The product encounters an error but does not provide a status code or return value to indicate that an error has occurred.
Volume of CVEs assigned to CWE-392 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-42246HIGH Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4, a man-in-the-middle attacker can cau | May 9, 2026 | 7.4 | 33 | NO | NO |
CVE-2025-32743CRITICAL In ConnMan through 1.44, the lookup string in ns_resolv in dnsproxy.c can be NULL or an empty string when the TC (Truncated) bit is set in a DNS response. This allows attackers to | Apr 10, 2025 | 9.0 | 26 | NO | NO |
CVE-2024-12797MEDIUM Issue summary: Clients using RFC7250 Raw Public Keys (RPKs) to authenticate a
server may fail to notice that the server was not authenticated, because
handshakes don't abort as exp | Feb 11, 2025 | 6.3 | 24 | NO | NO |
CVE-2024-39697HIGH phonenumber is a library for parsing, formatting and validating international phone numbers. Since 0.3.4, the phonenumber parsing code may panic due to a panic-guarded out-of-bound | Jul 9, 2024 | 8.6 | 23 | NO | NO |
CVE-2023-42444HIGH phonenumber is a library for parsing, formatting and validating international phone numbers. Prior to versions `0.3.3+8.13.9` and `0.2.5+8.11.3`, the phonenumber parsing code may p | Sep 19, 2023 | 7.5 | 22 | NO | NO |
CVE-2025-23270HIGH NVIDIA Jetson Linux contains a vulnerability in UEFI Management mode, where an unprivileged local attacker may cause exposure of sensitive information via a side channel vulnerabil | Jul 17, 2025 | 7.1 | 21 | NO | NO |
CVE-2017-2342HIGH MACsec feature on Juniper Networks Junos OS 15.1X49 prior to 15.1X49-D100 on SRX300 series does not report errors when a secure link can not be established. It falls back to an une | Jul 17, 2017 | 8.1 | 20 | NO | NO |
CVE-2026-20005MEDIUM Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine t | Mar 4, 2026 | 5.8 | 19 | NO | NO |
CVE-2025-26268MEDIUM DragonflyDB Dragonfly before 1.27.0 allows authenticated users to cause a denial of service (daemon crash) via a crafted Redis command. The validity of the scan cursor was not chec | Apr 17, 2025 | 6.5 | 19 | NO | NO |
CVE-2023-42447HIGH blurhash-rs is a pure Rust implementation of Blurhash, software for encoding images into ASCII strings that can be turned into a gradient of colors representing the original image. | Sep 19, 2023 | 7.5 | 19 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.