CWE-391
24 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Unchecked Error Condition
[PLANNED FOR DEPRECATION. SEE MAINTENANCE NOTES AND CONSIDER CWE-252, CWE-248, OR CWE-1069.] Ignoring exceptions and other error conditions may allow an attacker to induce unexpected behavior unnoticed.
CVEs (24)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian X.org2Debian Linux X ServerAug 29, 2025 Jan 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 xorg-x11-server before 1.19.5 had wrong extra length check in ProcXIChangeHierarchy function allowing malicious X client to cause X server to crash or possibly execute arbitrary code. |
2Debian X.org2Debian Linux X ServerAug 29, 2025 Jan 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 xorg-x11-server before 1.19.5 was vulnerable to integer overflow in ProcDbeGetVisualInfo function allowing malicious X client to cause X server to crash or possibly execute arbitrary code. |
2Debian X.org2Debian Linux X ServerAug 29, 2025 Jan 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 xorg-x11-server before 1.19.5 was missing extra length validation in ProcEstablishConnection function allowing malicious X client to cause X server to crash or possibly execute arbitrary code. |
fedora-arm-installer up to and including 1.99.16 is vulnerable to local privilege escalation due to lack of checking the error condition of mount operation failure on unsafely created temporary directories. |