CWE-253 · 24 записей
Incorrect Check of Function Return Value
CVE этого класса
24 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2017-7474Эксплойта нет | It was found that the Keycloak Node.js adapter 2.5 - 3.0 did not handle invalid tokens correctly.keycloak · keycloak-nodejs-auth-utils · CWE-253 | Критическая9,8 | — | 2,5 % | 12 мая 2017 г. |
39Наблюдать | CVE-2023-4501Эксплойта нет | Authentication bypass in OpenText (Micro Focus) Enterprise Servermicrofocus · cobol server · CWE-253 | Критическая9,8 | — | 0,8 % | 12 сент. 2023 г. |
33Наблюдать | CVE-2023-49286Эксплойта нет | Denial of Service in Helper Process managementsquid-cache · squid · CWE-253 | Высокая7,5 | — | 10,4 % | 4 дек. 2023 г. |
32Наблюдать | CVE-2026-35091Эксплойта нет | Corosync: corosync: denial of service and information disclosure via crafted udp packetcorosync · corosync · CWE-253 | Высокая8,2 | — | 1,1 % | 1 апр. 2026 г. |
31Наблюдать | CVE-2024-43521Эксплойта нет | Windows Hyper-V Denial of Service Vulnerabilitymicrosoft · windows server 2012 · CWE-253 | Высокая7,5 | — | 2,4 % | 8 окт. 2024 г. |
31Наблюдать | CVE-2026-53090Эксплойта нет | bpf: Fix ld_{abs,ind} failure path analysis in subprogslinux · linux kernel · CWE-253 | Высокая7,8 | — | 0,2 % | 24 июн. 2026 г. |
30Наблюдать | CVE-2023-24487Эксплойта нет | Arbitrary file read in Citrix ADC and Citrix Gateway citrix · application delivery controller · CWE-253 | Высокая7,5 | — | 1,1 % | 10 июл. 2023 г. |
30Наблюдать | CVE-2024-1622Эксплойта нет | Routinator terminates when RTR connection is reset too quickly after openingnlnetlabs · routinator · CWE-253 | Высокая7,5 | — | 1,0 % | 26 февр. 2024 г. |
30Наблюдать | CVE-2024-32475Эксплойта нет | Envoy RELEASE_ASSERT using auto_sni with :authority header > 255 bytesenvoyproxy · envoy · CWE-253 | Высокая7,5 | — | 0,7 % | 18 апр. 2024 г. |
30Наблюдать | CVE-2026-59847Эксплойта нет | Libssh: libssh: integrity downgrade via openssl aes-gcm tag verificationlibssh · libssh · CWE-253 | Высокая7,5 | — | 0,6 % | 21 июл. 2026 г. |
30Наблюдать | CVE-2026-46419Эксплойта нет | Yubico webauthn-server-core (aka java-webauthn-server) 2.8.0 before 2.8.2 incorrectly checks a function's return value in the second factor yubico · webauthn-server-core · CWE-253 | Высокая7,5 | — | 0,4 % | 13 мая 2026 г. |
30Наблюдать | CVE-2025-57767Эксплойта нет | Asterisk can crash from a specifically malformed Authorization header in an incoming SIP requestsangoma · asterisk · CWE-253 | Высокая7,5 | — | 0,4 % | 28 авг. 2025 г. |
28Наблюдать | CVE-2026-15686Эксплойта нет | Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerabilityadminer · adminer · CWE-253 | Высокая7,2 | — | 0,7 % | 20 авг. 2026 г. |
28Наблюдать | CVE-2026-5818Эксплойта нет | MCU Firmware Update Authentication Bypass on Caliptra Corecaliptra · core runtime firmware · CWE-253 | Высокая7,2 | — | 0,2 % | 23 июн. 2026 г. |
25Наблюдать | CVE-2025-54090Эксплойта нет | Apache HTTP Server: 'RewriteCond expr' always evaluates to true in 2.4.64apache · http server · CWE-253 | Средняя6,3 | — | 0,8 % | 23 июл. 2025 г. |
25Наблюдать | CVE-2026-0648Эксплойта нет | The vulnerability stems from an incorrect error-checking logic in the CreateCounter() function (in threadx/utility/rtos_compatibility_layerseclipse · threadx · CWE-253 | Средняя6,3 | — | 0,1 % | 27 янв. 2026 г. |
22Наблюдать | CVE-2020-6107Эксплойта нет | An exploitable information disclosure vulnerability exists in the dev_read functionality of F2fs-Tools F2fs.Fsck 1.13.f2fs-tools project · f2fs-tools · CWE-253 | Средняя5,5 | — | 1,5 % | 15 окт. 2020 г. |
22Наблюдать | CVE-2026-35340Эксплойта нет | uutils coreutils chown and chgrp False Success Exit Code in Recursive Modeuutils · coreutils · CWE-253 | Средняя5,5 | — | 0,2 % | 22 апр. 2026 г. |
22Наблюдать | CVE-2026-35339Эксплойта нет | uutils coreutils chmod False Success Exit Code in Recursive Modeuutils · coreutils · CWE-253 | Средняя5,5 | — | 0,2 % | 22 апр. 2026 г. |
22Наблюдать | GHSA-88ch-q68x-36v7Эксплойта нет | Duplicate Advisory: uutils coreutils has an Incorrect Check of Function Return Valuecrates.io · coreutils · CWE-253 | Средняя5,5 | — | — | 22 апр. 2026 г. |
22Наблюдать | GHSA-vp6q-mv9j-j428Эксплойта нет | Duplicate Advisory: uutils coreutils incorrectly handles exit codes when processing multiple filescrates.io · coreutils · CWE-253 | Средняя5,5 | — | — | 22 апр. 2026 г. |
21Наблюдать | CVE-2022-24880Эксплойта нет | Potential Captcha Validate Bypass in flask-session-captchaflask-session-captcha project · flask-session-captcha · CWE-253 | Средняя5,3 | — | 1,2 % | 25 апр. 2022 г. |
21Наблюдать | CVE-2023-34449Эксплойта нет | ink! vulnerable to incorrect decoding of storage value when using `DelegateCall`parity · ink\! · CWE-253 | Средняя5,3 | — | 1,0 % | 14 июн. 2023 г. |
14Наблюдать | CVE-2026-43863Эксплойта нет | mutt before 2.3.2 has an infinite loop in data_object_to_stream in crypt-gpgme.c.mutt · mutt · CWE-253 | Низкая3,7 | — | 0,3 % | 4 мая 2026 г. |
- CVE-2017-747440В плане
It was found that the Keycloak Node.js adapter 2.5 - 3.0 did not handle invalid tokens correctly.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %keycloak · keycloak-nodejs-auth-utils12 мая 2017 г.
- CVE-2023-450139Наблюдать
Authentication bypass in OpenText (Micro Focus) Enterprise Server
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %microfocus · cobol server12 сент. 2023 г.
- CVE-2023-4928633Наблюдать
Denial of Service in Helper Process management
ВысокаяCVSS 7,5Эксплойта нетEPSS 10 %squid-cache · squid4 дек. 2023 г.
- CVE-2026-3509132Наблюдать
Corosync: corosync: denial of service and information disclosure via crafted udp packet
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %corosync · corosync1 апр. 2026 г.
- CVE-2024-4352131Наблюдать
Windows Hyper-V Denial of Service Vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %microsoft · windows server 20128 окт. 2024 г.
- CVE-2026-5309031Наблюдать
bpf: Fix ld_{abs,ind} failure path analysis in subprogs
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %linux · linux kernel24 июн. 2026 г.
- CVE-2023-2448730Наблюдать
Arbitrary file read in Citrix ADC and Citrix Gateway
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %citrix · application delivery controller10 июл. 2023 г.
- CVE-2024-162230Наблюдать
Routinator terminates when RTR connection is reset too quickly after opening
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %nlnetlabs · routinator26 февр. 2024 г.
- CVE-2024-3247530Наблюдать
Envoy RELEASE_ASSERT using auto_sni with :authority header > 255 bytes
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %envoyproxy · envoy18 апр. 2024 г.
- CVE-2026-5984730Наблюдать
Libssh: libssh: integrity downgrade via openssl aes-gcm tag verification
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %libssh · libssh21 июл. 2026 г.
- CVE-2026-4641930Наблюдать
Yubico webauthn-server-core (aka java-webauthn-server) 2.8.0 before 2.8.2 incorrectly checks a function's return value in the second factor
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %yubico · webauthn-server-core13 мая 2026 г.
- CVE-2025-5776730Наблюдать
Asterisk can crash from a specifically malformed Authorization header in an incoming SIP request
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %sangoma · asterisk28 авг. 2025 г.
- CVE-2026-1568628Наблюдать
Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %adminer · adminer20 авг. 2026 г.
- CVE-2026-581828Наблюдать
MCU Firmware Update Authentication Bypass on Caliptra Core
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %caliptra · core runtime firmware23 июн. 2026 г.
- CVE-2025-5409025Наблюдать
Apache HTTP Server: 'RewriteCond expr' always evaluates to true in 2.4.64
СредняяCVSS 6,3Эксплойта нетEPSS 1 %apache · http server23 июл. 2025 г.
- CVE-2026-064825Наблюдать
The vulnerability stems from an incorrect error-checking logic in the CreateCounter() function (in threadx/utility/rtos_compatibility_layers
СредняяCVSS 6,3Эксплойта нетEPSS 0 %eclipse · threadx27 янв. 2026 г.
- CVE-2020-610722Наблюдать
An exploitable information disclosure vulnerability exists in the dev_read functionality of F2fs-Tools F2fs.Fsck 1.13.
СредняяCVSS 5,5Эксплойта нетEPSS 2 %f2fs-tools project · f2fs-tools15 окт. 2020 г.
- CVE-2026-3534022Наблюдать
uutils coreutils chown and chgrp False Success Exit Code in Recursive Mode
СредняяCVSS 5,5Эксплойта нетEPSS 0 %uutils · coreutils22 апр. 2026 г.
- CVE-2026-3533922Наблюдать
uutils coreutils chmod False Success Exit Code in Recursive Mode
СредняяCVSS 5,5Эксплойта нетEPSS 0 %uutils · coreutils22 апр. 2026 г.
- GHSA-88ch-q68x-36v722Наблюдать
Duplicate Advisory: uutils coreutils has an Incorrect Check of Function Return Value
СредняяCVSS 5,5Эксплойта нетcrates.io · coreutils22 апр. 2026 г.
- GHSA-vp6q-mv9j-j42822Наблюдать
Duplicate Advisory: uutils coreutils incorrectly handles exit codes when processing multiple files
СредняяCVSS 5,5Эксплойта нетcrates.io · coreutils22 апр. 2026 г.
- CVE-2022-2488021Наблюдать
Potential Captcha Validate Bypass in flask-session-captcha
СредняяCVSS 5,3Эксплойта нетEPSS 1 %flask-session-captcha project · flask-session-captcha25 апр. 2022 г.
- CVE-2023-3444921Наблюдать
ink! vulnerable to incorrect decoding of storage value when using `DelegateCall`
СредняяCVSS 5,3Эксплойта нетEPSS 1 %parity · ink\!14 июн. 2023 г.
- CVE-2026-4386314Наблюдать
mutt before 2.3.2 has an infinite loop in data_object_to_stream in crypt-gpgme.c.
НизкаяCVSS 3,7Эксплойта нетEPSS 0 %mutt · mutt4 мая 2026 г.