[PLANNED FOR DEPRECATION. SEE MAINTENANCE NOTES AND CONSIDER CWE-252, CWE-248, OR CWE-1069.] Ignoring exceptions and other error conditions may allow an attacker to induce unexpected behavior unnoticed.
Volume of CVEs assigned to CWE-391 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-52316CRITICAL Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may thr | Nov 18, 2024 | 9.8 | 34 | NO | NO |
CVE-2025-71325CRITICAL picklescan before 0.0.27 contains a parsing logic error in the _list_globals function when handling STACK_GLOBAL opcodes, failing to track arguments in the correct range and allowi | Jun 17, 2026 | 9.8 | 33 | NO | NO |
CVE-2017-12180CRITICAL xorg-x11-server before 1.19.5 was missing length validation in XFree86 VidModeExtension allowing malicious X client to cause X server to crash or possibly execute arbitrary code. | Jan 24, 2018 | 9.8 | 31 | NO | NO |
CVE-2017-12186CRITICAL xorg-x11-server before 1.19.5 was missing length validation in X-Resource extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code. | Jan 24, 2018 | 9.8 | 29 | NO | NO |
CVE-2017-12185CRITICAL xorg-x11-server before 1.19.5 was missing length validation in MIT-SCREEN-SAVER extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code. | Jan 24, 2018 | 9.8 | 28 | NO | NO |
CVE-2017-12183CRITICAL xorg-x11-server before 1.19.5 was missing length validation in XFIXES extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code. | Jan 24, 2018 | 9.8 | 28 | NO | NO |
CVE-2017-12182CRITICAL xorg-x11-server before 1.19.5 was missing length validation in XFree86 DRI extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code. | Jan 24, 2018 | 9.8 | 28 | NO | NO |
CVE-2017-12181CRITICAL xorg-x11-server before 1.19.5 was missing length validation in XFree86 DGA extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code. | Jan 24, 2018 | 9.8 | 28 | NO | NO |
CVE-2017-12178CRITICAL xorg-x11-server before 1.19.5 had wrong extra length check in ProcXIChangeHierarchy function allowing malicious X client to cause X server to crash or possibly execute arbitrary co | Jan 24, 2018 | 9.8 | 28 | NO | NO |
CVE-2017-12177CRITICAL xorg-x11-server before 1.19.5 was vulnerable to integer overflow in ProcDbeGetVisualInfo function allowing malicious X client to cause X server to crash or possibly execute arbitra | Jan 24, 2018 | 9.8 | 28 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.