CWE-252 · 161 записей
Unchecked Return Value
CVE этого класса
161 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
60На этой неделе | CVE-2007-3798Proof of concept | Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via craftcpdump · tcpdump · CWE-252 | Критическая9,8 | — | 70,4 % | 16 июл. 2007 г. |
57В плане | CVE-2005-4360Proof of concept | The URL parser in Microsoft Internet Information Services (IIS) 5.1 on Windows XP Professional SP2 allows remote attackers to execute arbitrmicrosoft · internet information services · CWE-252 | Высокая7,8 | — | 86,7 % | 19 дек. 2005 г. |
48В плане | CVE-2010-0211Proof of concept | The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which openldap · openldap · CWE-252 | Критическая9,8 | — | 28,5 % | 28 июл. 2010 г. |
40В плане | CVE-2021-38171Эксплойта нет | adts_decode_extradata in libavformat/adtsenc.c in FFmpeg 4.4 does not check the init_get_bits return value, which is a necessary step becausffmpeg · ffmpeg · CWE-252 | Критическая9,8 | — | 2,4 % | 21 авг. 2021 г. |
40В плане | CVE-1999-0199Эксплойта нет | manual/search.texi in the GNU C Library (aka glibc) before 2.2 lacks a statement about the unspecified tdelete return value upon deletion ofgnu · glibc · CWE-252 | Критическая9,8 | — | 2,4 % | 6 окт. 2020 г. |
40В плане | CVE-2019-15900Эксплойта нет | An issue was discovered in slicer69 doas before 6.2 on certain platforms other than OpenBSD.doas project · doas · CWE-252 | Критическая9,8 | — | 2,1 % | 18 окт. 2019 г. |
40В плане | CVE-2021-26955Эксплойта нет | An issue was discovered in the xcb crate through 2021-02-04 for Rust.xcb project · xcb · CWE-252 | Критическая9,8 | — | 1,7 % | 9 февр. 2021 г. |
39Наблюдать | CVE-2022-25718Эксплойта нет | Cryptographic issue in WLAN due to improper check on return value while authentication handshake in Snapdragon Auto, Snapdragon Connectivityqualcomm · apq8009 firmware · CWE-252 | Критическая9,8 | — | 0,4 % | 19 окт. 2022 г. |
37Наблюдать | CVE-2022-23806Эксплойта нет | Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int vagolang · go · CWE-252 | Критическая9,1 | — | 3,1 % | 10 февр. 2022 г. |
37Наблюдать | CVE-2025-66565Эксплойта нет | Fiber Utils UUIDv4 and UUID Silent Fallback to Predictable Valuesgofiber · utils · CWE-252 | Критическая9,3 | — | 0,5 % | 9 дек. 2025 г. |
36Наблюдать | CVE-2019-15942Эксплойта нет | FFmpeg through 4.2 has a "Conditional jump or move depends on uninitialised value" issue in h2645_parse because alloc_rbsp_buffer in libavcoffmpeg · ffmpeg · CWE-252 | Высокая8,8 | — | 2,0 % | 5 сент. 2019 г. |
36Наблюдать | CVE-2024-50306Эксплойта нет | Apache Traffic Server: Server process can fail to drop privilegeapache · traffic server · CWE-252 | Критическая9,1 | — | 1,6 % | 14 нояб. 2024 г. |
35Наблюдать | CVE-2021-26958Эксплойта нет | An issue was discovered in the xcb crate through 2021-02-04 for Rust.xcb project · xcb · CWE-252 | Высокая8,8 | — | 1,6 % | 9 февр. 2021 г. |
35Наблюдать | CVE-2023-44182Эксплойта нет | Junos OS and Junos OS Evolved: An Unchecked Return Value in multiple users interfaces affects confidentiality and integrity of device operationsjuniper · junos · CWE-252 | Высокая8,8 | — | 0,6 % | 12 окт. 2023 г. |
35Наблюдать | CVE-2024-1545Эксплойта нет | Fault Injection of RSA encryption in WolfCryptwolfssl · wolfssl · CWE-252 | Высокая8,8 | — | 0,6 % | 29 авг. 2024 г. |
35Наблюдать | CVE-2024-38427Эксплойта нет | In International Color Consortium DemoIccMAX before 85ce74e, a logic flaw in CIccTagXmlProfileSequenceId::ParseXml in IccXML/IccLibXML/IccTaCWE-252 | Высокая8,8 | — | 0,5 % | 15 июн. 2024 г. |
35Наблюдать | CVE-2025-46672Эксплойта нет | NASA CryptoLib before 1.3.2 does not check the OTAR crypto function returned status, potentially leading to spacecraft hijacking.nasa · cryptolib · CWE-252 | Высокая8,8 | — | 0,5 % | 26 апр. 2025 г. |
35Наблюдать | CVE-2024-2881Эксплойта нет | Fault Injection of EdDSA signature in WolfCryptwolfssl · wolfssl · CWE-252 | Высокая8,8 | — | 0,5 % | 29 авг. 2024 г. |
34Наблюдать | CVE-2021-40401Эксплойта нет | A use-after-free vulnerability exists in the RS-274X aperture definition tokenization functionality of Gerbv 2.7.0 and dev (commit b5f1eacd)gerbv project · gerbv · CWE-252 | Высокая8,6 | — | 1,3 % | 4 февр. 2022 г. |
34Наблюдать | CVE-2026-21920Эксплойта нет | Junos OS: SRX Series: If a specific request is processed by the DNS subsystem flowd will crashjuniper · junos · CWE-252 | Высокая8,7 | — | 0,5 % | 15 янв. 2026 г. |
34Наблюдать | CVE-2026-40060Эксплойта нет | BIG-IP Advanced WAF and ASM vulnerabilityf5 · big-ip application security manager · CWE-252 | Высокая8,7 | — | 0,5 % | 13 мая 2026 г. |
34Наблюдать | CVE-2025-61935Эксплойта нет | BIG-IP Advanced WAF and ASM vulnerabilityf5 · big-ip advanced web application firewall · CWE-252 | Высокая8,7 | — | 0,3 % | 15 окт. 2025 г. |
33Наблюдать | CVE-2020-17533Proof of concept | Apache Accumulo Improper Handling of Insufficient Permissionsapache · accumulo · CWE-252 | Высокая8,1 | — | 3,7 % | 29 дек. 2020 г. |
33Наблюдать | CVE-2023-47480Эксплойта нет | An issue in Pure Data 0.54-0 and fixed in 0.54-1 allows a local attacker to escalate privileges via the set*id () function.CWE-252 | Высокая8,4 | — | 0,2 % | 20 сент. 2024 г. |
33Наблюдать | CVE-2025-0028Эксплойта нет | An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to read or modify an arbitrary addressamd · amd ryzen™ 7035 series processors with radeon™ graphics (formerly codenamed "rembrandt r") · CWE-252 | Высокая8,3 | — | 0,1 % | 14 мая 2026 г. |
- CVE-2007-379860На этой неделе
Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via craf
КритическаяCVSS 9,8Proof of conceptEPSS 70 %tcpdump · tcpdump16 июл. 2007 г.
- CVE-2005-436057В плане
The URL parser in Microsoft Internet Information Services (IIS) 5.1 on Windows XP Professional SP2 allows remote attackers to execute arbitr
ВысокаяCVSS 7,8Proof of conceptEPSS 87 %microsoft · internet information services19 дек. 2005 г.
- CVE-2010-021148В плане
The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which
КритическаяCVSS 9,8Proof of conceptEPSS 28 %openldap · openldap28 июл. 2010 г.
- CVE-2021-3817140В плане
adts_decode_extradata in libavformat/adtsenc.c in FFmpeg 4.4 does not check the init_get_bits return value, which is a necessary step becaus
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %ffmpeg · ffmpeg21 авг. 2021 г.
- CVE-1999-019940В плане
manual/search.texi in the GNU C Library (aka glibc) before 2.2 lacks a statement about the unspecified tdelete return value upon deletion of
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %gnu · glibc6 окт. 2020 г.
- CVE-2019-1590040В плане
An issue was discovered in slicer69 doas before 6.2 on certain platforms other than OpenBSD.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %doas project · doas18 окт. 2019 г.
- CVE-2021-2695540В плане
An issue was discovered in the xcb crate through 2021-02-04 for Rust.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %xcb project · xcb9 февр. 2021 г.
- CVE-2022-2571839Наблюдать
Cryptographic issue in WLAN due to improper check on return value while authentication handshake in Snapdragon Auto, Snapdragon Connectivity
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %qualcomm · apq8009 firmware19 окт. 2022 г.
- CVE-2022-2380637Наблюдать
Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int va
КритическаяCVSS 9,1Эксплойта нетEPSS 3 %golang · go10 февр. 2022 г.
- CVE-2025-6656537Наблюдать
Fiber Utils UUIDv4 and UUID Silent Fallback to Predictable Values
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %gofiber · utils9 дек. 2025 г.
- CVE-2019-1594236Наблюдать
FFmpeg through 4.2 has a "Conditional jump or move depends on uninitialised value" issue in h2645_parse because alloc_rbsp_buffer in libavco
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %ffmpeg · ffmpeg5 сент. 2019 г.
- CVE-2024-5030636Наблюдать
Apache Traffic Server: Server process can fail to drop privilege
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %apache · traffic server14 нояб. 2024 г.
- CVE-2021-2695835Наблюдать
An issue was discovered in the xcb crate through 2021-02-04 for Rust.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %xcb project · xcb9 февр. 2021 г.
- CVE-2023-4418235Наблюдать
Junos OS and Junos OS Evolved: An Unchecked Return Value in multiple users interfaces affects confidentiality and integrity of device operations
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %juniper · junos12 окт. 2023 г.
- CVE-2024-154535Наблюдать
Fault Injection of RSA encryption in WolfCrypt
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %wolfssl · wolfssl29 авг. 2024 г.
- CVE-2024-3842735Наблюдать
In International Color Consortium DemoIccMAX before 85ce74e, a logic flaw in CIccTagXmlProfileSequenceId::ParseXml in IccXML/IccLibXML/IccTa
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %15 июн. 2024 г.
- CVE-2025-4667235Наблюдать
NASA CryptoLib before 1.3.2 does not check the OTAR crypto function returned status, potentially leading to spacecraft hijacking.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %nasa · cryptolib26 апр. 2025 г.
- CVE-2024-288135Наблюдать
Fault Injection of EdDSA signature in WolfCrypt
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %wolfssl · wolfssl29 авг. 2024 г.
- CVE-2021-4040134Наблюдать
A use-after-free vulnerability exists in the RS-274X aperture definition tokenization functionality of Gerbv 2.7.0 and dev (commit b5f1eacd)
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %gerbv project · gerbv4 февр. 2022 г.
- CVE-2026-2192034Наблюдать
Junos OS: SRX Series: If a specific request is processed by the DNS subsystem flowd will crash
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %juniper · junos15 янв. 2026 г.
- CVE-2026-4006034Наблюдать
BIG-IP Advanced WAF and ASM vulnerability
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %f5 · big-ip application security manager13 мая 2026 г.
- CVE-2025-6193534Наблюдать
BIG-IP Advanced WAF and ASM vulnerability
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %f5 · big-ip advanced web application firewall15 окт. 2025 г.
- CVE-2020-1753333Наблюдать
Apache Accumulo Improper Handling of Insufficient Permissions
ВысокаяCVSS 8,1Proof of conceptEPSS 4 %apache · accumulo29 дек. 2020 г.
- CVE-2023-4748033Наблюдать
An issue in Pure Data 0.54-0 and fixed in 0.54-1 allows a local attacker to escalate privileges via the set*id () function.
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %20 сент. 2024 г.
- CVE-2025-002833Наблюдать
An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to read or modify an arbitrary address
ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %amd · amd ryzen™ 7035 series processors with radeon™ graphics (formerly codenamed "rembrandt r")14 мая 2026 г.