CWE-158
29 CVEs • Abstraction: Variant
Improper Neutralization of Null Byte or NUL Character
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes NUL characters or null bytes when they are sent to a downstream component.
CVEs (29)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Fedoraproject RedhatTigervnc+1 more12Enterprise Linux Enterprise Linux DesktopEnterprise Linux For Ibm Z Systems+9 moreJun 17, 2026 Jan 18, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in the X.Org server. The GLX PBuffer code does not call the XACE hook when creating the buffer, leaving it unlabeled. When the client issues another request to access that resource (as with a GetGeometry...Show more |
The Crimson 3.2 Windows-based configuration tool allows users with administrative access to define new passwords for users and to download the resulting security configuration to a device. If such a password contains th...Show more |
1Dell 25Chengming 3900 Firmware Inspiron 14 Plus 7420 FirmwareInspiron 16 Plus 7620 Firmware+22 moreJun 17, 2026 Sep 12, 2022 N/A· v4 2.3 LOW· v3 N/A· v2 Dell BIOS versions contain an Improper Neutralization of Null Byte vulnerability. A local authenticated administrator user could potentially exploit this vulnerability by sending unexpected null bytes in order to read me...Show more |
1Cisco 2Expressway Telepresence Video Communication ServerJun 17, 2026 Jul 6, 2022 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a remote attacker to overwrite arbitrary files...Show more |
1Cisco 2Expressway Telepresence Video Communication ServerJun 17, 2026 Jul 6, 2022 N/A· v4 6.5 MEDIUM· v3 8.5 HIGH· v2 Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a remote attacker to overwrite arbitrary files...Show more |
A user authorized to perform database queries may trigger a read overrun and access arbitrary memory by issuing specially crafted queries. This issue affects MongoDB Server v4.4 versions prior to 4.4.1; MongoDB Server v4...Show more |
1Secomea 1Gatemanager 8250 Firmware Jun 17, 2026 Aug 25, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Secomea GateManager all versions prior to 9.2c, An attacker can send a negative value and overwrite arbitrary data. |
1Dell 18Latitude 5300 2 In 1 Firmware Latitude 5300 FirmwareLatitude 5400 Firmware+15 moreJun 17, 2026 Jun 10, 2020 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 Select Dell Client Consumer and Commercial platforms include an issue that allows the BIOS Admin password to be changed through Dell's manageability interface without knowledge of the current BIOS Admin password. This co...Show more |
1Microsoft 5Directx Windows 2000Windows 2003 Server+2 moreMay 21, 2026 May 29, 2009 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 allows remote atta...Show more |