CWE-178
85 CVEs • Abstraction: Base
Improper Handling of Case Sensitivity
The product does not properly account for differences in case sensitivity when accessing or determining the properties of a resource, leading to inconsistent results.
CVEs (85)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreJun 17, 2026 Apr 13, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Windows DNS Information Disclosure Vulnerability |
In OpenEMR, versions v2.7.2-rc1 to 6.0.0 are vulnerable to Improper Access Control when creating a new user, which leads to a malicious user able to read and send sensitive messages on behalf of the victim user. |
ORY Fosite is a security first OAuth2 & OpenID Connect framework for Go. In Fosite before version 0.34.1, the OAuth 2.0 Client's registered redirect URLs and the redirect URL provided at the OAuth2 Authorization Endpoint...Show more |
An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication...Show more |
SimpleSAMLphp versions before 1.18.6 contain an information disclosure vulnerability. The module controller in `SimpleSAML\Module` that processes requests for pages hosted by modules, has code to identify paths ending wi...Show more |
uploads/include/dialog/select_soft.php in DedeCMS V57_UTF8_SP2 allows remote attackers to execute arbitrary PHP code by uploading with a safe file extension and then renaming with a mixed-case variation of the .php exten...Show more |
1Microsoft 2Windows 10 Windows Server 2016Jun 17, 2026 Sep 13, 2018 N/A· v4 5.3 MEDIUM· v3 4.6 MEDIUM· v2 A security feature bypass vulnerability exists when Windows Subsystem for Linux improperly handles case sensitivity, aka "Windows Subsystem for Linux Security Feature Bypass Vulnerability." This affects Windows 10, Windo...Show more |
Etherpad Lite before 1.6.4 is exploitable for admin access. |
1Microsoft 5Windows 10 Windows 8.1Windows Rt 8.1+2 moreMay 13, 2026 Jun 15, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Microsoft Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to set variables that are either read-only or require authentication when...Show more |
MyServer 0.8.9 and earlier does not properly handle uppercase characters in filename extensions, which allows remote attackers to obtain sensitive information (script source code) via a modified extension, as demonstrate...Show more |
The file extension check in GNUBoard 3.40 and earlier only verifies extensions that contain all lowercase letters, which allows remote attackers to upload arbitrary files via file extensions that include uppercase letter...Show more |
1Mbedthis 1Appweb Http Server Apr 16, 2026 Dec 31, 2004 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to bypass access restrictions via a URI with mixed case characters. |
2Apple Canonical2Cups Ubuntu LinuxApr 16, 2026 Dec 31, 2004 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a printer name containing uppercase or lowercase letters that are different from what...Show more |
1Apple 4Darwin Streaming Server Mac Os XMac Os X Server+1 moreApr 16, 2026 Dec 3, 2004 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache for Apple Mac OS X 10.2.8 and 10.3.6 restricts access to files in a case sensitive manner, but the Apple HFS+ filesystem accesses files in a case insensitive manner, which allows remote attackers to read .DS_Store...Show more |
1Oracle 1Sun One Application Server Apr 16, 2026 Jun 30, 2003 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Sun ONE Application Server 7.0 for Windows 2000/XP allows remote attackers to obtain JSP source code via a request that uses the uppercase ".JSP" extension instead of the lowercase .jsp extension. |
Novell eDirectory 8.6.2 and 8.7 use case insensitive passwords, which makes it easier for remote attackers to conduct brute force password guessing. |
1Ultimate Php Board Project 1Ultimate Php Board Apr 16, 2026 Dec 31, 2002 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 register.php in Ultimate PHP Board (UPB) 1.0 and 1.0b uses an administrative account Admin with a capital "A," but allows a remote attacker to impersonate the administrator by registering an account name of admin with a...Show more |
Norton Anti-Virus (NAV) allows remote attackers to bypass content filtering via attachments whose Content-Type and Content-Disposition headers are mixed upper and lower case, which is ignored by some mail clients. |
Perception LiteServe 1.25 allows remote attackers to obtain source code of CGI scripts via URLs that contain MS-DOS conventions such as (1) upper case letters or (2) 8.3 file names. |
Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characters whose case is not matched by Apache's filters. |