CWE-159 · 11 записей
Improper Handling of Invalid Use of Special Elements
CVE этого класса
11 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2019-9505Эксплойта нет | PrinterLogic Print Management Software does not sanitize special charactersprinterlogic · print management · CWE-159 | Критическая9,8 | — | 3,5 % | 8 мая 2019 г. |
30Наблюдать | CVE-2020-1653Эксплойта нет | Junos OS: Kernel crash (vmcore) or FPC crash due to mbuf leakjuniper · junos · CWE-159 | Высокая7,5 | — | 1,6 % | 17 июл. 2020 г. |
30Наблюдать | CVE-2020-1648Эксплойта нет | Junos OS and Junos OS Evolved: RPD crash when processing a specific BGP packetjuniper · junos · CWE-159 | Высокая7,5 | — | 1,3 % | 17 июл. 2020 г. |
30Наблюдать | CVE-2020-1646Эксплойта нет | Junos OS and Junos OS Evolved: RPD crash while processing a specific BGP update information.juniper · junos · CWE-159 | Высокая7,5 | — | 1,0 % | 17 июл. 2020 г. |
29Наблюдать | CVE-2021-21707Proof of concept | Special characters break path parsing in XML functionsphp · php · CWE-159 | Средняя5,3 | — | 26,0 % | 29 нояб. 2021 г. |
22Наблюдать | CVE-2026-2636Proof of concept | Denial of Service in Microsoft OSmicrosoft · windows os · CWE-159 | Средняя5,5 | — | 0,4 % | 25 февр. 2026 г. |
22Наблюдать | CVE-2021-42375Эксплойта нет | An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due tbusybox · busybox · CWE-159 | Средняя5,5 | — | 0,4 % | 15 нояб. 2021 г. |
21Наблюдать | CVE-2020-29022Эксплойта нет | Host Header Injection allowing web cache poisoning attackssecomea · gatemanager 4250 firmware · CWE-159 | Средняя5,3 | — | 0,8 % | 16 февр. 2021 г. |
21Наблюдать | CVE-2026-35536Эксплойта нет | In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cooktornadoweb · tornado · CWE-159 | Средняя5,3 | — | 0,3 % | 3 апр. 2026 г. |
14Наблюдать | CVE-2025-61984Proof of concept | ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leadinopenbsd · openssh · CWE-159 | Низкая3,6 | — | 0,3 % | 6 окт. 2025 г. |
6Наблюдать | CVE-2025-52884Эксплойта нет | risc0-ethereum-contracts allows invalid commitment with digest value of zero to be accepted by Steel.validateCommitmentrisc0 · risc0-ethereum · CWE-159 | Низкая1,7 | — | 0,4 % | 24 июн. 2025 г. |
- CVE-2019-950540В плане
PrinterLogic Print Management Software does not sanitize special characters
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %printerlogic · print management8 мая 2019 г.
- CVE-2020-165330Наблюдать
Junos OS: Kernel crash (vmcore) or FPC crash due to mbuf leak
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %juniper · junos17 июл. 2020 г.
- CVE-2020-164830Наблюдать
Junos OS and Junos OS Evolved: RPD crash when processing a specific BGP packet
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %juniper · junos17 июл. 2020 г.
- CVE-2020-164630Наблюдать
Junos OS and Junos OS Evolved: RPD crash while processing a specific BGP update information.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %juniper · junos17 июл. 2020 г.
- CVE-2021-2170729Наблюдать
Special characters break path parsing in XML functions
СредняяCVSS 5,3Proof of conceptEPSS 26 %php · php29 нояб. 2021 г.
- CVE-2026-263622Наблюдать
Denial of Service in Microsoft OS
СредняяCVSS 5,5Proof of conceptEPSS 0 %microsoft · windows os25 февр. 2026 г.
- CVE-2021-4237522Наблюдать
An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due t
СредняяCVSS 5,5Эксплойта нетEPSS 0 %busybox · busybox15 нояб. 2021 г.
- CVE-2020-2902221Наблюдать
Host Header Injection allowing web cache poisoning attacks
СредняяCVSS 5,3Эксплойта нетEPSS 1 %secomea · gatemanager 4250 firmware16 февр. 2021 г.
- CVE-2026-3553621Наблюдать
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cook
СредняяCVSS 5,3Эксплойта нетEPSS 0 %tornadoweb · tornado3 апр. 2026 г.
- CVE-2025-6198414Наблюдать
ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leadin
НизкаяCVSS 3,6Proof of conceptEPSS 0 %openbsd · openssh6 окт. 2025 г.
- CVE-2025-528846Наблюдать
risc0-ethereum-contracts allows invalid commitment with digest value of zero to be accepted by Steel.validateCommitment
НизкаяCVSS 1,7Эксплойта нетEPSS 0 %risc0 · risc0-ethereum24 июн. 2025 г.