model 3009 MP installed on Tricon V11.3.x systems | 3.9 | - | 2021-05-26 |
| CVE-2021-22743 | Triconex Model 3009 MP 代码问题漏洞 — Triconex TCM 4351B installed on Tricon V11.3.x systems. | 3.9 | - | 2021-05-26 |
| CVE-2021-22742 | Triconex Model 3009 MP 代码问题漏洞 — Triconex Model 3009 MP installed on Tricon V11.3.x systems | 3.9 | - | 2021-05-26 |
| CVE-2021-29607 | Incomplete validation in `SparseSparseMinimum` — tensorflow | 5.3 | Medium | 2021-05-14 |
| CVE-2021-29531 | CHECK-fail in tf.raw_ops.EncodePng — tensorflow | 2.5 | Low | 2021-05-14 |
| CVE-2021-29533 | CHECK-fail in DrawBoundingBoxes — tensorflow | 2.5 | Low | 2021-05-14 |
| CVE-2021-29534 | CHECK-fail in SparseConcat — tensorflow | 2.5 | Low | 2021-05-14 |
| CVE-2021-29544 | CHECK-fail in `QuantizeAndDequantizeV4Grad` — tensorflow | 2.5 | Low | 2021-05-14 |
| CVE-2018-25007 | Unauthorized client-side property update in UIDL request handler in Vaadin 10 and 11 — Vaadin | 2.6 | Low | 2021-04-23 |
| CVE-2021-0239 | Junos OS Evolved: Denial of Service due to receipt of specific genuine layer 2 frames. — Junos OS Evolved | 6.5 | Medium | 2021-04-22 |
| CVE-2021-0236 | Junos OS: A specific BGP VPNv6 flowspec message causes routing protocol daemon (rpd) process to crash with a core. — Junos OS | 6.5 | Medium | 2021-04-22 |
| CVE-2021-0228 | Junos OS: MX Series: DDoS LACP violation upon receipt of specific layer 2 frames in EVPN-VXLAN deployment — Junos OS | 6.5 | Medium | 2021-04-22 |
| CVE-2021-0225 | Junos OS Evolved: Stateless IP firewall filter does not work as expected — Junos OS Evolved | 5.8 | Medium | 2021-04-22 |
| CVE-2021-1446 | Cisco IOS XE Software DNS NAT Protocol Application Layer Gateway Denial of Service Vulnerability — Cisco IOS XE Software | 8.6 | High | 2021-03-24 |
| CVE-2020-27274 | Honeywell OPC UA Tunneller 代码问题漏洞 — OPC UA Tunneller | 7.5 | - | 2021-01-26 |
| CVE-2020-24677 | Insecure Web Service in Symphony Plus — ABB Ability™ Symphony® Plus Operations | 8.8 | High | 2020-12-22 |
| CVE-2020-7549 | Schneider Electric Modicon M340 代码问题漏洞 — Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for affected versions) | 5.3 | - | 2020-12-11 |
| CVE-2020-7543 | 多款Schneider Electric产品代码问题漏洞 — Modicon M580, Modicon M340, Legacy Controllers Modicon Quantum & Modicon Premium (see security notifications for affected versions) | 7.5 | - | 2020-12-11 |
| CVE-2020-7542 | 多款Schneider Electric产品代码问题漏洞 — Modicon M580, Modicon M340, Legacy Controllers Modicon Quantum & Modicon Premium (see security notifications for affected versions) | 7.5 | - | 2020-12-11 |
| CVE-2020-7539 | 多款 Schneider Electric 产品代码问题漏洞 — Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for affected versions) | 7.5 | - | 2020-12-11 |
| CVE-2020-7537 | 多款Schneider Electric产品代码问题漏洞 — Modicon M580, Modicon M340, Legacy Controllers Modicon Quantum & Modicon Premium (see security notifications for affected versions) | 7.5 | - | 2020-12-11 |
| CVE-2020-7536 | Schneider Electric Modicon M340 代码问题漏洞 — Modicon M340 CPUs (BMXP34* versions prior to V3.30) and Modicon M340 Communication Ethernet modules (BMXNOE0100 (H) versions prior to V3.4, BMXNOE0110 (H) versions prior to V6.6, and BMXNOR0200H all versions) | 7.5 | - | 2020-12-11 |
| CVE-2020-7538 | Schneider Electric EcoStruxure Control Expert 代码问题漏洞 — PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) | 7.5 | - | 2020-11-19 |
| CVE-2020-1999 | PAN-OS: Threat signatures are evaded by specifically crafted packets — PAN-OS | 5.3 | Medium | 2020-11-12 |
| CVE-2020-16125 | gdm3 would start gnome-initial-setup if it cannot contact accountservice — GDM3 | 7.2 | High | 2020-11-10 |
| CVE-2020-3421 | Cisco IOS XE Software Zone-Based Firewall Denial of Service Vulnerabilities — Cisco IOS XE Software | 8.6 | High | 2020-09-24 |
| CVE-2020-3480 | Cisco IOS XE Software Zone-Based Firewall Denial of Service Vulnerabilities — Cisco IOS XE Software | 8.6 | High | 2020-09-24 |
Vulnerabilities classified as CWE-754 (对因果或异常条件的不恰当检查) represent 285 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.