Перейти к содержимому
Noroxi

CWE-158 · 27 записей

Improper Neutralization of Null Byte or NUL Character

CVE этого класса

27 записей

  • CVE-2025-47812
    98Срочно

    In Wing FTP Server before 7.4.4.

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 93 %

    wftpserver · wing ftp server10 июл. 2025 г.

  • CVE-2009-1537
    80Срочно

    Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows

    ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 51 %

    microsoft · directx29 мая 2009 г.

  • CVE-2020-14500
    39Наблюдать

    IMPROPER NEUTRALIZATION OF NULL BYTE OR NUL CHARACTER CWE-158

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    secomea · gatemanager 8250 firmware25 авг. 2020 г.

  • CVE-2023-5719
    39Наблюдать

    Red Lion Crimson Improper Neutralization of Null Byte or NUL Character

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    redlion · crimson6 нояб. 2023 г.

  • CVE-2025-14388
    39Наблюдать

    PhastPress <= 3.7 - Unauthenticated Arbitrary File Read via Null Byte Injection

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    kiboit · phastpress23 дек. 2025 г.

  • CVE-2025-55113
    38Наблюдать

    BMC Control-M/Agent unescaped NULL byte in access control list checks

    КритическаяCVSS 9,5Эксплойта нетEPSS 0 %

    bmc · control-m\/agent16 сент. 2025 г.

  • CVE-2025-66263
    35Наблюдать

    Unauthenticated Arbitrary File Read via Null Byte Injection

    ВысокаяCVSS 8,9Эксплойта нетEPSS 0 %

    dbbroadcast · mozart next 3000 firmware25 нояб. 2025 г.

  • CVE-2025-9648
    34Наблюдать

    Denial of Service in CivetWeb

    ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %

    civetweb · civetweb29 сент. 2025 г.

  • CVE-2026-33191
    34Наблюдать

    free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error

    ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %

    free5gc · udm20 мар. 2026 г.

  • CVE-2024-10921
    32Наблюдать

    Improper neutralization of null bytes may lead to buffer over-reads in MongoDB Server

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    mongodb · mongodb14 нояб. 2024 г.

  • CVE-2026-76354
    32Наблюдать

    Path Traversal through Search Head Clustering in Splunk Enterprise

    ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %

    splunk · splunk19 авг. 2026 г.

  • CVE-2022-41716
    30Наблюдать

    Unsanitized NUL in environment variables on Windows in syscall and os/exec

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    golang · go2 нояб. 2022 г.

  • CVE-2025-1936
    29Наблюдать

    Adding %00 and a fake extension to a jar: URL changed the interpretation of the contents

    ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %

    mozilla · firefox4 мар. 2025 г.

  • CVE-2022-20812
    27Наблюдать

    Cisco Expressway Series and Cisco TelePresence Video Communication Server Vulnerabilities

    СредняяCVSS 6,5Эксплойта нетEPSS 2 %

    cisco · expressway6 июл. 2022 г.

  • CVE-2020-7928
    26Наблюдать

    Improper neutralization of null byte leads to read overrun

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    mongodb · mongodb23 нояб. 2020 г.

  • CVE-2026-23863
    26Наблюдать

    An attachment spoofing issue in WhatsApp for Windows prior to v2.3000.1032164386.258709 could have allowed maliciously formatted documents w

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    whatsapp · whatsapp1 мая 2026 г.

  • CVE-2020-5363
    26Наблюдать

    Select Dell Client Consumer and Commercial platforms include an issue that allows the BIOS Admin password to be changed through Dell's manag

    СредняяCVSS 6,7Эксплойта нетEPSS 0 %

    dell · latitude 5300 firmware10 июн. 2020 г.

  • CVE-2022-20813
    23Наблюдать

    Cisco Expressway Series and Cisco TelePresence Video Communication Server Vulnerabilities

    СредняяCVSS 5,9Эксплойта нетEPSS 1 %

    cisco · expressway6 июл. 2022 г.

  • CVE-2024-0408
    22Наблюдать

    Xorg-x11-server: selinux unlabeled glx pbuffer

    СредняяCVSS 5,5Эксплойта нетEPSS 0 %

    x.org · x server18 янв. 2024 г.

  • CVE-2026-41256
    22Наблюдать

    jq: Embedded NUL truncates top-level jq programs loaded with -f

    СредняяCVSS 5,5Эксплойта нетEPSS 0 %

    jqlang · jq11 мая 2026 г.

  • CVE-2026-47778
    17Наблюдать

    Envoy: Embedded NUL in TLS DNS SAN Truncation in the Default TLS Certificate Validator. (Auth Bypass)

    СредняяCVSS 4,4Эксплойта нетEPSS 0 %

    envoyproxy · envoy26 июн. 2026 г.

  • CVE-2026-43859
    14Наблюдать

    mutt before 2.3.2 sometimes uses strfcpy instead of memcpy for the IMAP auth_cram MD5 digest.

    НизкаяCVSS 3,7Эксплойта нетEPSS 0 %

    mutt · mutt4 мая 2026 г.

  • CVE-2026-43861
    14Наблюдать

    mutt before 2.3.2 does not check for '\0' in url_pct_decode.

    НизкаяCVSS 3,7Эксплойта нетEPSS 0 %

    mutt · mutt4 мая 2026 г.

  • CVE-2025-61985
    14Наблюдать

    ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used.

    НизкаяCVSS 3,6Эксплойта нетEPSS 0 %

    openbsd · openssh6 окт. 2025 г.

  • CVE-2026-28540
    13Наблюдать

    Out-of-bounds character read vulnerability in Bluetooth.

    НизкаяCVSS 3,3Эксплойта нетEPSS 0 %

    huawei · harmonyos5 мар. 2026 г.

Все классы уязвимостей