CWE-170 · 42 записей
Improper Null Termination
CVE этого класса
42 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
46В плане | CVE-2021-22931Эксплойта нет | Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validationnodejs · node.js · CWE-170 | Критическая9,8 | — | 22,0 % | 16 авг. 2021 г. |
40В плане | CVE-2019-8275Эксплойта нет | UltraVNC revision 1211 has multiple improper null termination vulnerabilities in VNC server code, which result in out-of-bound data being acuvnc · ultravnc · CWE-170 | Критическая9,8 | — | 4,0 % | 8 мар. 2019 г. |
40В плане | CVE-2021-31886Эксплойта нет | A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (siemens · nucleus net · CWE-170 | Критическая9,8 | — | 3,0 % | 9 нояб. 2021 г. |
39Наблюдать | CVE-2021-31884Эксплойта нет | A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (siemens · capital vstar · CWE-170 | Критическая9,8 | — | 1,5 % | 9 нояб. 2021 г. |
39Наблюдать | CVE-2021-1411Эксплойта нет | Cisco Jabber Desktop and Mobile Client Software Vulnerabilitiescisco · jabber · CWE-170 | Критическая9,9 | — | 1,4 % | 24 мар. 2021 г. |
39Наблюдать | CVE-2026-42010Эксплойта нет | Gnutls: gnutls: authentication bypass via nul character in usernamegnu · gnutls · CWE-170 | Критическая9,8 | — | 0,9 % | 7 мая 2026 г. |
39Наблюдать | CVE-2026-5067Эксплойта нет | Out-of-bounds read/write in HTTP WebSocket upgrade via non-null-terminated Sec-WebSocket-Keyzephyrproject · zephyr · CWE-170 | Критическая9,8 | — | 0,9 % | 9 июн. 2026 г. |
39Наблюдать | CVE-2026-8721Эксплойта нет | Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl truncates passwords with embedded NULLsjonasbn · crypt::openssl::pkcs12 · CWE-170 | Критическая9,8 | — | 0,6 % | 17 мая 2026 г. |
36Наблюдать | CVE-2021-31888Эксплойта нет | A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (siemens · nucleus net · CWE-170 | Высокая8,8 | — | 2,4 % | 9 нояб. 2021 г. |
36Наблюдать | CVE-2021-31887Эксплойта нет | A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (siemens · nucleus net · CWE-170 | Высокая8,8 | — | 2,4 % | 9 нояб. 2021 г. |
33Наблюдать | CVE-2024-45288Эксплойта нет | Multiple vulnerabilities in libnvfreebsd · freebsd · CWE-170 | Высокая8,4 | — | 0,3 % | 5 сент. 2024 г. |
32Наблюдать | CVE-2019-11044Эксплойта нет | link() silently truncates after a null byte on Windowsphp · php · CWE-170 | Высокая7,5 | — | 5,1 % | 22 дек. 2019 г. |
31Наблюдать | CVE-2023-36906Эксплойта нет | Windows Cryptographic Services Information Disclosure Vulnerabilitymicrosoft · windows 10 · CWE-170 | Высокая7,5 | — | 2,0 % | 8 авг. 2023 г. |
31Наблюдать | CVE-2023-36907Эксплойта нет | Windows Cryptographic Services Information Disclosure Vulnerabilitymicrosoft · windows 10 · CWE-170 | Высокая7,5 | — | 1,7 % | 8 авг. 2023 г. |
31Наблюдать | CVE-2024-21442Эксплойта нет | Windows USB Print Driver Elevation of Privilege Vulnerabilitymicrosoft · windows 10 21h2 · CWE-170 | Высокая7,8 | — | 0,8 % | 12 мар. 2024 г. |
30Наблюдать | CVE-2024-43474Эксплойта нет | Microsoft SQL Server Information Disclosure Vulnerabilitymicrosoft · sql server 2017 · CWE-170 | Высокая7,5 | — | 1,3 % | 10 сент. 2024 г. |
30Наблюдать | CVE-2022-47515Эксплойта нет | An issue was discovered in drachtio-server before 0.8.20.drachtio · drachtio-server · CWE-170 | Высокая7,5 | — | 1,2 % | 18 дек. 2022 г. |
30Наблюдать | CVE-2026-70587Эксплойта нет | Windows Remote Desktop Protocol Information Disclosure Vulnerabilitymicrosoft · windows 10 1607 · CWE-170 | Высокая7,5 | — | 1,0 % | 8 сент. 2026 г. |
30Наблюдать | CVE-2023-24021Эксплойта нет | Incorrect handling of '\0' bytes in file uploads in ModSecurity before 2.9.7 may allow for Web Application Firewall bypasses and buffer overtrustwave · modsecurity · CWE-170 | Высокая7,5 | — | 0,9 % | 20 янв. 2023 г. |
30Наблюдать | CVE-2024-31197Эксплойта нет | Improper Null Termination in libfluid_msg libraryopennetworking · libfluid msg · CWE-170 | Высокая7,5 | — | 0,3 % | 18 сент. 2024 г. |
30Наблюдать | CVE-2025-67790Эксплойта нет | An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5.drivelock · drivelock · CWE-170 | Высокая7,5 | — | 0,3 % | 17 дек. 2025 г. |
29Наблюдать | CVE-2024-31484Эксплойта нет | A vulnerability has been identified in CPC80 Central Processing/Communication (All versions < V16.41), CPCI85 Central Processing/Communicatisiemens · cpc80 central processing/communication · CWE-170 | Высокая7,3 | — | 0,5 % | 14 мая 2024 г. |
28Наблюдать | CVE-2021-1469Эксплойта нет | Cisco Jabber Desktop and Mobile Client Software Vulnerabilitiescisco · jabber · CWE-170 | Высокая7,2 | — | 1,0 % | 24 мар. 2021 г. |
28Наблюдать | CVE-2025-2026Proof of concept | The NPort 6100-G2/6200-G2 Series is affected by a high-severity vulnerability (CVE-2025-2026) that allows remote attackers to execute a nullmoxa · nport 6100-g2/6200-g2 series · CWE-170 | Высокая7,1 | — | 0,4 % | 31 дек. 2025 г. |
28Наблюдать | CVE-2021-1120Эксплойта нет | NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a string provided by the guest OS may not be pnvidia · virtual gpu · CWE-170 | Высокая7,0 | — | 0,2 % | 29 окт. 2021 г. |
- CVE-2021-2293146В плане
Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation
КритическаяCVSS 9,8Эксплойта нетEPSS 22 %nodejs · node.js16 авг. 2021 г.
- CVE-2019-827540В плане
UltraVNC revision 1211 has multiple improper null termination vulnerabilities in VNC server code, which result in out-of-bound data being ac
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %uvnc · ultravnc8 мар. 2019 г.
- CVE-2021-3188640В плане
A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %siemens · nucleus net9 нояб. 2021 г.
- CVE-2021-3188439Наблюдать
A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %siemens · capital vstar9 нояб. 2021 г.
- CVE-2021-141139Наблюдать
Cisco Jabber Desktop and Mobile Client Software Vulnerabilities
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %cisco · jabber24 мар. 2021 г.
- CVE-2026-4201039Наблюдать
Gnutls: gnutls: authentication bypass via nul character in username
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %gnu · gnutls7 мая 2026 г.
- CVE-2026-506739Наблюдать
Out-of-bounds read/write in HTTP WebSocket upgrade via non-null-terminated Sec-WebSocket-Key
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %zephyrproject · zephyr9 июн. 2026 г.
- CVE-2026-872139Наблюдать
Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl truncates passwords with embedded NULLs
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %jonasbn · crypt::openssl::pkcs1217 мая 2026 г.
- CVE-2021-3188836Наблюдать
A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %siemens · nucleus net9 нояб. 2021 г.
- CVE-2021-3188736Наблюдать
A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %siemens · nucleus net9 нояб. 2021 г.
- CVE-2024-4528833Наблюдать
Multiple vulnerabilities in libnv
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %freebsd · freebsd5 сент. 2024 г.
- CVE-2019-1104432Наблюдать
link() silently truncates after a null byte on Windows
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %php · php22 дек. 2019 г.
- CVE-2023-3690631Наблюдать
Windows Cryptographic Services Information Disclosure Vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %microsoft · windows 108 авг. 2023 г.
- CVE-2023-3690731Наблюдать
Windows Cryptographic Services Information Disclosure Vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %microsoft · windows 108 авг. 2023 г.
- CVE-2024-2144231Наблюдать
Windows USB Print Driver Elevation of Privilege Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %microsoft · windows 10 21h212 мар. 2024 г.
- CVE-2024-4347430Наблюдать
Microsoft SQL Server Information Disclosure Vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %microsoft · sql server 201710 сент. 2024 г.
- CVE-2022-4751530Наблюдать
An issue was discovered in drachtio-server before 0.8.20.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %drachtio · drachtio-server18 дек. 2022 г.
- CVE-2026-7058730Наблюдать
Windows Remote Desktop Protocol Information Disclosure Vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %microsoft · windows 10 16078 сент. 2026 г.
- CVE-2023-2402130Наблюдать
Incorrect handling of '\0' bytes in file uploads in ModSecurity before 2.9.7 may allow for Web Application Firewall bypasses and buffer over
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %trustwave · modsecurity20 янв. 2023 г.
- CVE-2024-3119730Наблюдать
Improper Null Termination in libfluid_msg library
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %opennetworking · libfluid msg18 сент. 2024 г.
- CVE-2025-6779030Наблюдать
An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %drivelock · drivelock17 дек. 2025 г.
- CVE-2024-3148429Наблюдать
A vulnerability has been identified in CPC80 Central Processing/Communication (All versions < V16.41), CPCI85 Central Processing/Communicati
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %siemens · cpc80 central processing/communication14 мая 2024 г.
- CVE-2021-146928Наблюдать
Cisco Jabber Desktop and Mobile Client Software Vulnerabilities
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %cisco · jabber24 мар. 2021 г.
- CVE-2025-202628Наблюдать
The NPort 6100-G2/6200-G2 Series is affected by a high-severity vulnerability (CVE-2025-2026) that allows remote attackers to execute a null
ВысокаяCVSS 7,1Proof of conceptEPSS 0 %moxa · nport 6100-g2/6200-g2 series31 дек. 2025 г.
- CVE-2021-112028Наблюдать
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a string provided by the guest OS may not be p
ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %nvidia · virtual gpu29 окт. 2021 г.