CWE-228 · 23 записей
Improper Handling of Syntactically Invalid Structure
CVE этого класса
23 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2021-38443Эксплойта нет | Eclipse CycloneDDS Improper Handling of Syntactically Invalid Structureeclipse · cyclonedds · CWE-228 | Критическая9,8 | — | 2,1 % | 5 мая 2022 г. |
40В плане | CVE-2020-27847Эксплойта нет | A vulnerability exists in the SAML connector of the github.com/dexidp/dex library used to process SAML Signature Validation.linuxfoundation · dex · CWE-228 | Критическая9,8 | — | 1,7 % | 28 мая 2021 г. |
40В плане | CVE-2026-87986Эксплойта нет | An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using shell constructs it'smistralai · mistral-vibe · CWE-228 | Критическая10,0 | — | 0,6 % | 11 сент. 2026 г. |
39Наблюдать | CVE-2018-5381Эксплойта нет | The Quagga BGP daemon (bgpd) prior to version 1.2.3 has a bug in its parsing of "Capabilities" in BGP OPEN messages, in the bgp_packet.c:bgpquagga · quagga · CWE-228 | Высокая7,5 | — | 30,2 % | 19 февр. 2018 г. |
39Наблюдать | CVE-2024-55594Эксплойта нет | An improper handling of syntactically invalid structure in Fortinet FortiWeb at least vesrions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 fortinet · fortiweb · CWE-228 | Критическая9,8 | — | 0,5 % | 14 мар. 2025 г. |
39Наблюдать | CVE-2023-42784Эксплойта нет | An improper handling of syntactically invalid structure in Fortinet FortiWeb at least verions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 afortinet · fortiweb · CWE-228 | Критическая9,8 | — | 0,4 % | 11 мар. 2025 г. |
32Наблюдать | GHSA-hrhf-2vcr-ghchЭксплойта нет | CometBFT's invalid BitArray handling can lead to network haltGo · github.com/cometbft/cometbft · CWE-228 | Высокая8,0 | — | — | 14 окт. 2025 г. |
30Наблюдать | CVE-2026-34232Эксплойта нет | Firebird: DoS via `op_response` packet from clientfirebirdsql · firebird · CWE-228 | Высокая7,5 | — | 0,7 % | 17 апр. 2026 г. |
30Наблюдать | CVE-2025-22865Эксплойта нет | ParsePKCS1PrivateKey panic with partial keys in crypto/x509go standard library · crypto/x509 · CWE-228 | Высокая7,5 | — | 0,6 % | 27 янв. 2025 г. |
30Наблюдать | CVE-2024-21612Эксплойта нет | Junos OS Evolved: Specific TCP traffic causes OFP core and restart of REjuniper · junos os evolved · CWE-228 | Высокая7,5 | — | 0,5 % | 11 янв. 2024 г. |
30Наблюдать | CVE-2025-0343Эксплойта нет | Swift ASN.1 can be caused to crash when parsing certain BER/DER constructions.swift project · swift asn1 · CWE-228 | Высокая7,5 | — | 0,3 % | 14 янв. 2025 г. |
30Наблюдать | CVE-2026-20125Эксплойта нет | A vulnerability in the HTTP Server feature of Cisco IOS Software and Cisco IOS XE Software Release 3E could allow an authenticated, remote acisco · ios · CWE-228 | Высокая7,7 | — | 0,3 % | 25 мар. 2026 г. |
30Наблюдать | CVE-2024-6382Эксплойта нет | Adversarial unsanitized input may cause MongoDB Rust Driver to issue unintended commands.mongodb · rust driver · CWE-228 | Высокая7,5 | — | 0,3 % | 2 июл. 2024 г. |
28Наблюдать | CVE-2026-42100Эксплойта нет | DoS in Sparx Pro Cloud Serversparxsystems · pro cloud server · CWE-228 | Высокая7,1 | — | 0,6 % | 19 мая 2026 г. |
28Наблюдать | CVE-2026-25657Эксплойта нет | Ericsson Packet Core Gateway (PCG) - Improper Handling of Syntactically Invalid Structure Vulnerabilityericsson · packet core gateway · CWE-228 | Высокая7,1 | — | 0,3 % | 5 июн. 2026 г. |
28Наблюдать | CVE-2026-50103Эксплойта нет | Improper Handling of Syntactically Invalid Structure in MZ Automation libIEC61850mz automation · libiec61850 · CWE-228 | Высокая7,1 | — | 0,3 % | 23 июл. 2026 г. |
28Наблюдать | CVE-2025-59174Эксплойта нет | Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large volume of specially cericsson · packet core controller · CWE-228 | Высокая7,1 | — | 0,2 % | 5 июн. 2026 г. |
26Наблюдать | CVE-2024-22809Эксплойта нет | Incorrect access control in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to access the G code's shared folder andtormach · pathpilot controller · CWE-228 | Средняя6,5 | — | 0,3 % | 22 апр. 2024 г. |
21Наблюдать | CVE-2021-36199Эксплойта нет | Running a vulnerability scanner against VideoEdge NVRs can cause some functionality to stop.johnsoncontrols · videoedge · CWE-228 | Средняя5,3 | — | 1,0 % | 14 янв. 2022 г. |
21Наблюдать | CVE-2024-53828Эксплойта нет | Ericsson Packet Core Controller (PCC) - Improper Handling of Syntactically Invalid Structure Vulnerabilityericsson · packet core controller · CWE-228 | Средняя5,3 | — | 0,4 % | 1 апр. 2026 г. |
21Наблюдать | CVE-2024-22815Эксплойта нет | An issue in the communication protocol of Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cause a Denial of Servitormach · pathpilot controller · CWE-228 | Средняя5,3 | — | 0,2 % | 22 апр. 2024 г. |
14Наблюдать | CVE-2025-2529Эксплойта нет | IBM Terracotta denial of serviceibm · terracotta · CWE-228 | Низкая3,7 | — | 0,2 % | 15 окт. 2025 г. |
11Наблюдать | CVE-2025-47736Эксплойта нет | dialect/mod.rs in the libsql-sqlite3-parser crate through 0.13.0 before 14f422a for Rust can crash if the input is not valid UTF-8.gwenn · libsql-sqlite3-parser · CWE-228 | Низкая2,9 | — | 0,2 % | 9 мая 2025 г. |
- CVE-2021-3844340В плане
Eclipse CycloneDDS Improper Handling of Syntactically Invalid Structure
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %eclipse · cyclonedds5 мая 2022 г.
- CVE-2020-2784740В плане
A vulnerability exists in the SAML connector of the github.com/dexidp/dex library used to process SAML Signature Validation.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %linuxfoundation · dex28 мая 2021 г.
- CVE-2026-8798640В плане
An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using shell constructs it's
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %mistralai · mistral-vibe11 сент. 2026 г.
- CVE-2018-538139Наблюдать
The Quagga BGP daemon (bgpd) prior to version 1.2.3 has a bug in its parsing of "Capabilities" in BGP OPEN messages, in the bgp_packet.c:bgp
ВысокаяCVSS 7,5Эксплойта нетEPSS 30 %quagga · quagga19 февр. 2018 г.
- CVE-2024-5559439Наблюдать
An improper handling of syntactically invalid structure in Fortinet FortiWeb at least vesrions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %fortinet · fortiweb14 мар. 2025 г.
- CVE-2023-4278439Наблюдать
An improper handling of syntactically invalid structure in Fortinet FortiWeb at least verions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 a
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %fortinet · fortiweb11 мар. 2025 г.
- GHSA-hrhf-2vcr-ghch32Наблюдать
CometBFT's invalid BitArray handling can lead to network halt
ВысокаяCVSS 8,0Эксплойта нетGo · github.com/cometbft/cometbft14 окт. 2025 г.
- CVE-2026-3423230Наблюдать
Firebird: DoS via `op_response` packet from client
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %firebirdsql · firebird17 апр. 2026 г.
- CVE-2025-2286530Наблюдать
ParsePKCS1PrivateKey panic with partial keys in crypto/x509
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %go standard library · crypto/x50927 янв. 2025 г.
- CVE-2024-2161230Наблюдать
Junos OS Evolved: Specific TCP traffic causes OFP core and restart of RE
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %juniper · junos os evolved11 янв. 2024 г.
- CVE-2025-034330Наблюдать
Swift ASN.1 can be caused to crash when parsing certain BER/DER constructions.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %swift project · swift asn114 янв. 2025 г.
- CVE-2026-2012530Наблюдать
A vulnerability in the HTTP Server feature of Cisco IOS Software and Cisco IOS XE Software Release 3E could allow an authenticated, remote a
ВысокаяCVSS 7,7Эксплойта нетEPSS 0 %cisco · ios25 мар. 2026 г.
- CVE-2024-638230Наблюдать
Adversarial unsanitized input may cause MongoDB Rust Driver to issue unintended commands.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %mongodb · rust driver2 июл. 2024 г.
- CVE-2026-4210028Наблюдать
DoS in Sparx Pro Cloud Server
ВысокаяCVSS 7,1Эксплойта нетEPSS 1 %sparxsystems · pro cloud server19 мая 2026 г.
- CVE-2026-2565728Наблюдать
Ericsson Packet Core Gateway (PCG) - Improper Handling of Syntactically Invalid Structure Vulnerability
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %ericsson · packet core gateway5 июн. 2026 г.
- CVE-2026-5010328Наблюдать
Improper Handling of Syntactically Invalid Structure in MZ Automation libIEC61850
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %mz automation · libiec6185023 июл. 2026 г.
- CVE-2025-5917428Наблюдать
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large volume of specially c
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %ericsson · packet core controller5 июн. 2026 г.
- CVE-2024-2280926Наблюдать
Incorrect access control in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to access the G code's shared folder and
СредняяCVSS 6,5Эксплойта нетEPSS 0 %tormach · pathpilot controller22 апр. 2024 г.
- CVE-2021-3619921Наблюдать
Running a vulnerability scanner against VideoEdge NVRs can cause some functionality to stop.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %johnsoncontrols · videoedge14 янв. 2022 г.
- CVE-2024-5382821Наблюдать
Ericsson Packet Core Controller (PCC) - Improper Handling of Syntactically Invalid Structure Vulnerability
СредняяCVSS 5,3Эксплойта нетEPSS 0 %ericsson · packet core controller1 апр. 2026 г.
- CVE-2024-2281521Наблюдать
An issue in the communication protocol of Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cause a Denial of Servi
СредняяCVSS 5,3Эксплойта нетEPSS 0 %tormach · pathpilot controller22 апр. 2024 г.
- CVE-2025-252914Наблюдать
IBM Terracotta denial of service
НизкаяCVSS 3,7Эксплойта нетEPSS 0 %ibm · terracotta15 окт. 2025 г.
- CVE-2025-4773611Наблюдать
dialect/mod.rs in the libsql-sqlite3-parser crate through 0.13.0 before 14f422a for Rust can crash if the input is not valid UTF-8.
НизкаяCVSS 2,9Эксплойта нетEPSS 0 %gwenn · libsql-sqlite3-parser9 мая 2025 г.