The product does not handle or incorrectly handles when a value is not defined or supported for the associated parameter, field, or argument name.
Volume of CVEs assigned to CWE-232 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-40775HIGH When an incoming DNS protocol message includes a Transaction Signature (TSIG), BIND always checks it. If the TSIG contains an invalid value in the algorithm field, BIND immediatel | May 21, 2025 | 7.5 | 35 | NO | NO |
CVE-2023-2968HIGH A remote attacker can trigger a denial of service in the socket.remoteAddress variable, by sending a crafted HTTP request. Usage of the undefined variable raises a TypeError except | May 30, 2023 | 7.5 | 24 | NO | NO |
CVE-2025-20314MEDIUM A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to an affected de | Sep 24, 2025 | 6.7 | 23 | NO | NO |
CVE-2025-20192HIGH A vulnerability in the Internet Key Exchange version 1 (IKEv1) implementation of Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (D | May 7, 2025 | 7.7 | 23 | NO | NO |
CVE-2026-21689MEDIUM iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versio | Jan 7, 2026 | 6.5 | 22 | NO | NO |
CVE-2023-39915HIGH NLnet Labs' Routinator up to and including version 0.12.1 may crash when trying to parse certain malformed RPKI objects. This is due to insufficient input checking in the bcder lib | Sep 13, 2023 | 7.5 | 22 | NO | NO |
CVE-2023-39914HIGH NLnet Labs' bcder library up to and including version 0.7.2 panics while decoding certain invalid input data rather than rejecting the data with an error. This can affect both the | Sep 13, 2023 | 7.5 | 22 | NO | NO |
CVE-2022-22213MEDIUM A vulnerability in Handling of Undefined Values in the routing protocol daemon (RPD) process of Juniper Networks Junos OS and Junos OS Evolved may allow an unauthenticated network- | Jul 20, 2022 | 5.9 | 21 | NO | NO |
CVE-2021-34705MEDIUM A vulnerability in the Voice Telephony Service Provider (VTSP) service of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass con | Sep 23, 2021 | 5.3 | 20 | NO | NO |
CVE-2023-36848MEDIUM An Improper Handling of Undefined Values vulnerability in the periodic packet management daemon (PPMD) of Juniper Networks Junos OS on MX Series(except MPC10, MPC11 and LC9600) all | Jul 14, 2023 | 6.5 | 19 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.