Draft in the CWE catalog · 15 CVEs mapped
The product does not properly check when a function or operation returns a value that is legitimate for the function, but is not expected by the product.
In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.
A vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, in which an unexpected return value from the authentication routine is later on processed as a legitimate value, resulting in an authentication bypass.
⚡ A sneaky return value in AMD uProf could let local attackers dance past KSLR—imagine a VIP pass to your data party without the bouncer noticing! 🎉 Think of KSLR as a security guard who randomly rearranges the furniture at a venue to keep unwanted guests confused. If an attacker knows how the furniture is arranged, they can stroll right in, knowing exactly where the valuables are hidden. This vulnerability could lead to devastating consequences, such as unauthorized access to sensitive data or even service disruptions. With KSLR bypassed, an attacker could manipulate memory addresses, potentially wreaking havoc on the system's confidentiality and availability.