İçeriğe atla
Noroxi

CWE-158 · 27 kayıt

Improper Neutralization of Null Byte or NUL Character

Bu sınıftaki CVE’ler

27 kayıt

  • In Wing FTP Server before 7.4.4.

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %93

    wftpserver · wing ftp server10 Tem 2025

  • Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %51

    microsoft · directx29 May 2009

  • CVE-2020-14500
    39İzleyin

    IMPROPER NEUTRALIZATION OF NULL BYTE OR NUL CHARACTER CWE-158

    KritikCVSS 9,8İstismar yokEPSS %2

    secomea · gatemanager 8250 firmware25 Ağu 2020

  • CVE-2023-5719
    39İzleyin

    Red Lion Crimson Improper Neutralization of Null Byte or NUL Character

    KritikCVSS 9,8İstismar yokEPSS %1

    redlion · crimson6 Kas 2023

  • CVE-2025-14388
    39İzleyin

    PhastPress <= 3.7 - Unauthenticated Arbitrary File Read via Null Byte Injection

    KritikCVSS 9,8İstismar yokEPSS %0

    kiboit · phastpress23 Ara 2025

  • CVE-2025-55113
    38İzleyin

    BMC Control-M/Agent unescaped NULL byte in access control list checks

    KritikCVSS 9,5İstismar yokEPSS %0

    bmc · control-m\/agent16 Eyl 2025

  • CVE-2025-66263
    35İzleyin

    Unauthenticated Arbitrary File Read via Null Byte Injection

    YüksekCVSS 8,9İstismar yokEPSS %0

    dbbroadcast · mozart next 3000 firmware25 Kas 2025

  • CVE-2025-9648
    34İzleyin

    Denial of Service in CivetWeb

    YüksekCVSS 8,7İstismar yokEPSS %1

    civetweb · civetweb29 Eyl 2025

  • CVE-2026-33191
    34İzleyin

    free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error

    YüksekCVSS 8,7İstismar yokEPSS %1

    free5gc · udm20 Mar 2026

  • CVE-2024-10921
    32İzleyin

    Improper neutralization of null bytes may lead to buffer over-reads in MongoDB Server

    YüksekCVSS 8,1İstismar yokEPSS %1

    mongodb · mongodb14 Kas 2024

  • CVE-2026-76354
    32İzleyin

    Path Traversal through Search Head Clustering in Splunk Enterprise

    YüksekCVSS 8,1İstismar yokEPSS %0

    splunk · splunk19 Ağu 2026

  • CVE-2022-41716
    30İzleyin

    Unsanitized NUL in environment variables on Windows in syscall and os/exec

    YüksekCVSS 7,5İstismar yokEPSS %1

    golang · go2 Kas 2022

  • CVE-2025-1936
    29İzleyin

    Adding %00 and a fake extension to a jar: URL changed the interpretation of the contents

    YüksekCVSS 7,3İstismar yokEPSS %0

    mozilla · firefox4 Mar 2025

  • CVE-2022-20812
    27İzleyin

    Cisco Expressway Series and Cisco TelePresence Video Communication Server Vulnerabilities

    OrtaCVSS 6,5İstismar yokEPSS %2

    cisco · expressway6 Tem 2022

  • CVE-2020-7928
    26İzleyin

    Improper neutralization of null byte leads to read overrun

    OrtaCVSS 6,5İstismar yokEPSS %1

    mongodb · mongodb23 Kas 2020

  • CVE-2026-23863
    26İzleyin

    An attachment spoofing issue in WhatsApp for Windows prior to v2.3000.1032164386.258709 could have allowed maliciously formatted documents w

    OrtaCVSS 6,5İstismar yokEPSS %1

    whatsapp · whatsapp1 May 2026

  • CVE-2020-5363
    26İzleyin

    Select Dell Client Consumer and Commercial platforms include an issue that allows the BIOS Admin password to be changed through Dell's manag

    OrtaCVSS 6,7İstismar yokEPSS %0

    dell · latitude 5300 firmware10 Haz 2020

  • CVE-2022-20813
    23İzleyin

    Cisco Expressway Series and Cisco TelePresence Video Communication Server Vulnerabilities

    OrtaCVSS 5,9İstismar yokEPSS %1

    cisco · expressway6 Tem 2022

  • CVE-2024-0408
    22İzleyin

    Xorg-x11-server: selinux unlabeled glx pbuffer

    OrtaCVSS 5,5İstismar yokEPSS %0

    x.org · x server18 Oca 2024

  • CVE-2026-41256
    22İzleyin

    jq: Embedded NUL truncates top-level jq programs loaded with -f

    OrtaCVSS 5,5İstismar yokEPSS %0

    jqlang · jq11 May 2026

  • CVE-2026-47778
    17İzleyin

    Envoy: Embedded NUL in TLS DNS SAN Truncation in the Default TLS Certificate Validator. (Auth Bypass)

    OrtaCVSS 4,4İstismar yokEPSS %0

    envoyproxy · envoy26 Haz 2026

  • CVE-2026-43859
    14İzleyin

    mutt before 2.3.2 sometimes uses strfcpy instead of memcpy for the IMAP auth_cram MD5 digest.

    DüşükCVSS 3,7İstismar yokEPSS %0

    mutt · mutt4 May 2026

  • CVE-2026-43861
    14İzleyin

    mutt before 2.3.2 does not check for '\0' in url_pct_decode.

    DüşükCVSS 3,7İstismar yokEPSS %0

    mutt · mutt4 May 2026

  • CVE-2025-61985
    14İzleyin

    ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used.

    DüşükCVSS 3,6İstismar yokEPSS %0

    openbsd · openssh6 Eki 2025

  • CVE-2026-28540
    13İzleyin

    Out-of-bounds character read vulnerability in Bluetooth.

    DüşükCVSS 3,3İstismar yokEPSS %0

    huawei · harmonyos5 Mar 2026

Tüm zafiyet sınıfları