İçeriğe atla
Noroxi

CWE-176 · 30 kayıt

Improper Handling of Unicode Encoding

Bu sınıftaki CVE’ler

30 kayıt

  • CVE-2024-43093
    59Planlayın

    In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensit

    YüksekCVSS 7,3KEVSilahlaştırılmışEPSS %1

    google · android13 Kas 2024

  • CVE-2024-24691
    40Planlayın

    Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows - Improper Input Validation

    KritikCVSS 9,8İstismar yokEPSS %2

    zoom · meeting software development kit13 Şub 2024

  • CVE-2023-39213
    39İzleyin

    Improper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VDI Client before 5.15.2 may allow an unauthenticate

    KritikCVSS 9,8İstismar yokEPSS %1

    zoom · virtual desktop infrastructure8 Ağu 2023

  • CVE-2025-71316
    36İzleyin

    SQLite sqldiff remote code execution via argument injection

    KritikCVSS 9,2İstismar yokEPSS %0

    sqlite · sqldiff4 Haz 2026

  • CVE-2026-93990
    34İzleyin

    Expat before 2.8.5 Malformed UTF-16 Acceptance via Unchecked Surrogate

    YüksekCVSS 8,7İstismar yokEPSS %0

    libexpat · libexpat19 Eyl 2026

  • CVE-2026-4116
    28İzleyin

    Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user to bypass Workplace/C

    YüksekCVSS 7,2İstismar yokEPSS %1

    sonicwall · sma6210 firmware9 Nis 2026

  • CVE-2026-48618
    27İzleyin

    A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypas

    OrtaCVSS 6,5İstismar yokEPSS %3

    nodejs · node.js25 Haz 2026

  • CVE-2026-93751
    27İzleyin

    uri-js through 4.4.1 Improper UTF-8 Decoding via pctDecChars

    OrtaCVSS 6,9İstismar yokEPSS %0

    garycourt · uri-js18 Eyl 2026

  • CVE-2026-4114
    26İzleyin

    Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin to bypass AMC TOTP a

    OrtaCVSS 6,6İstismar yokEPSS %1

    sonicwall · sma6210 firmware9 Nis 2026

  • CVE-2026-25480
    26İzleyin

    FileStore key canonicalization collisions allow response cache mixup/poisoning (ASCII ord + Unicode NFKD)

    OrtaCVSS 6,5İstismar yokEPSS %1

    litestar · litestar9 Şub 2026

  • CVE-2026-20202
    26İzleyin

    Improper Input Validation during User Account Creation in Splunk Enterprise

    OrtaCVSS 6,6İstismar yokEPSS %0

    splunk · splunk15 Nis 2026

  • CVE-2026-59890
    24İzleyin

    setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+

    OrtaCVSS 6,1İstismar yokEPSS %0

    python · setuptools8 Tem 2026

  • CVE-2026-23950
    23İzleyin

    node-tar has Race Condition in Path Reservations via Unicode Ligature Collisions on macOS APFS

    OrtaCVSS 5,9İstismar yokEPSS %0

    isaacs · tar19 Oca 2026

  • CVE-2024-8067
    23İzleyin

    Unicode "best fit" argument injection

    OrtaCVSS 5,8İstismar yokEPSS %0

    helix · helix core24 Eyl 2024

  • CVE-2023-31169
    22İzleyin

    Improper Handling of Unicode Encoding

    OrtaCVSS 5,7İstismar yokEPSS %0

    selinc · sel-5030 acselerator quickset31 Ağu 2023

  • CVE-2026-14978
    22İzleyin

    Unicode normalization mismatch in go-slug ignore pattern matching may bypass intended file exclusions

    OrtaCVSS 5,5İstismar yokEPSS %0

    hashicorp · go-slug19 Ağu 2026

  • CVE-2026-35373
    22İzleyin

    uutils coreutils ln Local Denial of Service via Improper Handling of Non-UTF-8 Filenames

    OrtaCVSS 5,5İstismar yokEPSS %0

    uutils · coreutils22 Nis 2026

  • OpenClaw: Unicode canonicalization drift in node metadata policy classification could broaden node allowlists

    OrtaCVSS 5,5İstismar yok

    npm · openclaw2 Mar 2026

  • CVE-2023-41889
    21İzleyin

    Late-Unicode normalization vulnerability in SHIRASAGI

    OrtaCVSS 5,3İstismar yokEPSS %1

    ss-proj · shirasagi15 Eyl 2023

  • CVE-2020-8929
    21İzleyin

    Ciphertext integrity weakness in Tink

    OrtaCVSS 5,3İstismar yokEPSS %0

    google · tink java19 Eki 2020

  • CVE-2026-44288
    21İzleyin

    protobufjs: Overlong UTF-8 decoding

    OrtaCVSS 5,3İstismar yokEPSS %0

    protobufjs project · protobufjs13 May 2026

  • CVE-2025-59547
    21İzleyin

    DNN's CKEditor File Uploader functionality vulnerable through Unicode obfuscation

    OrtaCVSS 5,3İstismar yokEPSS %0

    dnnsoftware · dotnetnuke23 Eyl 2025

  • CVE-2025-55129
    21İzleyin

    HackerOne community member Kassem S.(kassem_s94) has reported that username handling in Revive Adserver was still vulnerable to impersonatio

    OrtaCVSS 5,4İstismar yokEPSS %0

    aquaplatform · revive adserver1 Ara 2025

  • CVE-2026-81869
    20İzleyin

    OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncation

    OrtaCVSS 5,1İstismar yokEPSS %0

    open-telemetry · opentelemetry-go16 Eyl 2026

  • CVE-2026-35346
    13İzleyin

    uutils coreutils comm Silent Data Corruption via Lossy UTF-8 Normalization

    DüşükCVSS 3,3İstismar yokEPSS %0

    uutils · coreutils22 Nis 2026

Tüm zafiyet sınıfları