CWE-791
42 CVEs • Abstraction: Base
Incomplete Filtering of Special Elements
The product receives data from an upstream component, but does not completely filter special elements before sending it to a downstream component.
CVEs (42)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian DpdkFedoraproject+1 more8Data Plane Development Kit Debian LinuxEnterprise Linux+5 moreJun 17, 2026 Aug 31, 2022 N/A· v4 8.6 HIGH· v3 N/A· v2 A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK. |
2Fedoraproject Pypa2Fedora PipenvJun 17, 2026 Jan 10, 2022 N/A· v4 8.6 HIGH· v3 9.3 HIGH· v2 pipenv is a Python development workflow tool. Starting with version 2018.10.9 and prior to version 2022.1.8, a flaw in pipenv's parsing of requirements files allows an attacker to insert a specially crafted string inside...Show more |