CWE-159 · 11 kayıt
Improper Handling of Invalid Use of Special Elements
Bu sınıftaki CVE’ler
11 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2019-9505İstismar yok | PrinterLogic Print Management Software does not sanitize special charactersprinterlogic · print management · CWE-159 | Kritik9,8 | — | %3,5 | 8 May 2019 |
30İzleyin | CVE-2020-1653İstismar yok | Junos OS: Kernel crash (vmcore) or FPC crash due to mbuf leakjuniper · junos · CWE-159 | Yüksek7,5 | — | %1,6 | 17 Tem 2020 |
30İzleyin | CVE-2020-1648İstismar yok | Junos OS and Junos OS Evolved: RPD crash when processing a specific BGP packetjuniper · junos · CWE-159 | Yüksek7,5 | — | %1,3 | 17 Tem 2020 |
30İzleyin | CVE-2020-1646İstismar yok | Junos OS and Junos OS Evolved: RPD crash while processing a specific BGP update information.juniper · junos · CWE-159 | Yüksek7,5 | — | %1,0 | 17 Tem 2020 |
29İzleyin | CVE-2021-21707Kavram kanıtı | Special characters break path parsing in XML functionsphp · php · CWE-159 | Orta5,3 | — | %26,0 | 29 Kas 2021 |
22İzleyin | CVE-2026-2636Kavram kanıtı | Denial of Service in Microsoft OSmicrosoft · windows os · CWE-159 | Orta5,5 | — | %0,4 | 25 Şub 2026 |
22İzleyin | CVE-2021-42375İstismar yok | An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due tbusybox · busybox · CWE-159 | Orta5,5 | — | %0,4 | 15 Kas 2021 |
21İzleyin | CVE-2020-29022İstismar yok | Host Header Injection allowing web cache poisoning attackssecomea · gatemanager 4250 firmware · CWE-159 | Orta5,3 | — | %0,8 | 16 Şub 2021 |
21İzleyin | CVE-2026-35536İstismar yok | In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cooktornadoweb · tornado · CWE-159 | Orta5,3 | — | %0,3 | 3 Nis 2026 |
14İzleyin | CVE-2025-61984Kavram kanıtı | ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leadinopenbsd · openssh · CWE-159 | Düşük3,6 | — | %0,3 | 6 Eki 2025 |
6İzleyin | CVE-2025-52884İstismar yok | risc0-ethereum-contracts allows invalid commitment with digest value of zero to be accepted by Steel.validateCommitmentrisc0 · risc0-ethereum · CWE-159 | Düşük1,7 | — | %0,4 | 24 Haz 2025 |
- CVE-2019-950540Planlayın
PrinterLogic Print Management Software does not sanitize special characters
KritikCVSS 9,8İstismar yokEPSS %3printerlogic · print management8 May 2019
- CVE-2020-165330İzleyin
Junos OS: Kernel crash (vmcore) or FPC crash due to mbuf leak
YüksekCVSS 7,5İstismar yokEPSS %2juniper · junos17 Tem 2020
- CVE-2020-164830İzleyin
Junos OS and Junos OS Evolved: RPD crash when processing a specific BGP packet
YüksekCVSS 7,5İstismar yokEPSS %1juniper · junos17 Tem 2020
- CVE-2020-164630İzleyin
Junos OS and Junos OS Evolved: RPD crash while processing a specific BGP update information.
YüksekCVSS 7,5İstismar yokEPSS %1juniper · junos17 Tem 2020
- CVE-2021-2170729İzleyin
Special characters break path parsing in XML functions
OrtaCVSS 5,3Kavram kanıtıEPSS %26php · php29 Kas 2021
- CVE-2026-263622İzleyin
Denial of Service in Microsoft OS
OrtaCVSS 5,5Kavram kanıtıEPSS %0microsoft · windows os25 Şub 2026
- CVE-2021-4237522İzleyin
An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due t
OrtaCVSS 5,5İstismar yokEPSS %0busybox · busybox15 Kas 2021
- CVE-2020-2902221İzleyin
Host Header Injection allowing web cache poisoning attacks
OrtaCVSS 5,3İstismar yokEPSS %1secomea · gatemanager 4250 firmware16 Şub 2021
- CVE-2026-3553621İzleyin
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cook
OrtaCVSS 5,3İstismar yokEPSS %0tornadoweb · tornado3 Nis 2026
- CVE-2025-6198414İzleyin
ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leadin
DüşükCVSS 3,6Kavram kanıtıEPSS %0openbsd · openssh6 Eki 2025
- CVE-2025-528846İzleyin
risc0-ethereum-contracts allows invalid commitment with digest value of zero to be accepted by Steel.validateCommitment
DüşükCVSS 1,7İstismar yokEPSS %0risc0 · risc0-ethereum24 Haz 2025