← Back
CWE-252

183 CVEs • Abstraction: Base • Likelihood of Exploit: Low

Unchecked Return Value

The product does not check the return value from a method or function, which can prevent it from detecting unexpected states and conditions.

JSON object

Loading...

CVEs (183)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Doas Project
1Doas
Jun 17, 2026
Oct 18, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered in slicer69 doas before 6.2 on certain platforms other than OpenBSD. On platforms without strtonum(3), sscanf was used without checking for error cases. Instead, the uninitialized variable errstr...Show more
An issue was discovered in slicer69 doas before 6.2 on certain platforms other than OpenBSD. On platforms without strtonum(3), sscanf was used without checking for error cases. Instead, the uninitialized variable errstr was checked and in some cases returned success even if sscanf failed. The result was that, instead of reporting that the supplied username or group name did not exist, it would execute the command as root.Show less
3Freerdp
LodevOpensuse
3Freerdp
LeapLodepng
Jun 17, 2026
Oct 4, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
HuffmanTree_makeFromFrequencies in lodepng.c in LodePNG through 2019-09-28, as used in WinPR in FreeRDP and other products, has a memory leak because a supplied realloc pointer (i.e., the first argument to realloc) is al...Show more
HuffmanTree_makeFromFrequencies in lodepng.c in LodePNG through 2019-09-28, as used in WinPR in FreeRDP and other products, has a memory leak because a supplied realloc pointer (i.e., the first argument to realloc) is also used for a realloc return value.Show less
1Google
1Android
Jun 17, 2026
Sep 27, 2019
N/A· v4
6.5 MEDIUM· v3
7.1 HIGH· v2
In libskia, there is a possible crash due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android...Show more
In libskia, there is a possible crash due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-132782448Show less
1Ffmpeg
1Ffmpeg
Jun 17, 2026
Sep 5, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
FFmpeg through 4.2 has a "Conditional jump or move depends on uninitialised value" issue in h2645_parse because alloc_rbsp_buffer in libavcodec/h2645_parse.c mishandles rbsp_buffer.
1Miniupnp.free
1Miniupnpd
Jun 17, 2026
May 15, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The upnp_event_prepare function in upnpevents.c in MiniUPnP MiniUPnPd through 2.1 allows a remote attacker to leak information from the heap due to improper validation of an snprintf return value.
2Fedoraproject
Wireshark
2Fedora
Wireshark
Jun 17, 2026
Apr 9, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Wireshark 3.0.0, the TSDNS dissector could crash. This was addressed in epan/dissectors/packet-tsdns.c by splitting strings safely.
3Cron Project
DebianFedoraproject
3Cron
Debian LinuxFedora
Jun 17, 2026
Mar 12, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (daemon crash) via a large crontab file because the calloc return value is not checked.
2Canonical
Qemu
2Qemu
Ubuntu Linux
Nov 21, 2024
Dec 20, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
QEMU can have an infinite loop in hw/rdma/vmw/pvrdma_dev_ring.c because return values are not checked (and -1 is mishandled).
3Canonical
DebianImagemagick
3Debian Linux
ImagemagickUbuntu Linux
Nov 21, 2024
Sep 6, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The functions ReadDCMImage in coders/dcm.c, ReadPWPImage in coders/pwp.c, ReadCALSImage in coders/cals.c, and ReadPICTImage in coders/pict.c in ImageMagick 7.0.8-4 do not check the return value of the fputc function, whi...Show more
The functions ReadDCMImage in coders/dcm.c, ReadPWPImage in coders/pwp.c, ReadCALSImage in coders/cals.c, and ReadPICTImage in coders/pict.c in ImageMagick 7.0.8-4 do not check the return value of the fputc function, which allows remote attackers to cause a denial of service via a crafted image file.Show less
4Canonical
DebianLibtirpc Project+1 more
8Debian Linux
Enterprise LinuxEnterprise Linux Desktop+5 more
Nov 21, 2024
Aug 30, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A null-pointer dereference vulnerability was found in libtirpc before version 0.3.3-rc3. The return value of makefd_xprt() was not checked in all instances, which could lead to a crash when the server exhausted the maxim...Show more
A null-pointer dereference vulnerability was found in libtirpc before version 0.3.3-rc3. The return value of makefd_xprt() was not checked in all instances, which could lead to a crash when the server exhausted the maximum number of available file descriptors. A remote attacker could cause an rpc-based application to crash by flooding it with new connections.Show less
1Wireshark
1Wireshark
Nov 21, 2024
Jul 19, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Wireshark 2.6.0 to 2.6.1 and 2.4.0 to 2.4.7, the CoAP protocol dissector could crash. This was addressed in epan/dissectors/packet-coap.c by properly checking for a NULL condition.
1Google
1Android
May 13, 2026
Sep 8, 2017
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
A denial of service vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-62673844.
1Google
1Android
May 13, 2026
Aug 9, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37430213.
1Google
1Android
May 13, 2026
May 12, 2017
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
A remote denial of service vulnerability in libhevc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of...Show more
A remote denial of service vulnerability in libhevc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34672748.Show less
2Canonical
Debian
2Debian Linux
Ubuntu Linux
May 13, 2026
Mar 28, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
dmcrypt-get-device, as shipped in the eject package of Debian and Ubuntu, does not check the return value of the (1) setuid or (2) setgid function, which might cause dmcrypt-get-device to execute code, which was intended...Show more
dmcrypt-get-device, as shipped in the eject package of Debian and Ubuntu, does not check the return value of the (1) setuid or (2) setgid function, which might cause dmcrypt-get-device to execute code, which was intended to run as an unprivileged user, as root. This affects eject through 2.1.5+deb1+cvs20081104-13.1 on Debian, eject before 2.1.5+deb1+cvs20081104-13.1ubuntu0.16.10.1 on Ubuntu 16.10, eject before 2.1.5+deb1+cvs20081104-13.1ubuntu0.16.04.1 on Ubuntu 16.04 LTS, eject before 2.1.5+deb1+cvs20081104-13.1ubuntu0.14.04.1 on Ubuntu 14.04 LTS, and eject before 2.1.5+deb1+cvs20081104-9ubuntu0.1 on Ubuntu 12.04 LTS.Show less
1Imagemagick
1Imagemagick
May 13, 2026
Mar 3, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The ReadGROUP4Image function in coders/tiff.c in ImageMagick before 7.0.1-10 does not check the return value of the fputc function, which allows remote attackers to cause a denial of service (crash) via a crafted image f...Show more
The ReadGROUP4Image function in coders/tiff.c in ImageMagick before 7.0.1-10 does not check the return value of the fputc function, which allows remote attackers to cause a denial of service (crash) via a crafted image file.Show less
1Imagemagick
1Imagemagick
May 13, 2026
Mar 2, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The ConcatenateImages function in MagickWand/magick-cli.c in ImageMagick before 7.0.1-10 does not check the return value of the fputc function, which allows remote attackers to cause a denial of service (application cras...Show more
The ConcatenateImages function in MagickWand/magick-cli.c in ImageMagick before 7.0.1-10 does not check the return value of the fputc function, which allows remote attackers to cause a denial of service (application crash) via a crafted file.Show less
4Apple
OpenldapOpensuse+1 more
5Esxi
Mac Os XMac Os X Server+2 more
Apr 29, 2026
Jul 28, 2010
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows remote attackers to cause a denial of service (segmentation fault) and po...Show more
The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a modrdn call with an RDN string containing invalid UTF-8 sequences, which triggers a free of an invalid, uninitialized pointer in the slap_mods_free function, as demonstrated using the Codenomicon LDAPv3 test suite.Show less
1Isc
1Bind
Apr 23, 2026
Jan 26, 2009
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Internet Systems Consortium (ISC) BIND 9.6.0 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via...Show more
Internet Systems Consortium (ISC) BIND 9.6.0 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077 and CVE-2009-0025.Show less
5Canonical
DebianFedoraproject+2 more
5Debian Linux
FedoraLoop Aes Utils+2 more
Apr 23, 2026
Oct 4, 2007
N/A· v4
N/A· v3
7.2 HIGH· v2
mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values, which might allow attackers to gain privileges via helpers such as mount.nfs.