CWE-391 · 26 записей
Unchecked Error Condition
CVE этого класса
26 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2024-52316Proof of concept | Apache Tomcat: Authentication bypass when using Jakarta Authentication APIapache · tomcat · CWE-391 | Критическая9,8 | — | 6,2 % | 18 нояб. 2024 г. |
40В плане | CVE-2017-12183Эксплойта нет | xorg-x11-server before 1.19.5 was missing length validation in XFIXES extension allowing malicious X client to cause X server to crash or podebian · debian linux · CWE-391 | Критическая9,8 | — | 4,5 % | 24 янв. 2018 г. |
40В плане | CVE-2017-12180Эксплойта нет | xorg-x11-server before 1.19.5 was missing length validation in XFree86 VidModeExtension allowing malicious X client to cause X server to cradebian · debian linux · CWE-391 | Критическая9,8 | — | 4,5 % | 24 янв. 2018 г. |
40В плане | CVE-2017-12178Эксплойта нет | xorg-x11-server before 1.19.5 had wrong extra length check in ProcXIChangeHierarchy function allowing malicious X client to cause X server tdebian · debian linux · CWE-391 | Критическая9,8 | — | 4,4 % | 24 янв. 2018 г. |
40В плане | CVE-2017-12179Эксплойта нет | xorg-x11-server before 1.19.5 was vulnerable to integer overflow in (S)ProcXIBarrierReleasePointer functions allowing malicious X client to debian · debian linux · CWE-391 | Критическая9,8 | — | 4,4 % | 24 янв. 2018 г. |
40В плане | CVE-2017-12177Эксплойта нет | xorg-x11-server before 1.19.5 was vulnerable to integer overflow in ProcDbeGetVisualInfo function allowing malicious X client to cause X serdebian · debian linux · CWE-391 | Критическая9,8 | — | 4,4 % | 24 янв. 2018 г. |
40В плане | CVE-2017-12186Эксплойта нет | xorg-x11-server before 1.19.5 was missing length validation in X-Resource extension allowing malicious X client to cause X server to crash odebian · debian linux · CWE-391 | Критическая9,8 | — | 4,3 % | 24 янв. 2018 г. |
40В плане | CVE-2017-12182Эксплойта нет | xorg-x11-server before 1.19.5 was missing length validation in XFree86 DRI extension allowing malicious X client to cause X server to crash debian · debian linux · CWE-391 | Критическая9,8 | — | 4,2 % | 24 янв. 2018 г. |
40В плане | CVE-2017-12181Эксплойта нет | xorg-x11-server before 1.19.5 was missing length validation in XFree86 DGA extension allowing malicious X client to cause X server to crash debian · debian linux · CWE-391 | Критическая9,8 | — | 4,2 % | 24 янв. 2018 г. |
40В плане | CVE-2017-12184Эксплойта нет | xorg-x11-server before 1.19.5 was missing length validation in XINERAMA extension allowing malicious X client to cause X server to crash or debian · debian linux · CWE-391 | Критическая9,8 | — | 4,2 % | 24 янв. 2018 г. |
40В плане | CVE-2017-12185Эксплойта нет | xorg-x11-server before 1.19.5 was missing length validation in MIT-SCREEN-SAVER extension allowing malicious X client to cause X server to cdebian · debian linux · CWE-391 | Критическая9,8 | — | 4,2 % | 24 янв. 2018 г. |
40В плане | CVE-2017-12176Эксплойта нет | xorg-x11-server before 1.19.5 was missing extra length validation in ProcEstablishConnection function allowing malicious X client to cause Xdebian · debian linux · CWE-391 | Критическая9,8 | — | 4,2 % | 24 янв. 2018 г. |
40В плане | CVE-2017-12187Эксплойта нет | xorg-x11-server before 1.19.5 was missing length validation in RENDER extension allowing malicious X client to cause X server to crash or podebian · debian linux · CWE-391 | Критическая9,8 | — | 3,3 % | 24 янв. 2018 г. |
39Наблюдать | GHSA-5rph-q42j-36j9Эксплойта нет | Duplicate Advisory: Picklescan has pickle parsing logic flaw that leads to malicious pickle file bypassPyPI · picklescan · CWE-391 | Критическая9,8 | — | — | 17 июн. 2026 г. |
37Наблюдать | CVE-2025-71325Эксплойта нет | picklescan - Detection Bypass via STACK_GLOBAL Opcode Parsing Logic Flawpicklescan · picklescan · CWE-391 | Критическая9,3 | — | 0,6 % | 17 июн. 2026 г. |
37Наблюдать | CVE-2026-74900Эксплойта нет | openssl_encrypt before 1.4.0 Weak Shared Secret via PQC Simulation Modejahlives · openssl encrypt · CWE-391 | Критическая9,3 | — | 0,6 % | 17 авг. 2026 г. |
34Наблюдать | CVE-2016-10526Эксплойта нет | A common setup to deploy to gh-pages on every commit via a CI system is to expose a github token to ENV and to use it directly in the auth pgrunt-gh-pages project · grunt-gh-pages · CWE-391 | Высокая8,6 | — | 1,6 % | 31 мая 2018 г. |
32Наблюдать | CVE-2024-23326Эксплойта нет | Envoy incorrectly accepts HTTP 200 response for entering upgrade modeenvoyproxy · envoy · CWE-391 | Высокая8,2 | — | 0,4 % | 4 июн. 2024 г. |
31Наблюдать | CVE-2019-14853Эксплойта нет | An error-handling flaw was found in python-ecdsa before version 0.13.3.python-ecdsa project · python-ecdsa · CWE-391 | Высокая7,5 | — | 2,4 % | 26 нояб. 2019 г. |
28Наблюдать | CVE-2017-7496Эксплойта нет | fedora-arm-installer up to and including 1.99.16 is vulnerable to local privilege escalation due to lack of checking the error condition of fedoraproject · arm installer · CWE-391 | Высокая7,0 | — | 0,3 % | 26 июн. 2017 г. |
27Наблюдать | CVE-2020-14383Эксплойта нет | A flaw was found in samba's DNS server.samba · samba · CWE-391 | Средняя6,5 | — | 2,2 % | 1 дек. 2020 г. |
26Наблюдать | CVE-2022-22160Эксплойта нет | Junos OS: MX Series: The bbe-smgd process crashes if an unsupported configuration exists and a PPPoE client sends a specific messagejuniper · junos · CWE-391 | Средняя6,5 | — | 0,4 % | 18 янв. 2022 г. |
24Наблюдать | CVE-2022-20849Эксплойта нет | Cisco IOS XR Software Broadband Network Gateway PPPoE Denial of Service Vulnerabilitycisco · ios xr · CWE-391 | Средняя6,1 | — | 0,3 % | 15 нояб. 2024 г. |
22Наблюдать | CVE-2018-1091Эксплойта нет | In the flush_tmregs_to_thread function in arch/powerpc/kernel/ptrace.c in the Linux kernel before 4.13.5, a guest kernel crash can be triggelinux · linux kernel · CWE-391 | Средняя5,5 | — | 0,4 % | 27 мар. 2018 г. |
21Наблюдать | CVE-2023-0572Эксплойта нет | Unchecked Error Condition in froxlor/froxlorfroxlor · froxlor · CWE-391 | Средняя5,3 | — | 0,7 % | 29 янв. 2023 г. |
- CVE-2024-5231641В плане
Apache Tomcat: Authentication bypass when using Jakarta Authentication API
КритическаяCVSS 9,8Proof of conceptEPSS 6 %apache · tomcat18 нояб. 2024 г.
- CVE-2017-1218340В плане
xorg-x11-server before 1.19.5 was missing length validation in XFIXES extension allowing malicious X client to cause X server to crash or po
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %debian · debian linux24 янв. 2018 г.
- CVE-2017-1218040В плане
xorg-x11-server before 1.19.5 was missing length validation in XFree86 VidModeExtension allowing malicious X client to cause X server to cra
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %debian · debian linux24 янв. 2018 г.
- CVE-2017-1217840В плане
xorg-x11-server before 1.19.5 had wrong extra length check in ProcXIChangeHierarchy function allowing malicious X client to cause X server t
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %debian · debian linux24 янв. 2018 г.
- CVE-2017-1217940В плане
xorg-x11-server before 1.19.5 was vulnerable to integer overflow in (S)ProcXIBarrierReleasePointer functions allowing malicious X client to
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %debian · debian linux24 янв. 2018 г.
- CVE-2017-1217740В плане
xorg-x11-server before 1.19.5 was vulnerable to integer overflow in ProcDbeGetVisualInfo function allowing malicious X client to cause X ser
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %debian · debian linux24 янв. 2018 г.
- CVE-2017-1218640В плане
xorg-x11-server before 1.19.5 was missing length validation in X-Resource extension allowing malicious X client to cause X server to crash o
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %debian · debian linux24 янв. 2018 г.
- CVE-2017-1218240В плане
xorg-x11-server before 1.19.5 was missing length validation in XFree86 DRI extension allowing malicious X client to cause X server to crash
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %debian · debian linux24 янв. 2018 г.
- CVE-2017-1218140В плане
xorg-x11-server before 1.19.5 was missing length validation in XFree86 DGA extension allowing malicious X client to cause X server to crash
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %debian · debian linux24 янв. 2018 г.
- CVE-2017-1218440В плане
xorg-x11-server before 1.19.5 was missing length validation in XINERAMA extension allowing malicious X client to cause X server to crash or
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %debian · debian linux24 янв. 2018 г.
- CVE-2017-1218540В плане
xorg-x11-server before 1.19.5 was missing length validation in MIT-SCREEN-SAVER extension allowing malicious X client to cause X server to c
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %debian · debian linux24 янв. 2018 г.
- CVE-2017-1217640В плане
xorg-x11-server before 1.19.5 was missing extra length validation in ProcEstablishConnection function allowing malicious X client to cause X
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %debian · debian linux24 янв. 2018 г.
- CVE-2017-1218740В плане
xorg-x11-server before 1.19.5 was missing length validation in RENDER extension allowing malicious X client to cause X server to crash or po
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %debian · debian linux24 янв. 2018 г.
- GHSA-5rph-q42j-36j939Наблюдать
Duplicate Advisory: Picklescan has pickle parsing logic flaw that leads to malicious pickle file bypass
КритическаяCVSS 9,8Эксплойта нетPyPI · picklescan17 июн. 2026 г.
- CVE-2025-7132537Наблюдать
picklescan - Detection Bypass via STACK_GLOBAL Opcode Parsing Logic Flaw
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %picklescan · picklescan17 июн. 2026 г.
- CVE-2026-7490037Наблюдать
openssl_encrypt before 1.4.0 Weak Shared Secret via PQC Simulation Mode
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %jahlives · openssl encrypt17 авг. 2026 г.
- CVE-2016-1052634Наблюдать
A common setup to deploy to gh-pages on every commit via a CI system is to expose a github token to ENV and to use it directly in the auth p
ВысокаяCVSS 8,6Эксплойта нетEPSS 2 %grunt-gh-pages project · grunt-gh-pages31 мая 2018 г.
- CVE-2024-2332632Наблюдать
Envoy incorrectly accepts HTTP 200 response for entering upgrade mode
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %envoyproxy · envoy4 июн. 2024 г.
- CVE-2019-1485331Наблюдать
An error-handling flaw was found in python-ecdsa before version 0.13.3.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %python-ecdsa project · python-ecdsa26 нояб. 2019 г.
- CVE-2017-749628Наблюдать
fedora-arm-installer up to and including 1.99.16 is vulnerable to local privilege escalation due to lack of checking the error condition of
ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %fedoraproject · arm installer26 июн. 2017 г.
- CVE-2020-1438327Наблюдать
A flaw was found in samba's DNS server.
СредняяCVSS 6,5Эксплойта нетEPSS 2 %samba · samba1 дек. 2020 г.
- CVE-2022-2216026Наблюдать
Junos OS: MX Series: The bbe-smgd process crashes if an unsupported configuration exists and a PPPoE client sends a specific message
СредняяCVSS 6,5Эксплойта нетEPSS 0 %juniper · junos18 янв. 2022 г.
- CVE-2022-2084924Наблюдать
Cisco IOS XR Software Broadband Network Gateway PPPoE Denial of Service Vulnerability
СредняяCVSS 6,1Эксплойта нетEPSS 0 %cisco · ios xr15 нояб. 2024 г.
- CVE-2018-109122Наблюдать
In the flush_tmregs_to_thread function in arch/powerpc/kernel/ptrace.c in the Linux kernel before 4.13.5, a guest kernel crash can be trigge
СредняяCVSS 5,5Эксплойта нетEPSS 0 %linux · linux kernel27 мар. 2018 г.
- CVE-2023-057221Наблюдать
Unchecked Error Condition in froxlor/froxlor
СредняяCVSS 5,3Эксплойта нетEPSS 1 %froxlor · froxlor29 янв. 2023 г.