İçeriğe atla
Noroxi

CWE-172 · 19 kayıt

Encoding Error

Bu sınıftaki CVE’ler

19 kayıt

  • CVE-2019-10160
    41Planlayın

    A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7

    KritikCVSS 9,8İstismar yokEPSS %5

    python · python7 Haz 2019

  • CVE-2016-6691
    39İzleyin

    service/jni/com_android_server_wifi_Gbk2Utf.cpp in the Qualcomm Wi-Fi gbk2utf module in Android before 2016-10-05 allows remote attackers to

    KritikCVSS 9,8İstismar yokEPSS %1

    google · android10 Eki 2016

  • CVE-2025-27110
    31İzleyin

    Libmodsecurity3 has possible bypass of encoded HTML entities

    YüksekCVSS 7,9İstismar yokEPSS %0

    trustwave · modsecurity25 Şub 2025

  • CVE-2019-12677
    26İzleyin

    Cisco Adaptive Security Appliance Software SSL VPN Denial of Service Vulnerability

    OrtaCVSS 6,5İstismar yokEPSS %2

    cisco · adaptive security appliance software2 Eki 2019

  • CVE-2026-42926
    25İzleyin

    NGINX ngx_http_proxy_v2_module vulnerability

    OrtaCVSS 6,3Kavram kanıtıEPSS %0

    f5 · nginx gateway fabric13 May 2026

  • CVE-2018-7173
    22İzleyin

    A large loop in JBIG2Stream::readSymbolDictSeg in xpdf 4.00 allows an attacker to cause denial of service via a specific file due to inappro

    OrtaCVSS 5,5İstismar yokEPSS %1

    xpdfreader · xpdf15 Şub 2018

  • CVE-2016-3829
    22İzleyin

    The ih264d decoder in mediaserver in Android 6.x before 2016-08-01 does not initialize certain structure members, which allows remote attack

    OrtaCVSS 5,5İstismar yokEPSS %1

    google · android5 Ağu 2016

  • CVE-2016-3828
    22İzleyin

    decoder/ih264d_api.c in mediaserver in Android 6.x before 2016-08-01 mishandles invalid PPS and SPS NAL units, which allows remote attackers

    OrtaCVSS 5,5İstismar yokEPSS %1

    google · android5 Ağu 2016

  • CVE-2016-3827
    22İzleyin

    codecs/hevcdec/SoftHEVC.cpp in libstagefright in mediaserver in Android 6.0.1 before 2016-08-01 mishandles decoder errors, which allows remo

    OrtaCVSS 5,5İstismar yokEPSS %1

    google · android5 Ağu 2016

  • CVE-2026-100891
    22İzleyin

    Trusted Domain Project OpenDMARC Internationalized Domain Name opendmarc_policy.c opendmarc_policy_query_dmarc encoding error

    OrtaCVSS 5,5İstismar yokEPSS %0

    trusted domain project · opendmarc2 gün önce

  • CVE-2019-10153
    21İzleyin

    A flaw was discovered in fence-agents, prior to version 4.3.4, where using non-ASCII characters in a guest VM's comment or other fields woul

    OrtaCVSS 5,0İstismar yokEPSS %2

    clusterlabs · fence-agents30 Tem 2019

  • CVE-2026-48784
    20İzleyin

    Symfony: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or `./` → Generated URL Collapses Off-Route Under RFC 3986 Normalization

    OrtaCVSS 5,1İstismar yokEPSS %0

    sensiolabs · symfony14 Tem 2026

  • CVE-2026-86818
    19İzleyin

    fast-uri vulnerable to mailto header injection via percent-encoded field-name desynchronization

    OrtaCVSS 4,8İstismar yokEPSS %0

    fast-uri · fast-uri15 Eyl 2026

  • CVE-2018-2415
    18İzleyin

    SAP NetWeaver Application Server Java Web Container and HTTP Service (Engine API, from 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; J2EE Engine Ser

    OrtaCVSS 4,7İstismar yokEPSS %1

    sap · netweaver java web container and http service engine9 May 2018

  • CVE-2018-7289
    14İzleyin

    An issue was discovered in armadito-windows-driver/src/communication.c in Armadito 0.12.7.2.

    DüşükCVSS 3,3Kavram kanıtıEPSS %2

    teclib-edition · armadito antivirus21 Şub 2018

  • CVE-2021-33604
    10İzleyin

    Reflected cross-site scripting in development mode handler in Vaadin 14, 15-19

    DüşükCVSS 2,5İstismar yokEPSS %0

    vaadin · flow-server24 Haz 2021

  • Reflected cross-site scripting in development mode handler in Vaadin

    DüşükCVSS 2,5İstismar yok

    Maven · com.vaadin:flow-server28 Haz 2021

  • The kstring integration in gix-attributes is unsound

    DüşükCVSS 2,5İstismar yok

    crates.io · gix-attributes25 Tem 2024

  • SpiceDB calls to LookupResources using LookupResources2 with caveats may return context is missing when it is not

    DüşükCVSS 2,4İstismar yokEPSS %0

    authzed · spicedb14 Eki 2024

Tüm zafiyet sınıfları