CWE-228 · 24 kayıt
Improper Handling of Syntactically Invalid Structure
Bu sınıftaki CVE’ler
24 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2021-38443İstismar yok | Eclipse CycloneDDS Improper Handling of Syntactically Invalid Structureeclipse · cyclonedds · CWE-228 | Kritik9,8 | — | %2,1 | 5 May 2022 |
40Planlayın | CVE-2020-27847İstismar yok | A vulnerability exists in the SAML connector of the github.com/dexidp/dex library used to process SAML Signature Validation.linuxfoundation · dex · CWE-228 | Kritik9,8 | — | %1,7 | 28 May 2021 |
40Planlayın | CVE-2026-87986İstismar yok | An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using shell constructs it'smistralai · mistral-vibe · CWE-228 | Kritik10,0 | — | %0,6 | 11 Eyl 2026 |
39İzleyin | CVE-2018-5381İstismar yok | The Quagga BGP daemon (bgpd) prior to version 1.2.3 has a bug in its parsing of "Capabilities" in BGP OPEN messages, in the bgp_packet.c:bgpquagga · quagga · CWE-228 | Yüksek7,5 | — | %30,2 | 19 Şub 2018 |
39İzleyin | CVE-2024-55594İstismar yok | An improper handling of syntactically invalid structure in Fortinet FortiWeb at least vesrions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 fortinet · fortiweb · CWE-228 | Kritik9,8 | — | %0,5 | 14 Mar 2025 |
39İzleyin | CVE-2023-42784İstismar yok | An improper handling of syntactically invalid structure in Fortinet FortiWeb at least verions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 afortinet · fortiweb · CWE-228 | Kritik9,8 | — | %0,4 | 11 Mar 2025 |
32İzleyin | GHSA-hrhf-2vcr-ghchİstismar yok | CometBFT's invalid BitArray handling can lead to network haltGo · github.com/cometbft/cometbft · CWE-228 | Yüksek8,0 | — | — | 14 Eki 2025 |
30İzleyin | CVE-2026-34232İstismar yok | Firebird: DoS via `op_response` packet from clientfirebirdsql · firebird · CWE-228 | Yüksek7,5 | — | %0,7 | 17 Nis 2026 |
30İzleyin | CVE-2025-22865İstismar yok | ParsePKCS1PrivateKey panic with partial keys in crypto/x509go standard library · crypto/x509 · CWE-228 | Yüksek7,5 | — | %0,6 | 27 Oca 2025 |
30İzleyin | CVE-2024-21612İstismar yok | Junos OS Evolved: Specific TCP traffic causes OFP core and restart of REjuniper · junos os evolved · CWE-228 | Yüksek7,5 | — | %0,5 | 11 Oca 2024 |
30İzleyin | CVE-2025-0343İstismar yok | Swift ASN.1 can be caused to crash when parsing certain BER/DER constructions.swift project · swift asn1 · CWE-228 | Yüksek7,5 | — | %0,3 | 14 Oca 2025 |
30İzleyin | CVE-2026-20125İstismar yok | A vulnerability in the HTTP Server feature of Cisco IOS Software and Cisco IOS XE Software Release 3E could allow an authenticated, remote acisco · ios · CWE-228 | Yüksek7,7 | — | %0,3 | 25 Mar 2026 |
30İzleyin | CVE-2024-6382İstismar yok | Adversarial unsanitized input may cause MongoDB Rust Driver to issue unintended commands.mongodb · rust driver · CWE-228 | Yüksek7,5 | — | %0,3 | 2 Tem 2024 |
28İzleyin | CVE-2026-42100İstismar yok | DoS in Sparx Pro Cloud Serversparxsystems · pro cloud server · CWE-228 | Yüksek7,1 | — | %0,6 | 19 May 2026 |
28İzleyin | CVE-2026-25657İstismar yok | Ericsson Packet Core Gateway (PCG) - Improper Handling of Syntactically Invalid Structure Vulnerabilityericsson · packet core gateway · CWE-228 | Yüksek7,1 | — | %0,3 | 5 Haz 2026 |
28İzleyin | CVE-2026-50103İstismar yok | Improper Handling of Syntactically Invalid Structure in MZ Automation libIEC61850mz automation · libiec61850 · CWE-228 | Yüksek7,1 | — | %0,3 | 23 Tem 2026 |
28İzleyin | CVE-2025-59174İstismar yok | Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large volume of specially cericsson · packet core controller · CWE-228 | Yüksek7,1 | — | %0,2 | 5 Haz 2026 |
26İzleyin | CVE-2024-22809İstismar yok | Incorrect access control in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to access the G code's shared folder andtormach · pathpilot controller · CWE-228 | Orta6,5 | — | %0,3 | 22 Nis 2024 |
23İzleyin | CVE-2026-107299İstismar yok | msgpack5: Reserved byte can cause unbounded stream bufferingmcollina · msgpack5 · CWE-228 | Orta5,9 | — | — | 1 gün önce |
21İzleyin | CVE-2021-36199İstismar yok | Running a vulnerability scanner against VideoEdge NVRs can cause some functionality to stop.johnsoncontrols · videoedge · CWE-228 | Orta5,3 | — | %1,0 | 14 Oca 2022 |
21İzleyin | CVE-2024-53828İstismar yok | Ericsson Packet Core Controller (PCC) - Improper Handling of Syntactically Invalid Structure Vulnerabilityericsson · packet core controller · CWE-228 | Orta5,3 | — | %0,4 | 1 Nis 2026 |
21İzleyin | CVE-2024-22815İstismar yok | An issue in the communication protocol of Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cause a Denial of Servitormach · pathpilot controller · CWE-228 | Orta5,3 | — | %0,2 | 22 Nis 2024 |
14İzleyin | CVE-2025-2529İstismar yok | IBM Terracotta denial of serviceibm · terracotta · CWE-228 | Düşük3,7 | — | %0,2 | 15 Eki 2025 |
11İzleyin | CVE-2025-47736İstismar yok | dialect/mod.rs in the libsql-sqlite3-parser crate through 0.13.0 before 14f422a for Rust can crash if the input is not valid UTF-8.gwenn · libsql-sqlite3-parser · CWE-228 | Düşük2,9 | — | %0,3 | 9 May 2025 |
- CVE-2021-3844340Planlayın
Eclipse CycloneDDS Improper Handling of Syntactically Invalid Structure
KritikCVSS 9,8İstismar yokEPSS %2eclipse · cyclonedds5 May 2022
- CVE-2020-2784740Planlayın
A vulnerability exists in the SAML connector of the github.com/dexidp/dex library used to process SAML Signature Validation.
KritikCVSS 9,8İstismar yokEPSS %2linuxfoundation · dex28 May 2021
- CVE-2026-8798640Planlayın
An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using shell constructs it's
KritikCVSS 10,0İstismar yokEPSS %1mistralai · mistral-vibe11 Eyl 2026
- CVE-2018-538139İzleyin
The Quagga BGP daemon (bgpd) prior to version 1.2.3 has a bug in its parsing of "Capabilities" in BGP OPEN messages, in the bgp_packet.c:bgp
YüksekCVSS 7,5İstismar yokEPSS %30quagga · quagga19 Şub 2018
- CVE-2024-5559439İzleyin
An improper handling of syntactically invalid structure in Fortinet FortiWeb at least vesrions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10
KritikCVSS 9,8İstismar yokEPSS %1fortinet · fortiweb14 Mar 2025
- CVE-2023-4278439İzleyin
An improper handling of syntactically invalid structure in Fortinet FortiWeb at least verions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 a
KritikCVSS 9,8İstismar yokEPSS %0fortinet · fortiweb11 Mar 2025
- GHSA-hrhf-2vcr-ghch32İzleyin
CometBFT's invalid BitArray handling can lead to network halt
YüksekCVSS 8,0İstismar yokGo · github.com/cometbft/cometbft14 Eki 2025
- CVE-2026-3423230İzleyin
Firebird: DoS via `op_response` packet from client
YüksekCVSS 7,5İstismar yokEPSS %1firebirdsql · firebird17 Nis 2026
- CVE-2025-2286530İzleyin
ParsePKCS1PrivateKey panic with partial keys in crypto/x509
YüksekCVSS 7,5İstismar yokEPSS %1go standard library · crypto/x50927 Oca 2025
- CVE-2024-2161230İzleyin
Junos OS Evolved: Specific TCP traffic causes OFP core and restart of RE
YüksekCVSS 7,5İstismar yokEPSS %1juniper · junos os evolved11 Oca 2024
- CVE-2025-034330İzleyin
Swift ASN.1 can be caused to crash when parsing certain BER/DER constructions.
YüksekCVSS 7,5İstismar yokEPSS %0swift project · swift asn114 Oca 2025
- CVE-2026-2012530İzleyin
A vulnerability in the HTTP Server feature of Cisco IOS Software and Cisco IOS XE Software Release 3E could allow an authenticated, remote a
YüksekCVSS 7,7İstismar yokEPSS %0cisco · ios25 Mar 2026
- CVE-2024-638230İzleyin
Adversarial unsanitized input may cause MongoDB Rust Driver to issue unintended commands.
YüksekCVSS 7,5İstismar yokEPSS %0mongodb · rust driver2 Tem 2024
- CVE-2026-4210028İzleyin
DoS in Sparx Pro Cloud Server
YüksekCVSS 7,1İstismar yokEPSS %1sparxsystems · pro cloud server19 May 2026
- CVE-2026-2565728İzleyin
Ericsson Packet Core Gateway (PCG) - Improper Handling of Syntactically Invalid Structure Vulnerability
YüksekCVSS 7,1İstismar yokEPSS %0ericsson · packet core gateway5 Haz 2026
- CVE-2026-5010328İzleyin
Improper Handling of Syntactically Invalid Structure in MZ Automation libIEC61850
YüksekCVSS 7,1İstismar yokEPSS %0mz automation · libiec6185023 Tem 2026
- CVE-2025-5917428İzleyin
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large volume of specially c
YüksekCVSS 7,1İstismar yokEPSS %0ericsson · packet core controller5 Haz 2026
- CVE-2024-2280926İzleyin
Incorrect access control in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to access the G code's shared folder and
OrtaCVSS 6,5İstismar yokEPSS %0tormach · pathpilot controller22 Nis 2024
- CVE-2026-10729923İzleyin
msgpack5: Reserved byte can cause unbounded stream buffering
OrtaCVSS 5,9İstismar yokmcollina · msgpack51 gün önce
- CVE-2021-3619921İzleyin
Running a vulnerability scanner against VideoEdge NVRs can cause some functionality to stop.
OrtaCVSS 5,3İstismar yokEPSS %1johnsoncontrols · videoedge14 Oca 2022
- CVE-2024-5382821İzleyin
Ericsson Packet Core Controller (PCC) - Improper Handling of Syntactically Invalid Structure Vulnerability
OrtaCVSS 5,3İstismar yokEPSS %0ericsson · packet core controller1 Nis 2026
- CVE-2024-2281521İzleyin
An issue in the communication protocol of Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cause a Denial of Servi
OrtaCVSS 5,3İstismar yokEPSS %0tormach · pathpilot controller22 Nis 2024
- CVE-2025-252914İzleyin
IBM Terracotta denial of service
DüşükCVSS 3,7İstismar yokEPSS %0ibm · terracotta15 Eki 2025
- CVE-2025-4773611İzleyin
dialect/mod.rs in the libsql-sqlite3-parser crate through 0.13.0 before 14f422a for Rust can crash if the input is not valid UTF-8.
DüşükCVSS 2,9İstismar yokEPSS %0gwenn · libsql-sqlite3-parser9 May 2025