CWE-172 · 19 kayıt
Encoding Error
Bu sınıftaki CVE’ler
19 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2019-10160İstismar yok | A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7python · python · CWE-172 | Kritik9,8 | — | %5,2 | 7 Haz 2019 |
39İzleyin | CVE-2016-6691İstismar yok | service/jni/com_android_server_wifi_Gbk2Utf.cpp in the Qualcomm Wi-Fi gbk2utf module in Android before 2016-10-05 allows remote attackers togoogle · android · CWE-172 | Kritik9,8 | — | %1,3 | 10 Eki 2016 |
31İzleyin | CVE-2025-27110İstismar yok | Libmodsecurity3 has possible bypass of encoded HTML entitiestrustwave · modsecurity · CWE-172 | Yüksek7,9 | — | %0,5 | 25 Şub 2025 |
26İzleyin | CVE-2019-12677İstismar yok | Cisco Adaptive Security Appliance Software SSL VPN Denial of Service Vulnerabilitycisco · adaptive security appliance software · CWE-172 | Orta6,5 | — | %1,5 | 2 Eki 2019 |
25İzleyin | CVE-2026-42926Kavram kanıtı | NGINX ngx_http_proxy_v2_module vulnerabilityf5 · nginx gateway fabric · CWE-172 | Orta6,3 | — | %0,3 | 13 May 2026 |
22İzleyin | CVE-2018-7173İstismar yok | A large loop in JBIG2Stream::readSymbolDictSeg in xpdf 4.00 allows an attacker to cause denial of service via a specific file due to inapproxpdfreader · xpdf · CWE-172 | Orta5,5 | — | %0,8 | 15 Şub 2018 |
22İzleyin | CVE-2016-3829İstismar yok | The ih264d decoder in mediaserver in Android 6.x before 2016-08-01 does not initialize certain structure members, which allows remote attackgoogle · android · CWE-172 | Orta5,5 | — | %0,7 | 5 Ağu 2016 |
22İzleyin | CVE-2016-3828İstismar yok | decoder/ih264d_api.c in mediaserver in Android 6.x before 2016-08-01 mishandles invalid PPS and SPS NAL units, which allows remote attackersgoogle · android · CWE-172 | Orta5,5 | — | %0,6 | 5 Ağu 2016 |
22İzleyin | CVE-2016-3827İstismar yok | codecs/hevcdec/SoftHEVC.cpp in libstagefright in mediaserver in Android 6.0.1 before 2016-08-01 mishandles decoder errors, which allows remogoogle · android · CWE-172 | Orta5,5 | — | %0,6 | 5 Ağu 2016 |
22İzleyin | CVE-2026-100891İstismar yok | Trusted Domain Project OpenDMARC Internationalized Domain Name opendmarc_policy.c opendmarc_policy_query_dmarc encoding errortrusted domain project · opendmarc · CWE-172 | Orta5,5 | — | %0,3 | 2 gün önce |
21İzleyin | CVE-2019-10153İstismar yok | A flaw was discovered in fence-agents, prior to version 4.3.4, where using non-ASCII characters in a guest VM's comment or other fields woulclusterlabs · fence-agents · CWE-172 | Orta5,0 | — | %2,2 | 30 Tem 2019 |
20İzleyin | CVE-2026-48784İstismar yok | Symfony: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or `./` → Generated URL Collapses Off-Route Under RFC 3986 Normalizationsensiolabs · symfony · CWE-172 | Orta5,1 | — | %0,3 | 14 Tem 2026 |
19İzleyin | CVE-2026-86818İstismar yok | fast-uri vulnerable to mailto header injection via percent-encoded field-name desynchronizationfast-uri · fast-uri · CWE-172 | Orta4,8 | — | %0,3 | 15 Eyl 2026 |
18İzleyin | CVE-2018-2415İstismar yok | SAP NetWeaver Application Server Java Web Container and HTTP Service (Engine API, from 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; J2EE Engine Sersap · netweaver java web container and http service engine · CWE-172 | Orta4,7 | — | %1,1 | 9 May 2018 |
14İzleyin | CVE-2018-7289Kavram kanıtı | An issue was discovered in armadito-windows-driver/src/communication.c in Armadito 0.12.7.2.teclib-edition · armadito antivirus · CWE-172 | Düşük3,3 | — | %1,7 | 21 Şub 2018 |
10İzleyin | CVE-2021-33604İstismar yok | Reflected cross-site scripting in development mode handler in Vaadin 14, 15-19vaadin · flow-server · CWE-172 | Düşük2,5 | — | %0,3 | 24 Haz 2021 |
10İzleyin | GHSA-8vfw-v2jv-9hwcİstismar yok | Reflected cross-site scripting in development mode handler in VaadinMaven · com.vaadin:flow-server · CWE-172 | Düşük2,5 | — | — | 28 Haz 2021 |
10İzleyin | GHSA-cx7h-h87r-jpgrİstismar yok | The kstring integration in gix-attributes is unsoundcrates.io · gix-attributes · CWE-172 | Düşük2,5 | — | — | 25 Tem 2024 |
9İzleyin | CVE-2024-48909İstismar yok | SpiceDB calls to LookupResources using LookupResources2 with caveats may return context is missing when it is notauthzed · spicedb · CWE-172 | Düşük2,4 | — | %0,3 | 14 Eki 2024 |
- CVE-2019-1016041Planlayın
A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7
KritikCVSS 9,8İstismar yokEPSS %5python · python7 Haz 2019
- CVE-2016-669139İzleyin
service/jni/com_android_server_wifi_Gbk2Utf.cpp in the Qualcomm Wi-Fi gbk2utf module in Android before 2016-10-05 allows remote attackers to
KritikCVSS 9,8İstismar yokEPSS %1google · android10 Eki 2016
- CVE-2025-2711031İzleyin
Libmodsecurity3 has possible bypass of encoded HTML entities
YüksekCVSS 7,9İstismar yokEPSS %0trustwave · modsecurity25 Şub 2025
- CVE-2019-1267726İzleyin
Cisco Adaptive Security Appliance Software SSL VPN Denial of Service Vulnerability
OrtaCVSS 6,5İstismar yokEPSS %2cisco · adaptive security appliance software2 Eki 2019
- CVE-2026-4292625İzleyin
NGINX ngx_http_proxy_v2_module vulnerability
OrtaCVSS 6,3Kavram kanıtıEPSS %0f5 · nginx gateway fabric13 May 2026
- CVE-2018-717322İzleyin
A large loop in JBIG2Stream::readSymbolDictSeg in xpdf 4.00 allows an attacker to cause denial of service via a specific file due to inappro
OrtaCVSS 5,5İstismar yokEPSS %1xpdfreader · xpdf15 Şub 2018
- CVE-2016-382922İzleyin
The ih264d decoder in mediaserver in Android 6.x before 2016-08-01 does not initialize certain structure members, which allows remote attack
OrtaCVSS 5,5İstismar yokEPSS %1google · android5 Ağu 2016
- CVE-2016-382822İzleyin
decoder/ih264d_api.c in mediaserver in Android 6.x before 2016-08-01 mishandles invalid PPS and SPS NAL units, which allows remote attackers
OrtaCVSS 5,5İstismar yokEPSS %1google · android5 Ağu 2016
- CVE-2016-382722İzleyin
codecs/hevcdec/SoftHEVC.cpp in libstagefright in mediaserver in Android 6.0.1 before 2016-08-01 mishandles decoder errors, which allows remo
OrtaCVSS 5,5İstismar yokEPSS %1google · android5 Ağu 2016
- CVE-2026-10089122İzleyin
Trusted Domain Project OpenDMARC Internationalized Domain Name opendmarc_policy.c opendmarc_policy_query_dmarc encoding error
OrtaCVSS 5,5İstismar yokEPSS %0trusted domain project · opendmarc2 gün önce
- CVE-2019-1015321İzleyin
A flaw was discovered in fence-agents, prior to version 4.3.4, where using non-ASCII characters in a guest VM's comment or other fields woul
OrtaCVSS 5,0İstismar yokEPSS %2clusterlabs · fence-agents30 Tem 2019
- CVE-2026-4878420İzleyin
Symfony: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or `./` → Generated URL Collapses Off-Route Under RFC 3986 Normalization
OrtaCVSS 5,1İstismar yokEPSS %0sensiolabs · symfony14 Tem 2026
- CVE-2026-8681819İzleyin
fast-uri vulnerable to mailto header injection via percent-encoded field-name desynchronization
OrtaCVSS 4,8İstismar yokEPSS %0fast-uri · fast-uri15 Eyl 2026
- CVE-2018-241518İzleyin
SAP NetWeaver Application Server Java Web Container and HTTP Service (Engine API, from 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; J2EE Engine Ser
OrtaCVSS 4,7İstismar yokEPSS %1sap · netweaver java web container and http service engine9 May 2018
- CVE-2018-728914İzleyin
An issue was discovered in armadito-windows-driver/src/communication.c in Armadito 0.12.7.2.
DüşükCVSS 3,3Kavram kanıtıEPSS %2teclib-edition · armadito antivirus21 Şub 2018
- CVE-2021-3360410İzleyin
Reflected cross-site scripting in development mode handler in Vaadin 14, 15-19
DüşükCVSS 2,5İstismar yokEPSS %0vaadin · flow-server24 Haz 2021
- GHSA-8vfw-v2jv-9hwc10İzleyin
Reflected cross-site scripting in development mode handler in Vaadin
DüşükCVSS 2,5İstismar yokMaven · com.vaadin:flow-server28 Haz 2021
- GHSA-cx7h-h87r-jpgr10İzleyin
The kstring integration in gix-attributes is unsound
DüşükCVSS 2,5İstismar yokcrates.io · gix-attributes25 Tem 2024
- CVE-2024-489099İzleyin
SpiceDB calls to LookupResources using LookupResources2 with caveats may return context is missing when it is not
DüşükCVSS 2,4İstismar yokEPSS %0authzed · spicedb14 Eki 2024