← Back
CWE-116

434 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Encoding or Escaping of Output

The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

JSON object

Loading...

CVEs (434)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Fedoraproject
Google
2Chrome
Fedora
Nov 21, 2024
Aug 3, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient validation of untrusted input in Sharing in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to bypass navigation restrictions via a crafted click-to-call link.
1Tekmonks
1Monkshu
Nov 21, 2024
Aug 2, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Monkshu is an enterprise application server for mobile apps (iOS and Android), responsive HTML 5 apps, and JSON API services. In version 2.90 and earlier, there is a reflected cross-site scripting vulnerability in fronte...Show more
Monkshu is an enterprise application server for mobile apps (iOS and Android), responsive HTML 5 apps, and JSON API services. In version 2.90 and earlier, there is a reflected cross-site scripting vulnerability in frontend HTTP server. The attacker can send in a carefully crafted URL along with a known bug in the server which will cause a 500 error, and the response will then embed the URL provided by the hacker. The impact is moderate as the hacker must also be able to craft an HTTP request which should cause a 500 server error. None such requests are known as this point. The issue is patched in version 2.95. As a workaround, one may use a disk caching plugin.Show less
1Gtranslate
1Gtranslate
Nov 21, 2024
Jul 30, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In the Pro and Enterprise versions of GTranslate < 2.8.65, the gtranslate_request_uri_var function runs at the top of all pages and echoes out the contents of $_SERVER['REQUEST_URI']. Although this uses addslashes, and m...Show more
In the Pro and Enterprise versions of GTranslate < 2.8.65, the gtranslate_request_uri_var function runs at the top of all pages and echoes out the contents of $_SERVER['REQUEST_URI']. Although this uses addslashes, and most modern browsers automatically URLencode requests, this plugin is still vulnerable to Reflected XSS in older browsers such as Internet Explorer 9 or below, or in cases where an attacker is able to modify the request en route between the client and the server, or in cases where the user is using an atypical browsing solution.Show less
1Xmldom Project
1Xmldom
Nov 21, 2024
Jul 27, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
xmldom is an open source pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. xmldom versions 0.6.0 and older do not correctly escape special characters when serializing elements...Show more
xmldom is an open source pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. xmldom versions 0.6.0 and older do not correctly escape special characters when serializing elements removed from their ancestor. This may lead to unexpected syntactic changes during XML processing in some downstream applications. This issue has been resolved in version 0.7.0. As a workaround downstream applications can validate the input and reject the maliciously crafted documents.Show less
1Mongodb
1Mongodb
Nov 21, 2024
Jul 23, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log entries to be split. This issue affects MongoDB Server v3.6 versions prior to 3.6.20; MongoDB Server...Show more
Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log entries to be split. This issue affects MongoDB Server v3.6 versions prior to 3.6.20; MongoDB Server v4.0 versions prior to 4.0.21 and MongoDB Server v4.2 versions prior to 4.2.10.Show less
3Apache
DebianOracle
7Communications Cloud Native Core Policy
Communications Diameter Signaling RouterCommunications Pricing Design Center+4 more
Nov 21, 2024
Jul 12, 2021
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache...Show more
A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.Show less
2Fedoraproject
Nextcloud
2Fedora
Nextcloud Server
Nov 21, 2024
Jul 12, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.0.11, and 21.0.3, filenames where not escaped by default in controllers using `DownloadResponse`. When a user-supplied f...Show more
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.0.11, and 21.0.3, filenames where not escaped by default in controllers using `DownloadResponse`. When a user-supplied filename was passed unsanitized into a `DownloadResponse`, this could be used to trick users into downloading malicious files with a benign file extension. This would show in UI behaviours where Nextcloud applications would display a benign file extension (e.g. JPEG), but the file will actually be downloaded with an executable file extension. The vulnerability is patched in versions 19.0.13, 20.0.11, and 21.0.3. Administrators of Nextcloud instances do not have a workaround available, but developers of Nextcloud apps may manually escape the file name before passing it into `DownloadResponse`.Show less
1Gallagher
1Command Centre
Nov 21, 2024
Jun 11, 2021
N/A· v4
8.1 HIGH· v3
8.5 HIGH· v2
Improper Encoding or Escaping in Gallagher Command Centre Server allows a Command Centre Operator to alter the configuration of Controllers and other hardware items beyond their privilege. This issue affects: Gallagher C...Show more
Improper Encoding or Escaping in Gallagher Command Centre Server allows a Command Centre Operator to alter the configuration of Controllers and other hardware items beyond their privilege. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.40.1888 (MR3); 8.30 versions prior to 8.30.1359 (MR3); 8.20 versions prior to 8.20.1259 (MR5); version 8.10 and prior versions.Show less
1Redhat
1Keycloak
Nov 21, 2024
May 28, 2021
N/A· v4
9.6 CRITICAL· v3
6.8 MEDIUM· v2
A flaw was found in keycloak in versions before 13.0.0. A Self Stored XSS attack vector escalating to a complete account takeover is possible due to user-supplied data fields not being properly encoded and Javascript cod...Show more
A flaw was found in keycloak in versions before 13.0.0. A Self Stored XSS attack vector escalating to a complete account takeover is possible due to user-supplied data fields not being properly encoded and Javascript code being used to process the data. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.Show less
4Debian
FedoraprojectNetapp+1 more
4Cloud Manager
Debian LinuxFedora+1 more
Nov 21, 2024
May 27, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a memory-management bug, it is vulnerable to a Denial of Service attack (against all clients using the proxy) via HTTP Range request processing.
3Debian
FedoraprojectSquid Cache
3Debian Linux
FedoraSquid
Nov 21, 2024
May 27, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Squid 4.x before 4.15 and 5.x before 5.0.6. If a remote server sends a certain response header over HTTP or HTTPS, there is a denial of service. This header can plausibly occur in benign networ...Show more
An issue was discovered in Squid 4.x before 4.15 and 5.x before 5.0.6. If a remote server sends a certain response header over HTTP or HTTPS, there is a denial of service. This header can plausibly occur in benign network traffic.Show less
1Ibm
1Gpfs.tct.server
Nov 21, 2024
May 20, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Spectrum Scale 1.1.1.0 through 1.1.8.4 Transparent Cloud Tiering could allow a remote attacker to obtain sensitive information, caused by the leftover files after configuration. IBM X-Force ID: 190298.
1Magpierss Project
1Magpierss
Nov 21, 2024
Apr 2, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Because of a incorrect escaped exec command in MagpieRSS in 0.72 in the /extlib/Snoopy.class.inc file, it is possible to add a extra command to the curl binary. This creates an issue on the /scripts/magpie_debug.php and...Show more
Because of a incorrect escaped exec command in MagpieRSS in 0.72 in the /extlib/Snoopy.class.inc file, it is possible to add a extra command to the curl binary. This creates an issue on the /scripts/magpie_debug.php and /scripts/magpie_simple.php page that if you send a specific https url in the RSS URL field, you are able to execute arbitrary commands.Show less
1Protocol
1Go Ipfs
Nov 21, 2024
Mar 24, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
go-ipfs is an open-source golang implementation of IPFS which is a global, versioned, peer-to-peer filesystem. In go-ipfs before version 0.8.0, control characters are not escaped from console output. This can result in h...Show more
go-ipfs is an open-source golang implementation of IPFS which is a global, versioned, peer-to-peer filesystem. In go-ipfs before version 0.8.0, control characters are not escaped from console output. This can result in hiding input from the user which could result in the user taking an unknown, malicious action. This is fixed in version 0.8.0.Show less
1Secomea
4Gatemanager 4250 Firmware
Gatemanager 4260 FirmwareGatemanager 8250 Firmware+1 more
Nov 21, 2024
Feb 16, 2021
N/A· v4
3.5 LOW· v3
4.9 MEDIUM· v2
Improper Encoding or Escaping of Output from CSV Report Generator of Secomea GateManager allows an authenticated administrator to generate a CSV file that may run arbitrary commands on a victim's computer when opened in...Show more
Improper Encoding or Escaping of Output from CSV Report Generator of Secomea GateManager allows an authenticated administrator to generate a CSV file that may run arbitrary commands on a victim's computer when opened in a spreadsheet program (like Excel). This issue affects: Secomea GateManager all versions prior to 9.3.Show less
1Ibm
1Security Verify Information Queue
Nov 21, 2024
Feb 11, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user to perform unauthorized activities due to improper encoding of output. IBM X-Force ID: 196183.
1Ninjaforms
1Ninja Forms
Nov 21, 2024
Jan 6, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The Ninja Forms plugin before 3.4.28 for WordPress lacks escaping for submissions-table fields.
1Xwiki
1Xwiki
Nov 21, 2024
Dec 31, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
XWiki Platform before 12.8 mishandles escaping in the property displayer.
1Bigbluebutton
1Bigbluebutton
Nov 21, 2024
Nov 19, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
web/controllers/ApiController.groovy in BigBlueButton before 2.2.29 lacks certain parameter sanitization, as demonstrated by accepting control characters in a user name.
1Semantic Release Project
1Semantic Release
Nov 21, 2024
Nov 18, 2020
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
In the npm package semantic-release before version 17.2.3, secrets that would normally be masked by `semantic-release` can be accidentally disclosed if they contain characters that become encoded when included in a URL....Show more
In the npm package semantic-release before version 17.2.3, secrets that would normally be masked by `semantic-release` can be accidentally disclosed if they contain characters that become encoded when included in a URL. Secrets that do not contain characters that become encoded when included in a URL are already masked properly. The issue is fixed in version 17.2.3.Show less