CWE-392: Missing Report of Error Condition
The product encounters an error but does not provide a status code or return value to indicate that an error has occurred.
12 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-32743 — In ConnMan through 1.44, the lookup string in ns_resolv in dnsproxy.c can be NULL or an empty string when the TC (Trunca
- CVE-2024-39697 — phonenumber panics on parsing crafted phonenumber inputs
- CVE-2025-23270 — NVIDIA Jetson Linux contains a vulnerability in UEFI Management mode, where an unprivileged local attacker may cause exp
- CVE-2026-42246 — net-imap vulnerable to STARTTLS stripping via invalid response timing
- CVE-2026-20005 — Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could allow an unauthentica
- CVE-2025-26268 — DragonflyDB Dragonfly before 1.27.0 allows authenticated users to cause a denial of service (daemon crash) via a crafted
- CVE-2025-59398 — The OCPP implementation in libocpp before 0.26.2 allows a denial of service (EVerest crash) via JSON input larger than 2
- CVE-2024-12797 — RFC7250 handshakes with unauthenticated servers don't abort as expected
Recently published
- CVE-2026-42246 — net-imap vulnerable to STARTTLS stripping via invalid response timing
- CVE-2026-20005 — Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could allow an unauthentica
- CVE-2025-59398 — The OCPP implementation in libocpp before 0.26.2 allows a denial of service (EVerest crash) via JSON input larger than 2
- CVE-2025-23270 — NVIDIA Jetson Linux contains a vulnerability in UEFI Management mode, where an unprivileged local attacker may cause exp
- CVE-2025-26268 — DragonflyDB Dragonfly before 1.27.0 allows authenticated users to cause a denial of service (daemon crash) via a crafted
- CVE-2025-32743 — In ConnMan through 1.44, the lookup string in ns_resolv in dnsproxy.c can be NULL or an empty string when the TC (Trunca
- CVE-2024-12797 — RFC7250 handshakes with unauthenticated servers don't abort as expected
- CVE-2024-39697 — phonenumber panics on parsing crafted phonenumber inputs