Skip to content
Noroxi

CWE-252 · 161 records

Unchecked Return Value

CVEs in this class

161 records

  • CVE-2007-3798
    60This week

    Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via craf

    CriticalCVSS 9.8Proof of conceptEPSS 70%

    tcpdump · tcpdumpJul 16, 2007

  • The URL parser in Microsoft Internet Information Services (IIS) 5.1 on Windows XP Professional SP2 allows remote attackers to execute arbitr

    HighCVSS 7.8Proof of conceptEPSS 87%

    microsoft · internet information servicesDec 19, 2005

  • The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which

    CriticalCVSS 9.8Proof of conceptEPSS 28%

    openldap · openldapJul 28, 2010

  • adts_decode_extradata in libavformat/adtsenc.c in FFmpeg 4.4 does not check the init_get_bits return value, which is a necessary step becaus

    CriticalCVSS 9.8No exploitEPSS 2%

    ffmpeg · ffmpegAug 21, 2021

  • manual/search.texi in the GNU C Library (aka glibc) before 2.2 lacks a statement about the unspecified tdelete return value upon deletion of

    CriticalCVSS 9.8No exploitEPSS 2%

    gnu · glibcOct 6, 2020

  • An issue was discovered in slicer69 doas before 6.2 on certain platforms other than OpenBSD.

    CriticalCVSS 9.8No exploitEPSS 2%

    doas project · doasOct 18, 2019

  • An issue was discovered in the xcb crate through 2021-02-04 for Rust.

    CriticalCVSS 9.8No exploitEPSS 2%

    xcb project · xcbFeb 9, 2021

  • Cryptographic issue in WLAN due to improper check on return value while authentication handshake in Snapdragon Auto, Snapdragon Connectivity

    CriticalCVSS 9.8No exploitEPSS 0%

    qualcomm · apq8009 firmwareOct 19, 2022

  • Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int va

    CriticalCVSS 9.1No exploitEPSS 3%

    golang · goFeb 10, 2022

  • Fiber Utils UUIDv4 and UUID Silent Fallback to Predictable Values

    CriticalCVSS 9.3No exploitEPSS 0%

    gofiber · utilsDec 9, 2025

  • FFmpeg through 4.2 has a "Conditional jump or move depends on uninitialised value" issue in h2645_parse because alloc_rbsp_buffer in libavco

    HighCVSS 8.8No exploitEPSS 2%

    ffmpeg · ffmpegSep 5, 2019

  • Apache Traffic Server: Server process can fail to drop privilege

    CriticalCVSS 9.1No exploitEPSS 2%

    apache · traffic serverNov 14, 2024

  • An issue was discovered in the xcb crate through 2021-02-04 for Rust.

    HighCVSS 8.8No exploitEPSS 2%

    xcb project · xcbFeb 9, 2021

  • Junos OS and Junos OS Evolved: An Unchecked Return Value in multiple users interfaces affects confidentiality and integrity of device operations

    HighCVSS 8.8No exploitEPSS 1%

    juniper · junosOct 12, 2023

  • CVE-2024-1545
    35Monitor

    Fault Injection of RSA encryption in WolfCrypt

    HighCVSS 8.8No exploitEPSS 1%

    wolfssl · wolfsslAug 29, 2024

  • In International Color Consortium DemoIccMAX before 85ce74e, a logic flaw in CIccTagXmlProfileSequenceId::ParseXml in IccXML/IccLibXML/IccTa

    HighCVSS 8.8No exploitEPSS 1%

    Jun 15, 2024

  • NASA CryptoLib before 1.3.2 does not check the OTAR crypto function returned status, potentially leading to spacecraft hijacking.

    HighCVSS 8.8No exploitEPSS 1%

    nasa · cryptolibApr 26, 2025

  • CVE-2024-2881
    35Monitor

    Fault Injection of EdDSA signature in WolfCrypt

    HighCVSS 8.8No exploitEPSS 0%

    wolfssl · wolfsslAug 29, 2024

  • A use-after-free vulnerability exists in the RS-274X aperture definition tokenization functionality of Gerbv 2.7.0 and dev (commit b5f1eacd)

    HighCVSS 8.6No exploitEPSS 1%

    gerbv project · gerbvFeb 4, 2022

  • Junos OS: SRX Series: If a specific request is processed by the DNS subsystem flowd will crash

    HighCVSS 8.7No exploitEPSS 0%

    juniper · junosJan 15, 2026

  • BIG-IP Advanced WAF and ASM vulnerability

    HighCVSS 8.7No exploitEPSS 0%

    f5 · big-ip application security managerMay 13, 2026

  • BIG-IP Advanced WAF and ASM vulnerability

    HighCVSS 8.7No exploitEPSS 0%

    f5 · big-ip advanced web application firewallOct 15, 2025

  • Apache Accumulo Improper Handling of Insufficient Permissions

    HighCVSS 8.1Proof of conceptEPSS 4%

    apache · accumuloDec 29, 2020

  • An issue in Pure Data 0.54-0 and fixed in 0.54-1 allows a local attacker to escalate privileges via the set*id () function.

    HighCVSS 8.4No exploitEPSS 0%

    Sep 20, 2024

  • CVE-2025-0028
    33Monitor

    An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to read or modify an arbitrary address

    HighCVSS 8.3No exploitEPSS 0%

    amd · amd ryzen™ 7035 series processors with radeon™ graphics (formerly codenamed "rembrandt r")May 14, 2026

All vulnerability classes