CWE-158 · 27 kayıt
Improper Neutralization of Null Byte or NUL Character
Bu sınıftaki CVE’ler
27 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
98Hemen | CVE-2025-47812Silahlaştırılmış | In Wing FTP Server before 7.4.4.wftpserver · wing ftp server · CWE-158 | Kritik10,0 | KEV | %92,9 | 10 Tem 2025 |
80Hemen | CVE-2009-1537Silahlaştırılmış | Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows microsoft · directx · CWE-158 | Yüksek8,8 | KEV | %51,2 | 29 May 2009 |
39İzleyin | CVE-2020-14500İstismar yok | IMPROPER NEUTRALIZATION OF NULL BYTE OR NUL CHARACTER CWE-158secomea · gatemanager 8250 firmware · CWE-158 | Kritik9,8 | — | %1,7 | 25 Ağu 2020 |
39İzleyin | CVE-2023-5719İstismar yok | Red Lion Crimson Improper Neutralization of Null Byte or NUL Characterredlion · crimson · CWE-158 | Kritik9,8 | — | %0,5 | 6 Kas 2023 |
39İzleyin | CVE-2025-14388İstismar yok | PhastPress <= 3.7 - Unauthenticated Arbitrary File Read via Null Byte Injectionkiboit · phastpress · CWE-158 | Kritik9,8 | — | %0,5 | 23 Ara 2025 |
38İzleyin | CVE-2025-55113İstismar yok | BMC Control-M/Agent unescaped NULL byte in access control list checksbmc · control-m\/agent · CWE-158 | Kritik9,5 | — | %0,3 | 16 Eyl 2025 |
35İzleyin | CVE-2025-66263İstismar yok | Unauthenticated Arbitrary File Read via Null Byte Injectiondbbroadcast · mozart next 3000 firmware · CWE-158 | Yüksek8,9 | — | %0,4 | 25 Kas 2025 |
34İzleyin | CVE-2025-9648İstismar yok | Denial of Service in CivetWebcivetweb · civetweb · CWE-158 | Yüksek8,7 | — | %0,8 | 29 Eyl 2025 |
34İzleyin | CVE-2026-33191İstismar yok | free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Errorfree5gc · udm · CWE-158 | Yüksek8,7 | — | %0,6 | 20 Mar 2026 |
32İzleyin | CVE-2024-10921İstismar yok | Improper neutralization of null bytes may lead to buffer over-reads in MongoDB Servermongodb · mongodb · CWE-158 | Yüksek8,1 | — | %0,6 | 14 Kas 2024 |
32İzleyin | CVE-2026-76354İstismar yok | Path Traversal through Search Head Clustering in Splunk Enterprisesplunk · splunk · CWE-158 | Yüksek8,1 | — | %0,4 | 19 Ağu 2026 |
30İzleyin | CVE-2022-41716İstismar yok | Unsanitized NUL in environment variables on Windows in syscall and os/execgolang · go · CWE-158 | Yüksek7,5 | — | %0,8 | 2 Kas 2022 |
29İzleyin | CVE-2025-1936İstismar yok | Adding %00 and a fake extension to a jar: URL changed the interpretation of the contentsmozilla · firefox · CWE-158 | Yüksek7,3 | — | %0,4 | 4 Mar 2025 |
27İzleyin | CVE-2022-20812İstismar yok | Cisco Expressway Series and Cisco TelePresence Video Communication Server Vulnerabilitiescisco · expressway · CWE-158 | Orta6,5 | — | %1,9 | 6 Tem 2022 |
26İzleyin | CVE-2020-7928İstismar yok | Improper neutralization of null byte leads to read overrunmongodb · mongodb · CWE-158 | Orta6,5 | — | %1,4 | 23 Kas 2020 |
26İzleyin | CVE-2026-23863İstismar yok | An attachment spoofing issue in WhatsApp for Windows prior to v2.3000.1032164386.258709 could have allowed maliciously formatted documents wwhatsapp · whatsapp · CWE-158 | Orta6,5 | — | %0,5 | 1 May 2026 |
26İzleyin | CVE-2020-5363İstismar yok | Select Dell Client Consumer and Commercial platforms include an issue that allows the BIOS Admin password to be changed through Dell's managdell · latitude 5300 firmware · CWE-158 | Orta6,7 | — | %0,3 | 10 Haz 2020 |
23İzleyin | CVE-2022-20813İstismar yok | Cisco Expressway Series and Cisco TelePresence Video Communication Server Vulnerabilitiescisco · expressway · CWE-158 | Orta5,9 | — | %1,1 | 6 Tem 2022 |
22İzleyin | CVE-2024-0408İstismar yok | Xorg-x11-server: selinux unlabeled glx pbufferx.org · x server · CWE-158 | Orta5,5 | — | %0,3 | 18 Oca 2024 |
22İzleyin | CVE-2026-41256İstismar yok | jq: Embedded NUL truncates top-level jq programs loaded with -fjqlang · jq · CWE-158 | Orta5,5 | — | %0,2 | 11 May 2026 |
17İzleyin | CVE-2026-47778İstismar yok | Envoy: Embedded NUL in TLS DNS SAN Truncation in the Default TLS Certificate Validator. (Auth Bypass)envoyproxy · envoy · CWE-158 | Orta4,4 | — | %0,2 | 26 Haz 2026 |
14İzleyin | CVE-2026-43859İstismar yok | mutt before 2.3.2 sometimes uses strfcpy instead of memcpy for the IMAP auth_cram MD5 digest.mutt · mutt · CWE-158 | Düşük3,7 | — | %0,3 | 4 May 2026 |
14İzleyin | CVE-2026-43861İstismar yok | mutt before 2.3.2 does not check for '\0' in url_pct_decode.mutt · mutt · CWE-158 | Düşük3,7 | — | %0,3 | 4 May 2026 |
14İzleyin | CVE-2025-61985İstismar yok | ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used.openbsd · openssh · CWE-158 | Düşük3,6 | — | %0,1 | 6 Eki 2025 |
13İzleyin | CVE-2026-28540İstismar yok | Out-of-bounds character read vulnerability in Bluetooth.huawei · harmonyos · CWE-158 | Düşük3,3 | — | %0,1 | 5 Mar 2026 |
- CVE-2025-4781298Hemen
In Wing FTP Server before 7.4.4.
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %93wftpserver · wing ftp server10 Tem 2025
- CVE-2009-153780Hemen
Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %51microsoft · directx29 May 2009
- CVE-2020-1450039İzleyin
IMPROPER NEUTRALIZATION OF NULL BYTE OR NUL CHARACTER CWE-158
KritikCVSS 9,8İstismar yokEPSS %2secomea · gatemanager 8250 firmware25 Ağu 2020
- CVE-2023-571939İzleyin
Red Lion Crimson Improper Neutralization of Null Byte or NUL Character
KritikCVSS 9,8İstismar yokEPSS %1redlion · crimson6 Kas 2023
- CVE-2025-1438839İzleyin
PhastPress <= 3.7 - Unauthenticated Arbitrary File Read via Null Byte Injection
KritikCVSS 9,8İstismar yokEPSS %0kiboit · phastpress23 Ara 2025
- CVE-2025-5511338İzleyin
BMC Control-M/Agent unescaped NULL byte in access control list checks
KritikCVSS 9,5İstismar yokEPSS %0bmc · control-m\/agent16 Eyl 2025
- CVE-2025-6626335İzleyin
Unauthenticated Arbitrary File Read via Null Byte Injection
YüksekCVSS 8,9İstismar yokEPSS %0dbbroadcast · mozart next 3000 firmware25 Kas 2025
- CVE-2025-964834İzleyin
Denial of Service in CivetWeb
YüksekCVSS 8,7İstismar yokEPSS %1civetweb · civetweb29 Eyl 2025
- CVE-2026-3319134İzleyin
free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error
YüksekCVSS 8,7İstismar yokEPSS %1free5gc · udm20 Mar 2026
- CVE-2024-1092132İzleyin
Improper neutralization of null bytes may lead to buffer over-reads in MongoDB Server
YüksekCVSS 8,1İstismar yokEPSS %1mongodb · mongodb14 Kas 2024
- CVE-2026-7635432İzleyin
Path Traversal through Search Head Clustering in Splunk Enterprise
YüksekCVSS 8,1İstismar yokEPSS %0splunk · splunk19 Ağu 2026
- CVE-2022-4171630İzleyin
Unsanitized NUL in environment variables on Windows in syscall and os/exec
YüksekCVSS 7,5İstismar yokEPSS %1golang · go2 Kas 2022
- CVE-2025-193629İzleyin
Adding %00 and a fake extension to a jar: URL changed the interpretation of the contents
YüksekCVSS 7,3İstismar yokEPSS %0mozilla · firefox4 Mar 2025
- CVE-2022-2081227İzleyin
Cisco Expressway Series and Cisco TelePresence Video Communication Server Vulnerabilities
OrtaCVSS 6,5İstismar yokEPSS %2cisco · expressway6 Tem 2022
- CVE-2020-792826İzleyin
Improper neutralization of null byte leads to read overrun
OrtaCVSS 6,5İstismar yokEPSS %1mongodb · mongodb23 Kas 2020
- CVE-2026-2386326İzleyin
An attachment spoofing issue in WhatsApp for Windows prior to v2.3000.1032164386.258709 could have allowed maliciously formatted documents w
OrtaCVSS 6,5İstismar yokEPSS %1whatsapp · whatsapp1 May 2026
- CVE-2020-536326İzleyin
Select Dell Client Consumer and Commercial platforms include an issue that allows the BIOS Admin password to be changed through Dell's manag
OrtaCVSS 6,7İstismar yokEPSS %0dell · latitude 5300 firmware10 Haz 2020
- CVE-2022-2081323İzleyin
Cisco Expressway Series and Cisco TelePresence Video Communication Server Vulnerabilities
OrtaCVSS 5,9İstismar yokEPSS %1cisco · expressway6 Tem 2022
- CVE-2024-040822İzleyin
Xorg-x11-server: selinux unlabeled glx pbuffer
OrtaCVSS 5,5İstismar yokEPSS %0x.org · x server18 Oca 2024
- CVE-2026-4125622İzleyin
jq: Embedded NUL truncates top-level jq programs loaded with -f
OrtaCVSS 5,5İstismar yokEPSS %0jqlang · jq11 May 2026
- CVE-2026-4777817İzleyin
Envoy: Embedded NUL in TLS DNS SAN Truncation in the Default TLS Certificate Validator. (Auth Bypass)
OrtaCVSS 4,4İstismar yokEPSS %0envoyproxy · envoy26 Haz 2026
- CVE-2026-4385914İzleyin
mutt before 2.3.2 sometimes uses strfcpy instead of memcpy for the IMAP auth_cram MD5 digest.
DüşükCVSS 3,7İstismar yokEPSS %0mutt · mutt4 May 2026
- CVE-2026-4386114İzleyin
mutt before 2.3.2 does not check for '\0' in url_pct_decode.
DüşükCVSS 3,7İstismar yokEPSS %0mutt · mutt4 May 2026
- CVE-2025-6198514İzleyin
ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used.
DüşükCVSS 3,6İstismar yokEPSS %0openbsd · openssh6 Eki 2025
- CVE-2026-2854013İzleyin
Out-of-bounds character read vulnerability in Bluetooth.
DüşükCVSS 3,3İstismar yokEPSS %0huawei · harmonyos5 Mar 2026