CVEbaza.plSłownik CWECWE-115
Common Weakness Enumeration

CWE-115

Misinterpretation of Input

Kategoria: BaseCVE: 31
Opis

Produkt błędnie interpretuje dane wejściowe pochodzące od atakującego lub innego produktu w sposób istotny dla bezpieczeństwa. Może to prowadzić do nieautoryzowanego dostępu, wykonania nieautoryzowanego kodu lub innych zagrożeń bezpieczeństwa.

Description (EN)

The product misinterprets an input, whether from an attacker or another product, in a security-relevant fashion.

Podatności CVE z CWE-115 (31)
9.8
CVSS
CRITICAL
CVE-2020-27846

W bibliotece crewjam/saml odkryto krytyczną podatność umożliwiającą obejście mechanizmu uwierzytelniania SAML. Błąd ten pozwala nieuwierzytelnionemu atakującemu zdalnie uzyskać pełny dostęp do chronionych zasobów.

pub. 2020-12-21
9.8
CVSS
CRITICAL
CVE-2020-29509

Pakiet encoding/xml w języku Go nie zachowuje poprawnie semantyki prefiksów przestrzeni nazw atrybutów podczas tokenizacji XML. Pozwala to atakującemu na przygotowanie danych wejściowych, które zachowują się w sprzeczny sposób na różnych etapach przetwarzania w aplikacjach korzystających z tej biblioteki.

pub. 2020-12-14
9.8
CVSS
CRITICAL
CVE-2020-29510

Pakiet encoding/xml w Go 1.15 i wcześniejszych wersjach niepoprawnie zachowuje semantykę dyrektyw XML podczas tokenizacji w obie strony (round-trip). Może to pozwolić atakującemu na dostarczenie spreparowanych danych wejściowych, które są interpretowane w sprzeczny sposób na różnych etapach przetwarzania w aplikacjach wykorzystujących podatny pakiet.

pub. 2020-12-14
9.8
CVSS
CRITICAL
CVE-2020-29511

Pakiet encoding/xml w języku Go nieprawidłowo zachowuje semantykę prefiksów przestrzeni nazw elementów XML podczas operacji tokenizacji (round-trip). Umożliwia to atakującemu spreparowanie danych wejściowych, które zachowują się sprzecznie na różnych etapach przetwarzania w aplikacjach korzystających z tej biblioteki.

pub. 2020-12-14
9.4
CVSS
CRITICAL
CVE-2026-17351

Podatność w pgAdmin 4 (wersje 9.13–9.16) pozwala na ominięcie zabezpieczenia transakcji READ ONLY w narzędziu AI Assistant poprzez spreparowany payload SQL, który sqlparse interpretuje jako pojedyncze polecenie, a PostgreSQL wykonuje jako wiele instrukcji. Jest to ponowne wprowadzenie podatności CVE-2026-12045, którą poprzednia poprawka miała wyeliminować.

pub. 2026-07-31
9.4
CVSS
CRITICAL
CVE-2026-17566

Podatność w pgAdmin 4 pozwala uwierzytelnionemu użytkownikowi z uprawnieniami do narzędzia Import/Export Data na wykonanie dowolnych poleceń systemowych na serwerze. Wynika z błędnej walidacji zapytania SQL przekazywanego do polecenia psql \copy, co umożliwia wstrzyknięcie klauzuli TO PROGRAM wykonującej kod przez popen().

pub. 2026-07-31
8.6
CVSS
HIGH
CVE-2021-1587

A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of specific packets with a Transparent Interconnection of Lots of Links (TRILL) OAM EtherType. An attacker could exploit this vulnerability by sending crafted packets, including the TRILL OAM EtherType of 0x8902, to a device that is part of a VXLAN Ethernet VPN (EVPN) fabric. A successful exploit could allow the attacker to cause an affected device to experience high CPU usage and consume excessive system resources, which may result in overall control plane instability and cause the affected device to reload. Note: The NGOAM feature is disabled by default.

pub. 2021-08-25
8.3
CVSS
HIGH
CVE-2023-0880

Misinterpretation of Input in GitHub repository thorsten/phpmyfaq prior to 3.1.11.

pub. 2023-02-17
8.0
CVSS
HIGH
CVE-2025-5747

WOLFBOX Level 2 EV Charger MCU Command Parsing Misinterpretation of Input Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installatons of WOLFBOX Level 2 EV Charger devices. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of command frames received by the MCU. When parsing frames, the process does not properly detect the start of a frame, which can lead to misinterpretation of input. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the device. Was ZDI-CAN-26501.

pub. 2025-06-06
7.5
CVSS
HIGH
CVE-2025-32908

A flaw was found in libsoup. The HTTP/2 server in libsoup may not fully validate the values of pseudo-headers :scheme, :authority, and :path, which may allow a user to cause a denial of service (DoS).

pub. 2025-04-14
7.5
CVSS
HIGH
CVE-2024-11169

An unhandled exception in danny-avila/librechat version 3c94ff2 can lead to a server crash. The issue occurs when the fs module throws an exception while handling file uploads. An unauthenticated user can trigger this exception by sending a specially crafted request, causing the server to crash. The vulnerability is fixed in version 0.7.6.

pub. 2025-03-20
7.5
CVSS
HIGH
CVE-2021-0207

An improper interpretation conflict of certain data between certain software components within the Juniper Networks Junos OS devices does not allow certain traffic to pass through the device upon receipt from an ingress interface filtering certain specific types of traffic which is then being redirected to an egress interface on a different VLAN. This causes a Denial of Service (DoS) to those clients sending these particular types of traffic. Such traffic being sent by a client may appear genuine, but is non-standard in nature and should be considered as potentially malicious, and can be targeted to the device, or destined through it for the issue to occur. This issues affects IPv4 and IPv6 traffic. An indicator of compromise may be found by checking log files. You may find that traffic on the input interface has 100% of traffic flowing into the device, yet the egress interface shows 0 pps leaving the device. For example: [show interfaces "interface" statistics detail] Output between two interfaces would reveal something similar to: Ingress, first interface: -------------------- Interface Link Input packets (pps) Output packets (pps) et-0/0/0 Up 9999999999 (9999) 1 (0) -------------------- Egress, second interface: -------------------- Interface Link Input packets (pps) Output packets (pps) et-0/0/1 Up 0 (0) 9999999999 (0) -------------------- Dropped packets will not show up in DDoS monitoring/protection counters as issue is not caused by anti-DDoS protection mechanisms. This issue affects: Juniper Networks Junos OS: 17.3 versions prior to 17.3R3-S7 on NFX250, QFX5K Series, EX4600; 17.4 versions prior to 17.4R2-S11, 17.4R3-S3 on NFX250, QFX5K Series, EX4600; 18.1 versions prior to 18.1R3-S9 on NFX250, QFX5K Series, EX2300 Series, EX3400 Series, EX4600; 18.2 versions prior to 18.2R3-S3 on NFX250, QFX5K Series, EX2300 Series, EX3400 Series, EX4300 Multigigabit, EX4600; 18.3 versions prior to 18.3R3-S1 on NFX250, QFX5K Series, EX2300 Series, EX3400 Series, EX4300 Multigigabit, EX4600 Series; 18.4 versions prior to 18.4R1-S5, 18.4R2-S3, 18.4R3 on NFX250, QFX5K Series, EX2300 Series, EX3400 Series, EX4300 Multigigabit, EX4600 Series; 19.1 versions prior to 19.1R1-S5, 19.1R2-S1, 19.1R3 on NFX250, QFX5K Series, EX2300 Series, EX3400 Series, EX4300 Multigigabit, EX4600 Series; 19.2 versions prior to 19.2R1-S5, 19.2R2 on NFX250, QFX5K Series, EX2300 Series, EX3400 Series, EX4300 Multigigabit, EX4600 Series; 19.3 versions prior to 19.3R2-S3, 19.3R3 on NFX250, QFX5K Series, EX2300 Series, EX3400 Series, EX4300 Multigigabit, EX4600 Series; 19.4 versions prior to 19.4R1-S2, 19.4R2 on NFX250, NFX350, QFX5K Series, EX2300 Series, EX3400 Series, EX4300 Multigigabit, EX4600 Series. This issue does not affect Junos OS releases prior to 17.2R2.

pub. 2021-01-15
7.5
CVSS
HIGH
CVE-2018-12116

Node.js: All versions prior to Node.js 6.15.0 and 8.14.0: HTTP request splitting: If Node.js can be convinced to use unsanitized user-provided Unicode data for the `path` option of an HTTP request, then data can be provided which will trigger a second, unexpected, and user-defined HTTP request to made to the same server.

pub. 2018-11-28
7.4
CVSS
HIGH
CVE-2022-20915

A vulnerability in the implementation of IPv6 VPN over MPLS (6VPE) with Zone-Based Firewall (ZBFW) of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper error handling of an IPv6 packet that is forwarded from an MPLS and ZBFW-enabled interface in a 6VPE deployment. An attacker could exploit this vulnerability by sending a crafted IPv6 packet sourced from a device on the IPv6-enabled virtual routing and forwarding (VRF) interface through the affected device. A successful exploit could allow the attacker to reload the device, resulting in a DoS condition.

pub. 2022-10-10
7.0
CVSS
HIGH
CVE-2025-54584

GitProxy is an application that stands between developers and a Git remote endpoint (e.g., github.com). In versions 1.19.1 and below, an attacker can craft a malicious Git packfile to exploit the PACK signature detection in the parsePush.ts file. By embedding a misleading PACK signature within commit content and carefully constructing the packet structure, the attacker can trick the parser into treating invalid or unintended data as the packfile. Potentially, this would allow bypassing approval or hiding commits. This issue is fixed in version 1.19.2.

pub. 2025-07-30
6.9
CVSS
MEDIUM
CVE-2025-55303

Astro is a web framework for content-driven websites. In versions of astro before 5.13.2 and 4.16.18, the image optimization endpoint in projects deployed with on-demand rendering allows images from unauthorized third-party domains to be served. On-demand rendered sites built with Astro include an /_image endpoint which returns optimized versions of images. A bug in impacted versions of astro allows an attacker to bypass the third-party domain restrictions by using a protocol-relative URL as the image source, e.g. /_image?href=//example.com/image.png. This vulnerability is fixed in 5.13.2 and 4.16.18.

pub. 2025-08-19
6.5
CVSS
MEDIUM
CVE-2025-68113

ALTCHA to oprogramowanie zapewniające prywatność, dedykowane do ochrony przed captchą i botami. Wada wiązania semantycznego w bibliotekach ALTCHA umożliwia splice'owanie payloadu wyzwania, co może prowadzić do ataków replay. Podpis HMAC nie jednoznacznie wiąże parametrów wyzwania z nonce'em, pozwalając atakującemu przeinterpretować prawidłowy submit proof-of-work ze zmodyfikowaną wartością wygaśnięcia. Może to pozwolić na ponowne użycie wcześniej rozwiązanych wyzwań poza ich zamierzoną żywotnością, w zależności od obsługi replay po stronie serwera i założeń wdrożenia. Luka wpływa głównie na mechanizmy zapobiegania nadużyciom, takie jak rate limiting i mitygacja botów. Nie wpływa bezpośrednio na poufność lub integralność danych. Problem został rozwiązany poprzez wymuszenie jawnego rozdzielenia semantycznego między parametrami wyzwania a nonce'em podczas obliczeń HMAC.

pub. 2025-12-16
6.5
CVSS
MEDIUM
CVE-2025-25069

A Cross-Protocol Scripting vulnerability is found in Apache Kvrocks. Since Kvrocks didn't detect if "Host:" or "POST" appears in RESP requests, a valid HTTP request can also be sent to Kvrocks as a valid RESP request and trigger some database operations, which can be dangerous when it is chained with SSRF. It is similiar to CVE-2016-10517 in Redis. This issue affects Apache Kvrocks: from the initial version to the latest version 2.11.0. Users are recommended to upgrade to version 2.11.1, which fixes the issue.

pub. 2025-02-07
6.5
CVSS
MEDIUM
CVE-2023-32260

Misinterpretation of Input vulnerability in OpenText™ Service Management Automation X (SMAX), OpenText™ Asset Management X (AMX), and OpenText™ Hybrid Cloud Management X (HCMX) products. The vulnerability could allow Input data manipulation.This issue affects Service Management Automation X (SMAX) versions: 2020.05, 2020.08, 2020.11, 2021.02, 2021.05, 2021.08, 2021.11, 2022.05, 2022.11, 2023.05; Asset Management X (AMX) versions: 2021.08, 2021.11, 2022.05, 2022.11, 2023.05; and Hybrid Cloud Management X (HCMX) versions: 2020.05, 2020.08, 2020.11, 2021.02, 2021.05, 2021.08, 2021.11, 2022.05, 2022.11, 2023.05.

pub. 2024-03-19
6.5
CVSS
MEDIUM
CVE-2022-21672

make-ca is a utility to deliver and manage a complete PKI configuration for workstations and servers. Starting with version 0.9 and prior to version 1.10, make-ca misinterprets Mozilla certdata.txt and treats explicitly untrusted certificates like trusted ones, causing those explicitly untrusted certificates trusted by the system. The explicitly untrusted certificates were used by some CAs already hacked. Hostile attackers may perform a MIM attack exploiting them. Everyone using the affected versions of make-ca should upgrade to make-ca-1.10, and run `make-ca -f -g` as the `root` user to regenerate the trusted store immediately. As a workaround, users may delete the untrusted certificates from /etc/pki/tls and /etc/ssl/certs manually (or by a script), but this is not recommended because the manual changes will be overwritten next time running make-ca to update the trusted anchor.

pub. 2022-01-10
Pokazano 20 z 31 podatności
Informacje
ID: CWE-115
Typ: Base
Podatności: 31
MITRE CWE ↗
← Słownik CWE