CWE-159 · 11 records
Improper Handling of Invalid Use of Special Elements
CVEs in this class
11 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2019-9505No exploit | PrinterLogic Print Management Software does not sanitize special charactersprinterlogic · print management · CWE-159 | Critical9.8 | — | 3.5% | May 8, 2019 |
30Monitor | CVE-2020-1653No exploit | Junos OS: Kernel crash (vmcore) or FPC crash due to mbuf leakjuniper · junos · CWE-159 | High7.5 | — | 1.6% | Jul 17, 2020 |
30Monitor | CVE-2020-1648No exploit | Junos OS and Junos OS Evolved: RPD crash when processing a specific BGP packetjuniper · junos · CWE-159 | High7.5 | — | 1.3% | Jul 17, 2020 |
30Monitor | CVE-2020-1646No exploit | Junos OS and Junos OS Evolved: RPD crash while processing a specific BGP update information.juniper · junos · CWE-159 | High7.5 | — | 1.0% | Jul 17, 2020 |
29Monitor | CVE-2021-21707Proof of concept | Special characters break path parsing in XML functionsphp · php · CWE-159 | Medium5.3 | — | 26.0% | Nov 29, 2021 |
22Monitor | CVE-2026-2636Proof of concept | Denial of Service in Microsoft OSmicrosoft · windows os · CWE-159 | Medium5.5 | — | 0.4% | Feb 25, 2026 |
22Monitor | CVE-2021-42375No exploit | An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due tbusybox · busybox · CWE-159 | Medium5.5 | — | 0.4% | Nov 15, 2021 |
21Monitor | CVE-2020-29022No exploit | Host Header Injection allowing web cache poisoning attackssecomea · gatemanager 4250 firmware · CWE-159 | Medium5.3 | — | 0.8% | Feb 16, 2021 |
21Monitor | CVE-2026-35536No exploit | In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cooktornadoweb · tornado · CWE-159 | Medium5.3 | — | 0.3% | Apr 3, 2026 |
14Monitor | CVE-2025-61984Proof of concept | ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leadinopenbsd · openssh · CWE-159 | Low3.6 | — | 0.4% | Oct 6, 2025 |
6Monitor | CVE-2025-52884No exploit | risc0-ethereum-contracts allows invalid commitment with digest value of zero to be accepted by Steel.validateCommitmentrisc0 · risc0-ethereum · CWE-159 | Low1.7 | — | 0.4% | Jun 24, 2025 |
- CVE-2019-950540Plan
PrinterLogic Print Management Software does not sanitize special characters
CriticalCVSS 9.8No exploitEPSS 3%printerlogic · print managementMay 8, 2019
- CVE-2020-165330Monitor
Junos OS: Kernel crash (vmcore) or FPC crash due to mbuf leak
HighCVSS 7.5No exploitEPSS 2%juniper · junosJul 17, 2020
- CVE-2020-164830Monitor
Junos OS and Junos OS Evolved: RPD crash when processing a specific BGP packet
HighCVSS 7.5No exploitEPSS 1%juniper · junosJul 17, 2020
- CVE-2020-164630Monitor
Junos OS and Junos OS Evolved: RPD crash while processing a specific BGP update information.
HighCVSS 7.5No exploitEPSS 1%juniper · junosJul 17, 2020
- CVE-2021-2170729Monitor
Special characters break path parsing in XML functions
MediumCVSS 5.3Proof of conceptEPSS 26%php · phpNov 29, 2021
- CVE-2026-263622Monitor
Denial of Service in Microsoft OS
MediumCVSS 5.5Proof of conceptEPSS 0%microsoft · windows osFeb 25, 2026
- CVE-2021-4237522Monitor
An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due t
MediumCVSS 5.5No exploitEPSS 0%busybox · busyboxNov 15, 2021
- CVE-2020-2902221Monitor
Host Header Injection allowing web cache poisoning attacks
MediumCVSS 5.3No exploitEPSS 1%secomea · gatemanager 4250 firmwareFeb 16, 2021
- CVE-2026-3553621Monitor
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cook
MediumCVSS 5.3No exploitEPSS 0%tornadoweb · tornadoApr 3, 2026
- CVE-2025-6198414Monitor
ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leadin
LowCVSS 3.6Proof of conceptEPSS 0%openbsd · opensshOct 6, 2025
- CVE-2025-528846Monitor
risc0-ethereum-contracts allows invalid commitment with digest value of zero to be accepted by Steel.validateCommitment
LowCVSS 1.7No exploitEPSS 0%risc0 · risc0-ethereumJun 24, 2025