CWE-116
Improper Encoding or Escaping of Output
Description
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-104 · CAPEC-73 · CAPEC-81 · CAPEC-85
CVEs mapped to this weakness (510)
page 7 of 26| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-73417 | Hig | 0.49 | — | 0.01 | Aug 13, 2026 | jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 3.3.0 until 4.5.10 and 4.6.2, JupyterLab allows notebook settings to be shared and applied through an overrides.json file using the Import button… | ||
| CVE-2024-46547 | Hig | 0.49 | 7.5 | 0.00 | Dec 9, 2024 | A vulnerability was found in Romain Bourdon Wampserver all versions (discovered in v3.2.3 and v3.2.6) where unauthorized users could access sensitive information due to improper access control validation via PHP Info Page. This issue can lead to data leaks. | ||
| CVE-2024-4420 | Hig | 0.49 | 7.5 | 0.00 | May 21, 2024 | There exists a Denial of service vulnerability in Tink-cc in versions prior to 2.1.3. * An adversary can crash binaries using the crypto::tink::JsonKeysetReader in tink-cc by providing an input that is not an encoded JSON object, but still a valid encoded JSON element, for… | ||
| CVE-2024-34510 | Hig | 0.49 | 7.5 | 0.01 | May 5, 2024 | Gradio before 4.20 allows credential leakage on Windows. | ||
| CVE-2024-1064 | Hig | 0.49 | 7.5 | 0.01 | Feb 3, 2024 | A host header injection vulnerability in the HTTP handler component of Crafty Controller allows a remote, unauthenticated attacker to trigger a Denial of Service (DoS) condition via a modified host header | ||
| CVE-2023-28738 | Hig | 0.49 | 7.5 | 0.00 | Jan 19, 2024 | Improper input validation for some Intel NUC BIOS firmware before version JY0070 may allow a privileged user to potentially enable escalation of privilege via local access. | ||
| CVE-2023-52102 | Hig | 0.49 | 7.5 | 0.00 | Jan 16, 2024 | Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2023-52098 | Hig | 0.49 | 7.5 | 0.00 | Jan 16, 2024 | Denial of Service (DoS) vulnerability in the DMS module. Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2023-39390 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Vulnerability of input parameter verification in certain APIs in the window management module. Successful exploitation of this vulnerability may cause the device to restart. | ||
| CVE-2023-39386 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause newly installed apps to fail to restart. | ||
| CVE-2023-39382 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Input verification vulnerability in the audio module. Successful exploitation of this vulnerability may cause virtual machines (VMs) to restart. | ||
| CVE-2023-39381 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2023 | Input verification vulnerability in the storage module. Successful exploitation of this vulnerability may cause the device to restart. | ||
| CVE-2022-43713 | Hig | 0.49 | 7.5 | 0.01 | Jul 26, 2023 | Interactive Forms (IAF) in GX Software XperienCentral versions 10.33.1 until 10.35.0 was vulnerable to invalid data input because form validation could be bypassed. | ||
| CVE-2022-30351 | Hig | 0.49 | 7.5 | 0.01 | Mar 30, 2023 | PDFZorro PDFZorro Online r20220428 using TCPDF 6.2.5, despite having workflows claiming to correctly remove redacted information from a supplied PDF file, does not properly sanitize this information in all cases, causing redacted information, including images and text embedded… | ||
| CVE-2022-39958 | Hig | 0.49 | 7.5 | 0.01 | Sep 20, 2022 | The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass to sequentially exfiltrate small and undetectable sections of data by repeatedly submitting an HTTP Range header field with a small byte range. A restricted resource, access to which would ordinarily… | ||
| CVE-2020-4850 | Hig | 0.49 | 7.5 | 0.01 | May 20, 2021 | IBM Spectrum Scale 1.1.1.0 through 1.1.8.4 Transparent Cloud Tiering could allow a remote attacker to obtain sensitive information, caused by the leftover files after configuration. IBM X-Force ID: 190298. | ||
| CVE-2021-20405 | Hig | 0.49 | 7.5 | 0.01 | Feb 11, 2021 | IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user to perform unauthorized activities due to improper encoding of output. IBM X-Force ID: 196183. | ||
| CVE-2019-4326 | Hig | 0.49 | 7.5 | 0.01 | Oct 6, 2020 | "HCL AppScan Enterprise security rules update administration section of the web application console is missing HTTP Strict-Transport-Security Header." | ||
| CVE-2020-5304 | Hig | 0.49 | 7.5 | 0.01 | Jun 8, 2020 | The dashboard in WhiteSource Application Vulnerability Management (AVM) before version 20.4.1 allows Log Injection via a %0A%0D substring in the idp parameter to the /saml/login URI. This closes the current log and creates a new log with one line of data. The attacker can also… | ||
| CVE-2020-6227 | Hig | 0.49 | 7.5 | 0.01 | Apr 14, 2020 | SAP Business Objects Business Intelligence Platform (CMS / Auditing issues), version 4.2, allows attacker to send specially crafted GIOP packets to several services due to Improper Input Validation, allowing to forge additional entries in GLF log files. |
- risk 0.49cvss —epss 0.01
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 3.3.0 until 4.5.10 and 4.6.2, JupyterLab allows notebook settings to be shared and applied through an overrides.json file using the Import button…
- risk 0.49cvss 7.5epss 0.00
A vulnerability was found in Romain Bourdon Wampserver all versions (discovered in v3.2.3 and v3.2.6) where unauthorized users could access sensitive information due to improper access control validation via PHP Info Page. This issue can lead to data leaks.
- risk 0.49cvss 7.5epss 0.00
There exists a Denial of service vulnerability in Tink-cc in versions prior to 2.1.3. * An adversary can crash binaries using the crypto::tink::JsonKeysetReader in tink-cc by providing an input that is not an encoded JSON object, but still a valid encoded JSON element, for…
- risk 0.49cvss 7.5epss 0.01
Gradio before 4.20 allows credential leakage on Windows.
- risk 0.49cvss 7.5epss 0.01
A host header injection vulnerability in the HTTP handler component of Crafty Controller allows a remote, unauthenticated attacker to trigger a Denial of Service (DoS) condition via a modified host header
- risk 0.49cvss 7.5epss 0.00
Improper input validation for some Intel NUC BIOS firmware before version JY0070 may allow a privileged user to potentially enable escalation of privilege via local access.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.49cvss 7.5epss 0.00
Denial of Service (DoS) vulnerability in the DMS module. Successful exploitation of this vulnerability will affect availability.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of input parameter verification in certain APIs in the window management module. Successful exploitation of this vulnerability may cause the device to restart.
- risk 0.49cvss 7.5epss 0.00
Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause newly installed apps to fail to restart.
- risk 0.49cvss 7.5epss 0.00
Input verification vulnerability in the audio module. Successful exploitation of this vulnerability may cause virtual machines (VMs) to restart.
- risk 0.49cvss 7.5epss 0.00
Input verification vulnerability in the storage module. Successful exploitation of this vulnerability may cause the device to restart.
- risk 0.49cvss 7.5epss 0.01
Interactive Forms (IAF) in GX Software XperienCentral versions 10.33.1 until 10.35.0 was vulnerable to invalid data input because form validation could be bypassed.
- risk 0.49cvss 7.5epss 0.01
PDFZorro PDFZorro Online r20220428 using TCPDF 6.2.5, despite having workflows claiming to correctly remove redacted information from a supplied PDF file, does not properly sanitize this information in all cases, causing redacted information, including images and text embedded…
- risk 0.49cvss 7.5epss 0.01
The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass to sequentially exfiltrate small and undetectable sections of data by repeatedly submitting an HTTP Range header field with a small byte range. A restricted resource, access to which would ordinarily…
- risk 0.49cvss 7.5epss 0.01
IBM Spectrum Scale 1.1.1.0 through 1.1.8.4 Transparent Cloud Tiering could allow a remote attacker to obtain sensitive information, caused by the leftover files after configuration. IBM X-Force ID: 190298.
- risk 0.49cvss 7.5epss 0.01
IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user to perform unauthorized activities due to improper encoding of output. IBM X-Force ID: 196183.
- risk 0.49cvss 7.5epss 0.01
"HCL AppScan Enterprise security rules update administration section of the web application console is missing HTTP Strict-Transport-Security Header."
- risk 0.49cvss 7.5epss 0.01
The dashboard in WhiteSource Application Vulnerability Management (AVM) before version 20.4.1 allows Log Injection via a %0A%0D substring in the idp parameter to the /saml/login URI. This closes the current log and creates a new log with one line of data. The attacker can also…
- risk 0.49cvss 7.5epss 0.01
SAP Business Objects Business Intelligence Platform (CMS / Auditing issues), version 4.2, allows attacker to send specially crafted GIOP packets to several services due to Improper Input Validation, allowing to forge additional entries in GLF log files.