CWE-252 · 161 records
Unchecked Return Value
CVEs in this class
161 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
60This week | CVE-2007-3798Proof of concept | Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via craftcpdump · tcpdump · CWE-252 | Critical9.8 | — | 70.4% | Jul 16, 2007 |
57Plan | CVE-2005-4360Proof of concept | The URL parser in Microsoft Internet Information Services (IIS) 5.1 on Windows XP Professional SP2 allows remote attackers to execute arbitrmicrosoft · internet information services · CWE-252 | High7.8 | — | 86.7% | Dec 19, 2005 |
48Plan | CVE-2010-0211Proof of concept | The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which openldap · openldap · CWE-252 | Critical9.8 | — | 28.5% | Jul 28, 2010 |
40Plan | CVE-2021-38171No exploit | adts_decode_extradata in libavformat/adtsenc.c in FFmpeg 4.4 does not check the init_get_bits return value, which is a necessary step becausffmpeg · ffmpeg · CWE-252 | Critical9.8 | — | 2.4% | Aug 21, 2021 |
40Plan | CVE-1999-0199No exploit | manual/search.texi in the GNU C Library (aka glibc) before 2.2 lacks a statement about the unspecified tdelete return value upon deletion ofgnu · glibc · CWE-252 | Critical9.8 | — | 2.4% | Oct 6, 2020 |
40Plan | CVE-2019-15900No exploit | An issue was discovered in slicer69 doas before 6.2 on certain platforms other than OpenBSD.doas project · doas · CWE-252 | Critical9.8 | — | 2.1% | Oct 18, 2019 |
40Plan | CVE-2021-26955No exploit | An issue was discovered in the xcb crate through 2021-02-04 for Rust.xcb project · xcb · CWE-252 | Critical9.8 | — | 1.7% | Feb 9, 2021 |
39Monitor | CVE-2022-25718No exploit | Cryptographic issue in WLAN due to improper check on return value while authentication handshake in Snapdragon Auto, Snapdragon Connectivityqualcomm · apq8009 firmware · CWE-252 | Critical9.8 | — | 0.4% | Oct 19, 2022 |
37Monitor | CVE-2022-23806No exploit | Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int vagolang · go · CWE-252 | Critical9.1 | — | 3.1% | Feb 10, 2022 |
37Monitor | CVE-2025-66565No exploit | Fiber Utils UUIDv4 and UUID Silent Fallback to Predictable Valuesgofiber · utils · CWE-252 | Critical9.3 | — | 0.5% | Dec 9, 2025 |
36Monitor | CVE-2019-15942No exploit | FFmpeg through 4.2 has a "Conditional jump or move depends on uninitialised value" issue in h2645_parse because alloc_rbsp_buffer in libavcoffmpeg · ffmpeg · CWE-252 | High8.8 | — | 2.0% | Sep 5, 2019 |
36Monitor | CVE-2024-50306No exploit | Apache Traffic Server: Server process can fail to drop privilegeapache · traffic server · CWE-252 | Critical9.1 | — | 1.6% | Nov 14, 2024 |
35Monitor | CVE-2021-26958No exploit | An issue was discovered in the xcb crate through 2021-02-04 for Rust.xcb project · xcb · CWE-252 | High8.8 | — | 1.6% | Feb 9, 2021 |
35Monitor | CVE-2023-44182No exploit | Junos OS and Junos OS Evolved: An Unchecked Return Value in multiple users interfaces affects confidentiality and integrity of device operationsjuniper · junos · CWE-252 | High8.8 | — | 0.6% | Oct 12, 2023 |
35Monitor | CVE-2024-1545No exploit | Fault Injection of RSA encryption in WolfCryptwolfssl · wolfssl · CWE-252 | High8.8 | — | 0.6% | Aug 29, 2024 |
35Monitor | CVE-2024-38427No exploit | In International Color Consortium DemoIccMAX before 85ce74e, a logic flaw in CIccTagXmlProfileSequenceId::ParseXml in IccXML/IccLibXML/IccTaCWE-252 | High8.8 | — | 0.5% | Jun 15, 2024 |
35Monitor | CVE-2025-46672No exploit | NASA CryptoLib before 1.3.2 does not check the OTAR crypto function returned status, potentially leading to spacecraft hijacking.nasa · cryptolib · CWE-252 | High8.8 | — | 0.5% | Apr 26, 2025 |
35Monitor | CVE-2024-2881No exploit | Fault Injection of EdDSA signature in WolfCryptwolfssl · wolfssl · CWE-252 | High8.8 | — | 0.5% | Aug 29, 2024 |
34Monitor | CVE-2021-40401No exploit | A use-after-free vulnerability exists in the RS-274X aperture definition tokenization functionality of Gerbv 2.7.0 and dev (commit b5f1eacd)gerbv project · gerbv · CWE-252 | High8.6 | — | 1.3% | Feb 4, 2022 |
34Monitor | CVE-2026-21920No exploit | Junos OS: SRX Series: If a specific request is processed by the DNS subsystem flowd will crashjuniper · junos · CWE-252 | High8.7 | — | 0.5% | Jan 15, 2026 |
34Monitor | CVE-2026-40060No exploit | BIG-IP Advanced WAF and ASM vulnerabilityf5 · big-ip application security manager · CWE-252 | High8.7 | — | 0.5% | May 13, 2026 |
34Monitor | CVE-2025-61935No exploit | BIG-IP Advanced WAF and ASM vulnerabilityf5 · big-ip advanced web application firewall · CWE-252 | High8.7 | — | 0.3% | Oct 15, 2025 |
33Monitor | CVE-2020-17533Proof of concept | Apache Accumulo Improper Handling of Insufficient Permissionsapache · accumulo · CWE-252 | High8.1 | — | 3.7% | Dec 29, 2020 |
33Monitor | CVE-2023-47480No exploit | An issue in Pure Data 0.54-0 and fixed in 0.54-1 allows a local attacker to escalate privileges via the set*id () function.CWE-252 | High8.4 | — | 0.2% | Sep 20, 2024 |
33Monitor | CVE-2025-0028No exploit | An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to read or modify an arbitrary addressamd · amd ryzen™ 7035 series processors with radeon™ graphics (formerly codenamed "rembrandt r") · CWE-252 | High8.3 | — | 0.1% | May 14, 2026 |
- CVE-2007-379860This week
Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via craf
CriticalCVSS 9.8Proof of conceptEPSS 70%tcpdump · tcpdumpJul 16, 2007
- CVE-2005-436057Plan
The URL parser in Microsoft Internet Information Services (IIS) 5.1 on Windows XP Professional SP2 allows remote attackers to execute arbitr
HighCVSS 7.8Proof of conceptEPSS 87%microsoft · internet information servicesDec 19, 2005
- CVE-2010-021148Plan
The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which
CriticalCVSS 9.8Proof of conceptEPSS 28%openldap · openldapJul 28, 2010
- CVE-2021-3817140Plan
adts_decode_extradata in libavformat/adtsenc.c in FFmpeg 4.4 does not check the init_get_bits return value, which is a necessary step becaus
CriticalCVSS 9.8No exploitEPSS 2%ffmpeg · ffmpegAug 21, 2021
- CVE-1999-019940Plan
manual/search.texi in the GNU C Library (aka glibc) before 2.2 lacks a statement about the unspecified tdelete return value upon deletion of
CriticalCVSS 9.8No exploitEPSS 2%gnu · glibcOct 6, 2020
- CVE-2019-1590040Plan
An issue was discovered in slicer69 doas before 6.2 on certain platforms other than OpenBSD.
CriticalCVSS 9.8No exploitEPSS 2%doas project · doasOct 18, 2019
- CVE-2021-2695540Plan
An issue was discovered in the xcb crate through 2021-02-04 for Rust.
CriticalCVSS 9.8No exploitEPSS 2%xcb project · xcbFeb 9, 2021
- CVE-2022-2571839Monitor
Cryptographic issue in WLAN due to improper check on return value while authentication handshake in Snapdragon Auto, Snapdragon Connectivity
CriticalCVSS 9.8No exploitEPSS 0%qualcomm · apq8009 firmwareOct 19, 2022
- CVE-2022-2380637Monitor
Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int va
CriticalCVSS 9.1No exploitEPSS 3%golang · goFeb 10, 2022
- CVE-2025-6656537Monitor
Fiber Utils UUIDv4 and UUID Silent Fallback to Predictable Values
CriticalCVSS 9.3No exploitEPSS 0%gofiber · utilsDec 9, 2025
- CVE-2019-1594236Monitor
FFmpeg through 4.2 has a "Conditional jump or move depends on uninitialised value" issue in h2645_parse because alloc_rbsp_buffer in libavco
HighCVSS 8.8No exploitEPSS 2%ffmpeg · ffmpegSep 5, 2019
- CVE-2024-5030636Monitor
Apache Traffic Server: Server process can fail to drop privilege
CriticalCVSS 9.1No exploitEPSS 2%apache · traffic serverNov 14, 2024
- CVE-2021-2695835Monitor
An issue was discovered in the xcb crate through 2021-02-04 for Rust.
HighCVSS 8.8No exploitEPSS 2%xcb project · xcbFeb 9, 2021
- CVE-2023-4418235Monitor
Junos OS and Junos OS Evolved: An Unchecked Return Value in multiple users interfaces affects confidentiality and integrity of device operations
HighCVSS 8.8No exploitEPSS 1%juniper · junosOct 12, 2023
- CVE-2024-154535Monitor
Fault Injection of RSA encryption in WolfCrypt
HighCVSS 8.8No exploitEPSS 1%wolfssl · wolfsslAug 29, 2024
- CVE-2024-3842735Monitor
In International Color Consortium DemoIccMAX before 85ce74e, a logic flaw in CIccTagXmlProfileSequenceId::ParseXml in IccXML/IccLibXML/IccTa
HighCVSS 8.8No exploitEPSS 1%Jun 15, 2024
- CVE-2025-4667235Monitor
NASA CryptoLib before 1.3.2 does not check the OTAR crypto function returned status, potentially leading to spacecraft hijacking.
HighCVSS 8.8No exploitEPSS 1%nasa · cryptolibApr 26, 2025
- CVE-2024-288135Monitor
Fault Injection of EdDSA signature in WolfCrypt
HighCVSS 8.8No exploitEPSS 0%wolfssl · wolfsslAug 29, 2024
- CVE-2021-4040134Monitor
A use-after-free vulnerability exists in the RS-274X aperture definition tokenization functionality of Gerbv 2.7.0 and dev (commit b5f1eacd)
HighCVSS 8.6No exploitEPSS 1%gerbv project · gerbvFeb 4, 2022
- CVE-2026-2192034Monitor
Junos OS: SRX Series: If a specific request is processed by the DNS subsystem flowd will crash
HighCVSS 8.7No exploitEPSS 0%juniper · junosJan 15, 2026
- CVE-2026-4006034Monitor
BIG-IP Advanced WAF and ASM vulnerability
HighCVSS 8.7No exploitEPSS 0%f5 · big-ip application security managerMay 13, 2026
- CVE-2025-6193534Monitor
BIG-IP Advanced WAF and ASM vulnerability
HighCVSS 8.7No exploitEPSS 0%f5 · big-ip advanced web application firewallOct 15, 2025
- CVE-2020-1753333Monitor
Apache Accumulo Improper Handling of Insufficient Permissions
HighCVSS 8.1Proof of conceptEPSS 4%apache · accumuloDec 29, 2020
- CVE-2023-4748033Monitor
An issue in Pure Data 0.54-0 and fixed in 0.54-1 allows a local attacker to escalate privileges via the set*id () function.
HighCVSS 8.4No exploitEPSS 0%Sep 20, 2024
- CVE-2025-002833Monitor
An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to read or modify an arbitrary address
HighCVSS 8.3No exploitEPSS 0%amd · amd ryzen™ 7035 series processors with radeon™ graphics (formerly codenamed "rembrandt r")May 14, 2026