The product does not check the return value from a method or function, which can prevent it from detecting unexpected states and conditions.
Volume of CVEs assigned to CWE-252 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
174 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-3798CRITICAL Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an | Jul 16, 2007 | 9.8 | 78 | NO | YES |
CVE-2005-4360HIGH The URL parser in Microsoft Internet Information Services (IIS) 5.1 on Windows XP Professional SP2 allows remote attackers to execute arbitrary code via multiple requests to ".dll" | Dec 20, 2005 | 7.8 | 73 | NO | YES |
CVE-2010-0211CRITICAL The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows remote attackers to cause a denia | Jul 28, 2010 | 9.8 | 56 | NO | YES |
CVE-2022-23626HIGH m1k1o/blog is a lightweight self-hosted facebook-styled PHP blog. Errors from functions `imagecreatefrom*` and `image*` have not been checked properly. Although PHP issued warnings | Feb 8, 2022 | 8.8 | 44 | NO | YES |
CVE-2026-11972HIGH When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer. | Jun 23, 2026 | 8.2 | 37 | NO | NO |
CVE-2026-61857HIGH ImageMagick before 7.1.2-26 contains a heap use-after-free vulnerability caused by missing null check when parsing XMP profiles. Attackers can craft malicious image files with spec | Jul 11, 2026 | 7.5 | 34 | NO | NO |
CVE-2026-40092HIGH nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In versions 1.3.0 and below, a malicious network peer can crash any Nimiq full node by publishin | May 20, 2026 | 7.5 | 32 | NO | NO |
CVE-1999-0199CRITICAL manual/search.texi in the GNU C Library (aka glibc) before 2.2 lacks a statement about the unspecified tdelete return value upon deletion of a tree's root, which might allow attack | Oct 6, 2020 | 9.8 | 32 | NO | NO |
CVE-2026-40060HIGH When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate.
Note: Software versions which | May 13, 2026 | 7.5 | 31 | NO | NO |
CVE-2025-66565CRITICAL Fiber Utils is a collection of common functions created for Fiber. In versions 2.0.0-rc.3 and below, when the system's cryptographic random number generator (crypto/rand) fails, bo | Dec 9, 2025 | 9.8 | 31 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.