Перейти к содержимому
Noroxi

CWE-176 · 30 записей

Improper Handling of Unicode Encoding

CVE этого класса

30 записей

  • CVE-2024-43093
    59В плане

    In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensit

    ВысокаяCVSS 7,3KEVГотовый эксплойтEPSS 1 %

    google · android13 нояб. 2024 г.

  • CVE-2024-24691
    40В плане

    Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows - Improper Input Validation

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    zoom · meeting software development kit13 февр. 2024 г.

  • CVE-2023-39213
    39Наблюдать

    Improper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VDI Client before 5.15.2 may allow an unauthenticate

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    zoom · virtual desktop infrastructure8 авг. 2023 г.

  • CVE-2025-71316
    36Наблюдать

    SQLite sqldiff remote code execution via argument injection

    КритическаяCVSS 9,2Эксплойта нетEPSS 0 %

    sqlite · sqldiff4 июн. 2026 г.

  • CVE-2026-93990
    34Наблюдать

    Expat before 2.8.5 Malformed UTF-16 Acceptance via Unchecked Surrogate

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    libexpat · libexpat19 сент. 2026 г.

  • CVE-2026-4116
    28Наблюдать

    Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user to bypass Workplace/C

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    sonicwall · sma6210 firmware9 апр. 2026 г.

  • CVE-2026-48618
    27Наблюдать

    A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypas

    СредняяCVSS 6,5Эксплойта нетEPSS 3 %

    nodejs · node.js25 июн. 2026 г.

  • CVE-2026-93751
    27Наблюдать

    uri-js through 4.4.1 Improper UTF-8 Decoding via pctDecChars

    СредняяCVSS 6,9Эксплойта нетEPSS 0 %

    garycourt · uri-js18 сент. 2026 г.

  • CVE-2026-4114
    26Наблюдать

    Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin to bypass AMC TOTP a

    СредняяCVSS 6,6Эксплойта нетEPSS 1 %

    sonicwall · sma6210 firmware9 апр. 2026 г.

  • CVE-2026-25480
    26Наблюдать

    FileStore key canonicalization collisions allow response cache mixup/poisoning (ASCII ord + Unicode NFKD)

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    litestar · litestar9 февр. 2026 г.

  • CVE-2026-20202
    26Наблюдать

    Improper Input Validation during User Account Creation in Splunk Enterprise

    СредняяCVSS 6,6Эксплойта нетEPSS 0 %

    splunk · splunk15 апр. 2026 г.

  • CVE-2026-59890
    24Наблюдать

    setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    python · setuptools8 июл. 2026 г.

  • CVE-2026-23950
    23Наблюдать

    node-tar has Race Condition in Path Reservations via Unicode Ligature Collisions on macOS APFS

    СредняяCVSS 5,9Эксплойта нетEPSS 0 %

    isaacs · tar19 янв. 2026 г.

  • CVE-2024-8067
    23Наблюдать

    Unicode "best fit" argument injection

    СредняяCVSS 5,8Эксплойта нетEPSS 0 %

    helix · helix core24 сент. 2024 г.

  • CVE-2023-31169
    22Наблюдать

    Improper Handling of Unicode Encoding

    СредняяCVSS 5,7Эксплойта нетEPSS 0 %

    selinc · sel-5030 acselerator quickset31 авг. 2023 г.

  • CVE-2026-14978
    22Наблюдать

    Unicode normalization mismatch in go-slug ignore pattern matching may bypass intended file exclusions

    СредняяCVSS 5,5Эксплойта нетEPSS 0 %

    hashicorp · go-slug19 авг. 2026 г.

  • CVE-2026-35373
    22Наблюдать

    uutils coreutils ln Local Denial of Service via Improper Handling of Non-UTF-8 Filenames

    СредняяCVSS 5,5Эксплойта нетEPSS 0 %

    uutils · coreutils22 апр. 2026 г.

  • GHSA-392f-ggf5-fp3c
    22Наблюдать

    OpenClaw: Unicode canonicalization drift in node metadata policy classification could broaden node allowlists

    СредняяCVSS 5,5Эксплойта нет

    npm · openclaw2 мар. 2026 г.

  • CVE-2023-41889
    21Наблюдать

    Late-Unicode normalization vulnerability in SHIRASAGI

    СредняяCVSS 5,3Эксплойта нетEPSS 1 %

    ss-proj · shirasagi15 сент. 2023 г.

  • CVE-2020-8929
    21Наблюдать

    Ciphertext integrity weakness in Tink

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    google · tink java19 окт. 2020 г.

  • CVE-2026-44288
    21Наблюдать

    protobufjs: Overlong UTF-8 decoding

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    protobufjs project · protobufjs13 мая 2026 г.

  • CVE-2025-59547
    21Наблюдать

    DNN's CKEditor File Uploader functionality vulnerable through Unicode obfuscation

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    dnnsoftware · dotnetnuke23 сент. 2025 г.

  • CVE-2025-55129
    21Наблюдать

    HackerOne community member Kassem S.(kassem_s94) has reported that username handling in Revive Adserver was still vulnerable to impersonatio

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    aquaplatform · revive adserver1 дек. 2025 г.

  • CVE-2026-81869
    20Наблюдать

    OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncation

    СредняяCVSS 5,1Эксплойта нетEPSS 0 %

    open-telemetry · opentelemetry-go16 сент. 2026 г.

  • CVE-2026-35346
    13Наблюдать

    uutils coreutils comm Silent Data Corruption via Lossy UTF-8 Normalization

    НизкаяCVSS 3,3Эксплойта нетEPSS 0 %

    uutils · coreutils22 апр. 2026 г.

Все классы уязвимостей