CWE-252 · 160 kayıt
Unchecked Return Value
Bu sınıftaki CVE’ler
161 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
60Bu hafta | CVE-2007-3798Kavram kanıtı | Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via craftcpdump · tcpdump · CWE-252 | Kritik9,8 | — | %70,4 | 16 Tem 2007 |
57Planlayın | CVE-2005-4360Kavram kanıtı | The URL parser in Microsoft Internet Information Services (IIS) 5.1 on Windows XP Professional SP2 allows remote attackers to execute arbitrmicrosoft · internet information services · CWE-252 | Yüksek7,8 | — | %86,7 | 19 Ara 2005 |
48Planlayın | CVE-2010-0211Kavram kanıtı | The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which openldap · openldap · CWE-252 | Kritik9,8 | — | %28,5 | 28 Tem 2010 |
40Planlayın | CVE-2021-38171İstismar yok | adts_decode_extradata in libavformat/adtsenc.c in FFmpeg 4.4 does not check the init_get_bits return value, which is a necessary step becausffmpeg · ffmpeg · CWE-252 | Kritik9,8 | — | %2,4 | 21 Ağu 2021 |
40Planlayın | CVE-1999-0199İstismar yok | manual/search.texi in the GNU C Library (aka glibc) before 2.2 lacks a statement about the unspecified tdelete return value upon deletion ofgnu · glibc · CWE-252 | Kritik9,8 | — | %2,4 | 6 Eki 2020 |
40Planlayın | CVE-2019-15900İstismar yok | An issue was discovered in slicer69 doas before 6.2 on certain platforms other than OpenBSD.doas project · doas · CWE-252 | Kritik9,8 | — | %2,1 | 18 Eki 2019 |
40Planlayın | CVE-2021-26955İstismar yok | An issue was discovered in the xcb crate through 2021-02-04 for Rust.xcb project · xcb · CWE-252 | Kritik9,8 | — | %1,7 | 9 Şub 2021 |
39İzleyin | CVE-2022-25718İstismar yok | Cryptographic issue in WLAN due to improper check on return value while authentication handshake in Snapdragon Auto, Snapdragon Connectivityqualcomm · apq8009 firmware · CWE-252 | Kritik9,8 | — | %0,4 | 19 Eki 2022 |
37İzleyin | CVE-2022-23806İstismar yok | Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int vagolang · go · CWE-252 | Kritik9,1 | — | %3,1 | 10 Şub 2022 |
37İzleyin | CVE-2025-66565İstismar yok | Fiber Utils UUIDv4 and UUID Silent Fallback to Predictable Valuesgofiber · utils · CWE-252 | Kritik9,3 | — | %0,5 | 9 Ara 2025 |
36İzleyin | CVE-2019-15942İstismar yok | FFmpeg through 4.2 has a "Conditional jump or move depends on uninitialised value" issue in h2645_parse because alloc_rbsp_buffer in libavcoffmpeg · ffmpeg · CWE-252 | Yüksek8,8 | — | %2,0 | 5 Eyl 2019 |
36İzleyin | CVE-2024-50306İstismar yok | Apache Traffic Server: Server process can fail to drop privilegeapache · traffic server · CWE-252 | Kritik9,1 | — | %1,6 | 14 Kas 2024 |
35İzleyin | CVE-2021-26958İstismar yok | An issue was discovered in the xcb crate through 2021-02-04 for Rust.xcb project · xcb · CWE-252 | Yüksek8,8 | — | %1,6 | 9 Şub 2021 |
35İzleyin | CVE-2023-44182İstismar yok | Junos OS and Junos OS Evolved: An Unchecked Return Value in multiple users interfaces affects confidentiality and integrity of device operationsjuniper · junos · CWE-252 | Yüksek8,8 | — | %0,6 | 12 Eki 2023 |
35İzleyin | CVE-2024-1545İstismar yok | Fault Injection of RSA encryption in WolfCryptwolfssl · wolfssl · CWE-252 | Yüksek8,8 | — | %0,6 | 29 Ağu 2024 |
35İzleyin | CVE-2024-38427İstismar yok | In International Color Consortium DemoIccMAX before 85ce74e, a logic flaw in CIccTagXmlProfileSequenceId::ParseXml in IccXML/IccLibXML/IccTaCWE-252 | Yüksek8,8 | — | %0,5 | 15 Haz 2024 |
35İzleyin | CVE-2025-46672İstismar yok | NASA CryptoLib before 1.3.2 does not check the OTAR crypto function returned status, potentially leading to spacecraft hijacking.nasa · cryptolib · CWE-252 | Yüksek8,8 | — | %0,5 | 26 Nis 2025 |
35İzleyin | CVE-2024-2881İstismar yok | Fault Injection of EdDSA signature in WolfCryptwolfssl · wolfssl · CWE-252 | Yüksek8,8 | — | %0,5 | 29 Ağu 2024 |
34İzleyin | CVE-2021-40401İstismar yok | A use-after-free vulnerability exists in the RS-274X aperture definition tokenization functionality of Gerbv 2.7.0 and dev (commit b5f1eacd)gerbv project · gerbv · CWE-252 | Yüksek8,6 | — | %1,3 | 4 Şub 2022 |
34İzleyin | CVE-2026-21920İstismar yok | Junos OS: SRX Series: If a specific request is processed by the DNS subsystem flowd will crashjuniper · junos · CWE-252 | Yüksek8,7 | — | %0,5 | 15 Oca 2026 |
34İzleyin | CVE-2026-40060İstismar yok | BIG-IP Advanced WAF and ASM vulnerabilityf5 · big-ip application security manager · CWE-252 | Yüksek8,7 | — | %0,5 | 13 May 2026 |
34İzleyin | CVE-2025-61935İstismar yok | BIG-IP Advanced WAF and ASM vulnerabilityf5 · big-ip advanced web application firewall · CWE-252 | Yüksek8,7 | — | %0,3 | 15 Eki 2025 |
33İzleyin | CVE-2020-17533Kavram kanıtı | Apache Accumulo Improper Handling of Insufficient Permissionsapache · accumulo · CWE-252 | Yüksek8,1 | — | %3,7 | 29 Ara 2020 |
33İzleyin | CVE-2023-47480İstismar yok | An issue in Pure Data 0.54-0 and fixed in 0.54-1 allows a local attacker to escalate privileges via the set*id () function.CWE-252 | Yüksek8,4 | — | %0,2 | 20 Eyl 2024 |
33İzleyin | CVE-2025-0028İstismar yok | An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to read or modify an arbitrary addressamd · amd ryzen™ 7035 series processors with radeon™ graphics (formerly codenamed "rembrandt r") · CWE-252 | Yüksek8,3 | — | %0,1 | 14 May 2026 |
- CVE-2007-379860Bu hafta
Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via craf
KritikCVSS 9,8Kavram kanıtıEPSS %70tcpdump · tcpdump16 Tem 2007
- CVE-2005-436057Planlayın
The URL parser in Microsoft Internet Information Services (IIS) 5.1 on Windows XP Professional SP2 allows remote attackers to execute arbitr
YüksekCVSS 7,8Kavram kanıtıEPSS %87microsoft · internet information services19 Ara 2005
- CVE-2010-021148Planlayın
The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which
KritikCVSS 9,8Kavram kanıtıEPSS %28openldap · openldap28 Tem 2010
- CVE-2021-3817140Planlayın
adts_decode_extradata in libavformat/adtsenc.c in FFmpeg 4.4 does not check the init_get_bits return value, which is a necessary step becaus
KritikCVSS 9,8İstismar yokEPSS %2ffmpeg · ffmpeg21 Ağu 2021
- CVE-1999-019940Planlayın
manual/search.texi in the GNU C Library (aka glibc) before 2.2 lacks a statement about the unspecified tdelete return value upon deletion of
KritikCVSS 9,8İstismar yokEPSS %2gnu · glibc6 Eki 2020
- CVE-2019-1590040Planlayın
An issue was discovered in slicer69 doas before 6.2 on certain platforms other than OpenBSD.
KritikCVSS 9,8İstismar yokEPSS %2doas project · doas18 Eki 2019
- CVE-2021-2695540Planlayın
An issue was discovered in the xcb crate through 2021-02-04 for Rust.
KritikCVSS 9,8İstismar yokEPSS %2xcb project · xcb9 Şub 2021
- CVE-2022-2571839İzleyin
Cryptographic issue in WLAN due to improper check on return value while authentication handshake in Snapdragon Auto, Snapdragon Connectivity
KritikCVSS 9,8İstismar yokEPSS %0qualcomm · apq8009 firmware19 Eki 2022
- CVE-2022-2380637İzleyin
Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int va
KritikCVSS 9,1İstismar yokEPSS %3golang · go10 Şub 2022
- CVE-2025-6656537İzleyin
Fiber Utils UUIDv4 and UUID Silent Fallback to Predictable Values
KritikCVSS 9,3İstismar yokEPSS %0gofiber · utils9 Ara 2025
- CVE-2019-1594236İzleyin
FFmpeg through 4.2 has a "Conditional jump or move depends on uninitialised value" issue in h2645_parse because alloc_rbsp_buffer in libavco
YüksekCVSS 8,8İstismar yokEPSS %2ffmpeg · ffmpeg5 Eyl 2019
- CVE-2024-5030636İzleyin
Apache Traffic Server: Server process can fail to drop privilege
KritikCVSS 9,1İstismar yokEPSS %2apache · traffic server14 Kas 2024
- CVE-2021-2695835İzleyin
An issue was discovered in the xcb crate through 2021-02-04 for Rust.
YüksekCVSS 8,8İstismar yokEPSS %2xcb project · xcb9 Şub 2021
- CVE-2023-4418235İzleyin
Junos OS and Junos OS Evolved: An Unchecked Return Value in multiple users interfaces affects confidentiality and integrity of device operations
YüksekCVSS 8,8İstismar yokEPSS %1juniper · junos12 Eki 2023
- CVE-2024-154535İzleyin
Fault Injection of RSA encryption in WolfCrypt
YüksekCVSS 8,8İstismar yokEPSS %1wolfssl · wolfssl29 Ağu 2024
- CVE-2024-3842735İzleyin
In International Color Consortium DemoIccMAX before 85ce74e, a logic flaw in CIccTagXmlProfileSequenceId::ParseXml in IccXML/IccLibXML/IccTa
YüksekCVSS 8,8İstismar yokEPSS %115 Haz 2024
- CVE-2025-4667235İzleyin
NASA CryptoLib before 1.3.2 does not check the OTAR crypto function returned status, potentially leading to spacecraft hijacking.
YüksekCVSS 8,8İstismar yokEPSS %1nasa · cryptolib26 Nis 2025
- CVE-2024-288135İzleyin
Fault Injection of EdDSA signature in WolfCrypt
YüksekCVSS 8,8İstismar yokEPSS %0wolfssl · wolfssl29 Ağu 2024
- CVE-2021-4040134İzleyin
A use-after-free vulnerability exists in the RS-274X aperture definition tokenization functionality of Gerbv 2.7.0 and dev (commit b5f1eacd)
YüksekCVSS 8,6İstismar yokEPSS %1gerbv project · gerbv4 Şub 2022
- CVE-2026-2192034İzleyin
Junos OS: SRX Series: If a specific request is processed by the DNS subsystem flowd will crash
YüksekCVSS 8,7İstismar yokEPSS %0juniper · junos15 Oca 2026
- CVE-2026-4006034İzleyin
BIG-IP Advanced WAF and ASM vulnerability
YüksekCVSS 8,7İstismar yokEPSS %0f5 · big-ip application security manager13 May 2026
- CVE-2025-6193534İzleyin
BIG-IP Advanced WAF and ASM vulnerability
YüksekCVSS 8,7İstismar yokEPSS %0f5 · big-ip advanced web application firewall15 Eki 2025
- CVE-2020-1753333İzleyin
Apache Accumulo Improper Handling of Insufficient Permissions
YüksekCVSS 8,1Kavram kanıtıEPSS %4apache · accumulo29 Ara 2020
- CVE-2023-4748033İzleyin
An issue in Pure Data 0.54-0 and fixed in 0.54-1 allows a local attacker to escalate privileges via the set*id () function.
YüksekCVSS 8,4İstismar yokEPSS %020 Eyl 2024
- CVE-2025-002833İzleyin
An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to read or modify an arbitrary address
YüksekCVSS 8,3İstismar yokEPSS %0amd · amd ryzen™ 7035 series processors with radeon™ graphics (formerly codenamed "rembrandt r")14 May 2026