The product detects a specific error, but takes no actions to handle the error.
Volume of CVEs assigned to CWE-390 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-30255HIGH Envoy is a cloud-native, open source edge and service proxy. The HTTP/2 protocol stack in Envoy versions prior to 1.29.3, 1.28.2, 1.27.4, and 1.26.8 are vulnerable to CPU exhaustio | Apr 4, 2024 | 7.5 | 70 | NO | NO |
CVE-2024-27919HIGH Envoy is a cloud-native, open-source edge and service proxy. In versions 1.29.0 and 1.29.1, theEnvoy HTTP/2 protocol stack is vulnerable to the flood of CONTINUATION frames. Envoy' | Apr 4, 2024 | 7.5 | 70 | NO | NO |
CVE-2026-53434CRITICAL Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector.
This issue affects Apache Tomcat: from 11.0.0-M1 throug | Jun 29, 2026 | 9.1 | 42 | NO | NO |
CVE-2026-52989CRITICAL In the Linux kernel, the following vulnerability has been resolved:
nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers
Currently, when nvmet_tcp_build_pdu_iov | Jun 24, 2026 | 9.8 | 38 | NO | NO |
CVE-2025-26465MEDIUM A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit serve | Feb 18, 2025 | 6.8 | 33 | NO | NO |
CVE-2021-40391CRITICAL An out-of-bounds write vulnerability exists in the drill format T-code tool number functionality of Gerbv 2.7.0, dev (commit b5f1eacd), and the forked version of Gerbv (commit 7149 | Nov 19, 2021 | 9.8 | 31 | NO | NO |
CVE-2019-5051HIGH An exploitable heap-based buffer overflow vulnerability exists when loading a PCX file in SDL2_image, version 2.0.4. A missing error handler can lead to a buffer overflow and poten | Jul 3, 2019 | 8.8 | 29 | NO | NO |
CVE-2026-59845MEDIUM A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's acce | Jul 21, 2026 | 5.3 | 25 | NO | NO |
CVE-2024-12086MEDIUM A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a cl | Jan 14, 2025 | 6.8 | 25 | NO | NO |
CVE-2025-46367HIGH Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contain a Detection of Error Condition Without Action vulnerability. A low privileged attacker with local acc | Nov 13, 2025 | 7.8 | 24 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.