CWE-232Variant

Improper Handling of Undefined Values

Draft in the CWE catalog · 11 CVEs mapped

11
CVEs mapped
6.7
Median CVSS
What it is

The product does not handle or incorrectly handles when a value is not defined or supported for the associated parameter, field, or argument name.

Recent examples
6.5cvss
CVE-2026-21689

iccDEV has Type Confusion in CIccProfileXml::ParseBasic() at IccXML/IccLibXML/IccProfileXml.cpp

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a Type Confusion vulnerability in `CIccProfileXml::ParseBasic()` at `IccXML/IccLibXML/IccProfileXml.cpp`. This vulnerability affects users of the iccDEV library who process ICC color profiles. Version 2.3.1.2 contains a patch. No known workarounds are available.

MEDIUMno explanation yet
0%
epss
6.7cvss
CVE-2025-20314

A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical…

A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to an affected device to execute persistent code at boot time and break the chain of trust. This vulnerability is due to improper validation of software packages. An attacker could exploit this vulnerability by placing a crafted file into a specific location on an affected device. A successful exploit could allow the attacker to execute persistent code on the underlying operating system. Because this vulnerability allows an attacker to bypass a major security feature of a device, Cisco has raised the Security Impact Rating (SIR) of this advisory from Medium to High.

MEDIUMno explanation yet
0%
epss
7.5cvss
CVE-2025-40775

DNS message with invalid TSIG causes an assertion failure

When an incoming DNS protocol message includes a Transaction Signature (TSIG), BIND always checks it. If the TSIG contains an invalid value in the algorithm field, BIND immediately aborts with an assertion failure. This issue affects BIND 9 versions 9.20.0 through 9.20.8 and 9.21.0 through 9.21.7.

HIGHno explanation yet
15%
epss
The record
Technical detail
CWE ID
CWE-232
Abstraction
Variant
Structure
Simple
Status
Draft