CWE-116
434 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Encoding or Escaping of Output
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
CVEs (434)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Google2Chrome FedoraNov 21, 2024 Aug 3, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient validation of untrusted input in Sharing in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to bypass navigation restrictions via a crafted click-to-call link. |
Monkshu is an enterprise application server for mobile apps (iOS and Android), responsive HTML 5 apps, and JSON API services. In version 2.90 and earlier, there is a reflected cross-site scripting vulnerability in fronte...Show more |
In the Pro and Enterprise versions of GTranslate < 2.8.65, the gtranslate_request_uri_var function runs at the top of all pages and echoes out the contents of $_SERVER['REQUEST_URI']. Although this uses addslashes, and m...Show more |
xmldom is an open source pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. xmldom versions 0.6.0 and older do not correctly escape special characters when serializing elements...Show more |
Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log entries to be split. This issue affects MongoDB Server v3.6 versions prior to 3.6.20; MongoDB Server...Show more |
3Apache DebianOracle7Communications Cloud Native Core Policy Communications Diameter Signaling RouterCommunications Pricing Design Center+4 moreNov 21, 2024 Jul 12, 2021 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache...Show more |
2Fedoraproject Nextcloud2Fedora Nextcloud ServerNov 21, 2024 Jul 12, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.0.11, and 21.0.3, filenames where not escaped by default in controllers using `DownloadResponse`. When a user-supplied f...Show more |
Improper Encoding or Escaping in Gallagher Command Centre Server allows a Command Centre Operator to alter the configuration of Controllers and other hardware items beyond their privilege. This issue affects: Gallagher C...Show more |
A flaw was found in keycloak in versions before 13.0.0. A Self Stored XSS attack vector escalating to a complete account takeover is possible due to user-supplied data fields not being properly encoded and Javascript cod...Show more |
4Debian FedoraprojectNetapp+1 more4Cloud Manager Debian LinuxFedora+1 moreNov 21, 2024 May 27, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a memory-management bug, it is vulnerable to a Denial of Service attack (against all clients using the proxy) via HTTP Range request processing. |
3Debian FedoraprojectSquid Cache3Debian Linux FedoraSquidNov 21, 2024 May 27, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Squid 4.x before 4.15 and 5.x before 5.0.6. If a remote server sends a certain response header over HTTP or HTTPS, there is a denial of service. This header can plausibly occur in benign networ...Show more |
IBM Spectrum Scale 1.1.1.0 through 1.1.8.4 Transparent Cloud Tiering could allow a remote attacker to obtain sensitive information, caused by the leftover files after configuration. IBM X-Force ID: 190298. |
1Magpierss Project 1Magpierss Nov 21, 2024 Apr 2, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Because of a incorrect escaped exec command in MagpieRSS in 0.72 in the /extlib/Snoopy.class.inc file, it is possible to add a extra command to the curl binary. This creates an issue on the /scripts/magpie_debug.php and...Show more |
go-ipfs is an open-source golang implementation of IPFS which is a global, versioned, peer-to-peer filesystem. In go-ipfs before version 0.8.0, control characters are not escaped from console output. This can result in h...Show more |
1Secomea 4Gatemanager 4250 Firmware Gatemanager 4260 FirmwareGatemanager 8250 Firmware+1 moreNov 21, 2024 Feb 16, 2021 N/A· v4 3.5 LOW· v3 4.9 MEDIUM· v2 Improper Encoding or Escaping of Output from CSV Report Generator of Secomea GateManager allows an authenticated administrator to generate a CSV file that may run arbitrary commands on a victim's computer when opened in...Show more |
1Ibm 1Security Verify Information Queue Nov 21, 2024 Feb 11, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user to perform unauthorized activities due to improper encoding of output. IBM X-Force ID: 196183. |
The Ninja Forms plugin before 3.4.28 for WordPress lacks escaping for submissions-table fields. |
XWiki Platform before 12.8 mishandles escaping in the property displayer. |
1Bigbluebutton 1Bigbluebutton Nov 21, 2024 Nov 19, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 web/controllers/ApiController.groovy in BigBlueButton before 2.2.29 lacks certain parameter sanitization, as demonstrated by accepting control characters in a user name. |
1Semantic Release Project 1Semantic Release Nov 21, 2024 Nov 18, 2020 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 In the npm package semantic-release before version 17.2.3, secrets that would normally be masked by `semantic-release` can be accidentally disclosed if they contain characters that become encoded when included in a URL....Show more |