CWE-166
Improper Handling of Missing Special Element
Description
The product receives input from an upstream component, but it does not handle or incorrectly handles when an expected special element is missing.
Hierarchy (View 1000)
CVEs mapped to this weakness (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-34582 | Cri | 0.52 | 9.1 | 0.00 | Apr 7, 2026 | Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to be processed prior to the Finished message being received. A server which is attempting to enforce client authentication via certificates can by bypassed… | ||
| CVE-2024-38091 | Hig | 0.49 | 7.5 | 0.02 | Jul 9, 2024 | Microsoft WS-Discovery Denial of Service Vulnerability | ||
| CVE-2026-21218 | Hig | 0.42 | 7.5 | 0.01 | Feb 10, 2026 | Improper handling of missing special element in .NET allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-32792 | Med | 0.27 | 5.3 | 0.00 | May 20, 2026 | NLnet Labs Unbound 1.6.2 up to and including version 1.25.0 has a denial of service vulnerability when compiled with DNSCrypt support ('--enable-dnscrypt'). A bad DNSCrypt query could underflow Unbound's DNSCrypt packet reading procedure that may lead to heap overflow. A… |
- risk 0.52cvss 9.1epss 0.00
Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to be processed prior to the Finished message being received. A server which is attempting to enforce client authentication via certificates can by bypassed…
- risk 0.49cvss 7.5epss 0.02
Microsoft WS-Discovery Denial of Service Vulnerability
- risk 0.42cvss 7.5epss 0.01
Improper handling of missing special element in .NET allows an unauthorized attacker to perform spoofing over a network.
- risk 0.27cvss 5.3epss 0.00
NLnet Labs Unbound 1.6.2 up to and including version 1.25.0 has a denial of service vulnerability when compiled with DNSCrypt support ('--enable-dnscrypt'). A bad DNSCrypt query could underflow Unbound's DNSCrypt packet reading procedure that may lead to heap overflow. A…