Skip to content
Noroxi

CWE-159 · 11 records

Improper Handling of Invalid Use of Special Elements

CVEs in this class

11 records

  • PrinterLogic Print Management Software does not sanitize special characters

    CriticalCVSS 9.8No exploitEPSS 3%

    printerlogic · print managementMay 8, 2019

  • CVE-2020-1653
    30Monitor

    Junos OS: Kernel crash (vmcore) or FPC crash due to mbuf leak

    HighCVSS 7.5No exploitEPSS 2%

    juniper · junosJul 17, 2020

  • CVE-2020-1648
    30Monitor

    Junos OS and Junos OS Evolved: RPD crash when processing a specific BGP packet

    HighCVSS 7.5No exploitEPSS 1%

    juniper · junosJul 17, 2020

  • CVE-2020-1646
    30Monitor

    Junos OS and Junos OS Evolved: RPD crash while processing a specific BGP update information.

    HighCVSS 7.5No exploitEPSS 1%

    juniper · junosJul 17, 2020

  • Special characters break path parsing in XML functions

    MediumCVSS 5.3Proof of conceptEPSS 26%

    php · phpNov 29, 2021

  • CVE-2026-2636
    22Monitor

    Denial of Service in Microsoft OS

    MediumCVSS 5.5Proof of conceptEPSS 0%

    microsoft · windows osFeb 25, 2026

  • An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due t

    MediumCVSS 5.5No exploitEPSS 0%

    busybox · busyboxNov 15, 2021

  • Host Header Injection allowing web cache poisoning attacks

    MediumCVSS 5.3No exploitEPSS 1%

    secomea · gatemanager 4250 firmwareFeb 16, 2021

  • In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cook

    MediumCVSS 5.3No exploitEPSS 0%

    tornadoweb · tornadoApr 3, 2026

  • ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leadin

    LowCVSS 3.6Proof of conceptEPSS 0%

    openbsd · opensshOct 6, 2025

  • risc0-ethereum-contracts allows invalid commitment with digest value of zero to be accepted by Steel.validateCommitment

    LowCVSS 1.7No exploitEPSS 0%

    risc0 · risc0-ethereumJun 24, 2025

All vulnerability classes