CWE-158 · 27 записей
Improper Neutralization of Null Byte or NUL Character
CVE этого класса
27 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
98Срочно | CVE-2025-47812Готовый эксплойт | In Wing FTP Server before 7.4.4.wftpserver · wing ftp server · CWE-158 | Критическая10,0 | KEV | 92,9 % | 10 июл. 2025 г. |
80Срочно | CVE-2009-1537Готовый эксплойт | Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows microsoft · directx · CWE-158 | Высокая8,8 | KEV | 51,2 % | 29 мая 2009 г. |
39Наблюдать | CVE-2020-14500Эксплойта нет | IMPROPER NEUTRALIZATION OF NULL BYTE OR NUL CHARACTER CWE-158secomea · gatemanager 8250 firmware · CWE-158 | Критическая9,8 | — | 1,7 % | 25 авг. 2020 г. |
39Наблюдать | CVE-2023-5719Эксплойта нет | Red Lion Crimson Improper Neutralization of Null Byte or NUL Characterredlion · crimson · CWE-158 | Критическая9,8 | — | 0,5 % | 6 нояб. 2023 г. |
39Наблюдать | CVE-2025-14388Эксплойта нет | PhastPress <= 3.7 - Unauthenticated Arbitrary File Read via Null Byte Injectionkiboit · phastpress · CWE-158 | Критическая9,8 | — | 0,5 % | 23 дек. 2025 г. |
38Наблюдать | CVE-2025-55113Эксплойта нет | BMC Control-M/Agent unescaped NULL byte in access control list checksbmc · control-m\/agent · CWE-158 | Критическая9,5 | — | 0,3 % | 16 сент. 2025 г. |
35Наблюдать | CVE-2025-66263Эксплойта нет | Unauthenticated Arbitrary File Read via Null Byte Injectiondbbroadcast · mozart next 3000 firmware · CWE-158 | Высокая8,9 | — | 0,4 % | 25 нояб. 2025 г. |
34Наблюдать | CVE-2025-9648Эксплойта нет | Denial of Service in CivetWebcivetweb · civetweb · CWE-158 | Высокая8,7 | — | 0,8 % | 29 сент. 2025 г. |
34Наблюдать | CVE-2026-33191Эксплойта нет | free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Errorfree5gc · udm · CWE-158 | Высокая8,7 | — | 0,6 % | 20 мар. 2026 г. |
32Наблюдать | CVE-2024-10921Эксплойта нет | Improper neutralization of null bytes may lead to buffer over-reads in MongoDB Servermongodb · mongodb · CWE-158 | Высокая8,1 | — | 0,6 % | 14 нояб. 2024 г. |
32Наблюдать | CVE-2026-76354Эксплойта нет | Path Traversal through Search Head Clustering in Splunk Enterprisesplunk · splunk · CWE-158 | Высокая8,1 | — | 0,4 % | 19 авг. 2026 г. |
30Наблюдать | CVE-2022-41716Эксплойта нет | Unsanitized NUL in environment variables on Windows in syscall and os/execgolang · go · CWE-158 | Высокая7,5 | — | 0,8 % | 2 нояб. 2022 г. |
29Наблюдать | CVE-2025-1936Эксплойта нет | Adding %00 and a fake extension to a jar: URL changed the interpretation of the contentsmozilla · firefox · CWE-158 | Высокая7,3 | — | 0,4 % | 4 мар. 2025 г. |
27Наблюдать | CVE-2022-20812Эксплойта нет | Cisco Expressway Series and Cisco TelePresence Video Communication Server Vulnerabilitiescisco · expressway · CWE-158 | Средняя6,5 | — | 1,9 % | 6 июл. 2022 г. |
26Наблюдать | CVE-2020-7928Эксплойта нет | Improper neutralization of null byte leads to read overrunmongodb · mongodb · CWE-158 | Средняя6,5 | — | 1,4 % | 23 нояб. 2020 г. |
26Наблюдать | CVE-2026-23863Эксплойта нет | An attachment spoofing issue in WhatsApp for Windows prior to v2.3000.1032164386.258709 could have allowed maliciously formatted documents wwhatsapp · whatsapp · CWE-158 | Средняя6,5 | — | 0,5 % | 1 мая 2026 г. |
26Наблюдать | CVE-2020-5363Эксплойта нет | Select Dell Client Consumer and Commercial platforms include an issue that allows the BIOS Admin password to be changed through Dell's managdell · latitude 5300 firmware · CWE-158 | Средняя6,7 | — | 0,3 % | 10 июн. 2020 г. |
23Наблюдать | CVE-2022-20813Эксплойта нет | Cisco Expressway Series and Cisco TelePresence Video Communication Server Vulnerabilitiescisco · expressway · CWE-158 | Средняя5,9 | — | 1,1 % | 6 июл. 2022 г. |
22Наблюдать | CVE-2024-0408Эксплойта нет | Xorg-x11-server: selinux unlabeled glx pbufferx.org · x server · CWE-158 | Средняя5,5 | — | 0,3 % | 18 янв. 2024 г. |
22Наблюдать | CVE-2026-41256Эксплойта нет | jq: Embedded NUL truncates top-level jq programs loaded with -fjqlang · jq · CWE-158 | Средняя5,5 | — | 0,2 % | 11 мая 2026 г. |
17Наблюдать | CVE-2026-47778Эксплойта нет | Envoy: Embedded NUL in TLS DNS SAN Truncation in the Default TLS Certificate Validator. (Auth Bypass)envoyproxy · envoy · CWE-158 | Средняя4,4 | — | 0,2 % | 26 июн. 2026 г. |
14Наблюдать | CVE-2026-43859Эксплойта нет | mutt before 2.3.2 sometimes uses strfcpy instead of memcpy for the IMAP auth_cram MD5 digest.mutt · mutt · CWE-158 | Низкая3,7 | — | 0,3 % | 4 мая 2026 г. |
14Наблюдать | CVE-2026-43861Эксплойта нет | mutt before 2.3.2 does not check for '\0' in url_pct_decode.mutt · mutt · CWE-158 | Низкая3,7 | — | 0,3 % | 4 мая 2026 г. |
14Наблюдать | CVE-2025-61985Эксплойта нет | ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used.openbsd · openssh · CWE-158 | Низкая3,6 | — | 0,1 % | 6 окт. 2025 г. |
13Наблюдать | CVE-2026-28540Эксплойта нет | Out-of-bounds character read vulnerability in Bluetooth.huawei · harmonyos · CWE-158 | Низкая3,3 | — | 0,1 % | 5 мар. 2026 г. |
- CVE-2025-4781298Срочно
In Wing FTP Server before 7.4.4.
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 93 %wftpserver · wing ftp server10 июл. 2025 г.
- CVE-2009-153780Срочно
Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 51 %microsoft · directx29 мая 2009 г.
- CVE-2020-1450039Наблюдать
IMPROPER NEUTRALIZATION OF NULL BYTE OR NUL CHARACTER CWE-158
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %secomea · gatemanager 8250 firmware25 авг. 2020 г.
- CVE-2023-571939Наблюдать
Red Lion Crimson Improper Neutralization of Null Byte or NUL Character
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %redlion · crimson6 нояб. 2023 г.
- CVE-2025-1438839Наблюдать
PhastPress <= 3.7 - Unauthenticated Arbitrary File Read via Null Byte Injection
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %kiboit · phastpress23 дек. 2025 г.
- CVE-2025-5511338Наблюдать
BMC Control-M/Agent unescaped NULL byte in access control list checks
КритическаяCVSS 9,5Эксплойта нетEPSS 0 %bmc · control-m\/agent16 сент. 2025 г.
- CVE-2025-6626335Наблюдать
Unauthenticated Arbitrary File Read via Null Byte Injection
ВысокаяCVSS 8,9Эксплойта нетEPSS 0 %dbbroadcast · mozart next 3000 firmware25 нояб. 2025 г.
- CVE-2025-964834Наблюдать
Denial of Service in CivetWeb
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %civetweb · civetweb29 сент. 2025 г.
- CVE-2026-3319134Наблюдать
free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %free5gc · udm20 мар. 2026 г.
- CVE-2024-1092132Наблюдать
Improper neutralization of null bytes may lead to buffer over-reads in MongoDB Server
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %mongodb · mongodb14 нояб. 2024 г.
- CVE-2026-7635432Наблюдать
Path Traversal through Search Head Clustering in Splunk Enterprise
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %splunk · splunk19 авг. 2026 г.
- CVE-2022-4171630Наблюдать
Unsanitized NUL in environment variables on Windows in syscall and os/exec
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %golang · go2 нояб. 2022 г.
- CVE-2025-193629Наблюдать
Adding %00 and a fake extension to a jar: URL changed the interpretation of the contents
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %mozilla · firefox4 мар. 2025 г.
- CVE-2022-2081227Наблюдать
Cisco Expressway Series and Cisco TelePresence Video Communication Server Vulnerabilities
СредняяCVSS 6,5Эксплойта нетEPSS 2 %cisco · expressway6 июл. 2022 г.
- CVE-2020-792826Наблюдать
Improper neutralization of null byte leads to read overrun
СредняяCVSS 6,5Эксплойта нетEPSS 1 %mongodb · mongodb23 нояб. 2020 г.
- CVE-2026-2386326Наблюдать
An attachment spoofing issue in WhatsApp for Windows prior to v2.3000.1032164386.258709 could have allowed maliciously formatted documents w
СредняяCVSS 6,5Эксплойта нетEPSS 1 %whatsapp · whatsapp1 мая 2026 г.
- CVE-2020-536326Наблюдать
Select Dell Client Consumer and Commercial platforms include an issue that allows the BIOS Admin password to be changed through Dell's manag
СредняяCVSS 6,7Эксплойта нетEPSS 0 %dell · latitude 5300 firmware10 июн. 2020 г.
- CVE-2022-2081323Наблюдать
Cisco Expressway Series and Cisco TelePresence Video Communication Server Vulnerabilities
СредняяCVSS 5,9Эксплойта нетEPSS 1 %cisco · expressway6 июл. 2022 г.
- CVE-2024-040822Наблюдать
Xorg-x11-server: selinux unlabeled glx pbuffer
СредняяCVSS 5,5Эксплойта нетEPSS 0 %x.org · x server18 янв. 2024 г.
- CVE-2026-4125622Наблюдать
jq: Embedded NUL truncates top-level jq programs loaded with -f
СредняяCVSS 5,5Эксплойта нетEPSS 0 %jqlang · jq11 мая 2026 г.
- CVE-2026-4777817Наблюдать
Envoy: Embedded NUL in TLS DNS SAN Truncation in the Default TLS Certificate Validator. (Auth Bypass)
СредняяCVSS 4,4Эксплойта нетEPSS 0 %envoyproxy · envoy26 июн. 2026 г.
- CVE-2026-4385914Наблюдать
mutt before 2.3.2 sometimes uses strfcpy instead of memcpy for the IMAP auth_cram MD5 digest.
НизкаяCVSS 3,7Эксплойта нетEPSS 0 %mutt · mutt4 мая 2026 г.
- CVE-2026-4386114Наблюдать
mutt before 2.3.2 does not check for '\0' in url_pct_decode.
НизкаяCVSS 3,7Эксплойта нетEPSS 0 %mutt · mutt4 мая 2026 г.
- CVE-2025-6198514Наблюдать
ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used.
НизкаяCVSS 3,6Эксплойта нетEPSS 0 %openbsd · openssh6 окт. 2025 г.
- CVE-2026-2854013Наблюдать
Out-of-bounds character read vulnerability in Bluetooth.
НизкаяCVSS 3,3Эксплойта нетEPSS 0 %huawei · harmonyos5 мар. 2026 г.