VYPR

CWE-390

Detection of Error Condition Without Action

BaseDraftLikelihood: Medium

Description

The product detects a specific error, but takes no actions to handle the error.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (22)

page 2 of 2
  • CVE-2025-0029LowFeb 10, 2026
    risk 0.12cvss —epss 0.00

    Improper handling of error condition during host-induced faults can allow a local high-privileged attack to selectively drop guest DMA writes, potentially resulting in a loss of SEV-SNP guest memory integrity

  • CVE-2024-27919HigApr 4, 2024
    risk 0.07cvss 7.5epss 0.87

    Envoy is a cloud-native, open-source edge and service proxy. In versions 1.29.0 and 1.29.1, theEnvoy HTTP/2 protocol stack is vulnerable to the flood of CONTINUATION frames. Envoy's HTTP/2 codec does not reset a request when header map limits have been exceeded. This allows an…