CWE-170
Improper Null Termination
Description
The product does not terminate or incorrectly terminates a string or array with a null character or equivalent terminator.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (56)
page 2 of 3| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-70587 | Hig | 0.49 | 7.5 | 0.01 | Sep 8, 2026 | Improper null termination in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-67790 | Hig | 0.49 | 7.5 | 0.00 | Dec 17, 2025 | An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. An unprivileged user could cause occasionally a Blue Screen Of Death (BSOD) on Windows computers by using an IOCTL and an unterminated string. | ||
| CVE-2025-62792 | Hig | 0.49 | 7.5 | 0.00 | Oct 29, 2025 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.12.0, a buffer over-read occurs in w_expression_match() when strlen() is called on str_test, because the corresponding buffer is not being properly NULL terminated during its… | ||
| CVE-2025-2026 | Hig | 0.46 | — | 0.00 | Dec 31, 2025 | The NPort 6100-G2/6200-G2 Series is affected by a high-severity vulnerability (CVE-2025-2026) that allows remote attackers to execute a null byte injection through the device’s web API. This may lead to an unexpected device reboot and result in a denial-of-service (DoS)… | ||
| CVE-2021-1120 | Hig | 0.46 | 7.0 | 0.00 | Oct 29, 2021 | NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a string provided by the guest OS may not be properly null terminated. The guest OS or attacker has no ability to push content to the plugin through this vulnerability, which may lead… | ||
| CVE-2026-34462 | Hig | 0.44 | 7.8 | 0.00 | May 5, 2026 | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, several ProcessServer handlers (KillAllHandler, SuspendAllHandler, and RunSandboxedHandler) copy a WCHAR boxname[34] field from request structures into WCHAR[40] stack… | ||
| CVE-2023-48674 | Med | 0.44 | 6.8 | 0.00 | Mar 1, 2024 | Dell Platform BIOS contains an Improper Null Termination vulnerability. A high privilege user with network access to the system could potentially send malicious data to the device in order to cause some services to cease to function. | ||
| CVE-2020-27736 | Med | 0.43 | 6.5 | 0.04 | Apr 22, 2021 | A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20), APOGEE PXC Modular (BACnet) (All versions < V3.5.5), APOGEE PXC Modular (P2 Ethernet) (All versions < V2.8.20), Nucleus NET (All… | ||
| CVE-2026-45798 | Hig | 0.42 | 7.5 | 0.01 | Aug 19, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.5.0 until 4.14.6 and 5.0.0-beta2, compare_wazuh_versions() in src/shared/version_op.c copies the attacker-controlled enrollment V: field into a 10-byte stack buffer with… | ||
| CVE-2023-35321 | Med | 0.42 | 6.5 | 0.02 | Jul 11, 2023 | Windows Deployment Services Denial of Service Vulnerability | ||
| CVE-2026-42010 | Hig | 0.39 | 7.1 | 0.01 | May 7, 2026 | A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to… | ||
| CVE-2026-78506 | Med | 0.36 | 5.5 | 0.01 | Sep 8, 2026 | Improper null termination in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | ||
| CVE-2023-36907 | Med | 0.36 | 5.5 | 0.02 | Aug 8, 2023 | Windows Cryptographic Services Information Disclosure Vulnerability | ||
| CVE-2023-36906 | Med | 0.36 | 5.5 | 0.02 | Aug 8, 2023 | Windows Cryptographic Services Information Disclosure Vulnerability | ||
| CVE-2023-28263 | Med | 0.36 | 5.5 | 0.01 | Apr 11, 2023 | Visual Studio Information Disclosure Vulnerability | ||
| CVE-2020-14323 | Med | 0.36 | 5.5 | 0.01 | Oct 29, 2020 | A null pointer dereference flaw was found in samba's Winbind service in versions before 4.11.15, before 4.12.9 and before 4.13.1. A local user could use this flaw to crash the winbind service causing denial of service. | ||
| CVE-2020-7066 | Med | 0.35 | 5.3 | 0.03 | Apr 1, 2020 | In PHP versions 7.2.x below 7.2.29, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using get_headers() with user-supplied URL, if the URL contains zero (\0) character, the URL will be silently truncated at it. This may cause some software to make incorrect assumptions about the… | ||
| CVE-2024-31197 | Med | 0.34 | 5.3 | 0.00 | Sep 18, 2024 | Improper Null Termination vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of10::Port:unpack. This issue affects libfluid: 0.1.0. | ||
| CVE-2025-66220 | Med | 0.33 | 5.0 | 0.00 | Dec 3, 2025 | Envoy is a high-performance edge/middle/service proxy. In 1.33.12, 1.34.10, 1.35.6, 1.36.2, and earlier, Envoy’s mTLS certificate matcher for match_typed_subject_alt_names may incorrectly treat certificates containing an embedded null byte (\0) inside an OTHERNAME SAN value as… | ||
| CVE-2026-44452 | Med | 0.31 | 5.9 | 0.00 | Jul 16, 2026 | h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 8dc37cb, when h2o receives a ClientHello message over TLS or QUIC and it contains a zero-length SNI extension, the h2o server runs over the zero-length hostname while trying to copy the hostname,… |
- risk 0.49cvss 7.5epss 0.01
Improper null termination in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.
- risk 0.49cvss 7.5epss 0.00
An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. An unprivileged user could cause occasionally a Blue Screen Of Death (BSOD) on Windows computers by using an IOCTL and an unterminated string.
- risk 0.49cvss 7.5epss 0.00
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.12.0, a buffer over-read occurs in w_expression_match() when strlen() is called on str_test, because the corresponding buffer is not being properly NULL terminated during its…
- risk 0.46cvss —epss 0.00
The NPort 6100-G2/6200-G2 Series is affected by a high-severity vulnerability (CVE-2025-2026) that allows remote attackers to execute a null byte injection through the device’s web API. This may lead to an unexpected device reboot and result in a denial-of-service (DoS)…
- risk 0.46cvss 7.0epss 0.00
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a string provided by the guest OS may not be properly null terminated. The guest OS or attacker has no ability to push content to the plugin through this vulnerability, which may lead…
- risk 0.44cvss 7.8epss 0.00
Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, several ProcessServer handlers (KillAllHandler, SuspendAllHandler, and RunSandboxedHandler) copy a WCHAR boxname[34] field from request structures into WCHAR[40] stack…
- risk 0.44cvss 6.8epss 0.00
Dell Platform BIOS contains an Improper Null Termination vulnerability. A high privilege user with network access to the system could potentially send malicious data to the device in order to cause some services to cease to function.
- risk 0.43cvss 6.5epss 0.04
A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20), APOGEE PXC Modular (BACnet) (All versions < V3.5.5), APOGEE PXC Modular (P2 Ethernet) (All versions < V2.8.20), Nucleus NET (All…
- risk 0.42cvss 7.5epss 0.01
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.5.0 until 4.14.6 and 5.0.0-beta2, compare_wazuh_versions() in src/shared/version_op.c copies the attacker-controlled enrollment V: field into a 10-byte stack buffer with…
- risk 0.42cvss 6.5epss 0.02
Windows Deployment Services Denial of Service Vulnerability
- risk 0.39cvss 7.1epss 0.01
A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to…
- risk 0.36cvss 5.5epss 0.01
Improper null termination in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.02
Windows Cryptographic Services Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.02
Windows Cryptographic Services Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Visual Studio Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
A null pointer dereference flaw was found in samba's Winbind service in versions before 4.11.15, before 4.12.9 and before 4.13.1. A local user could use this flaw to crash the winbind service causing denial of service.
- risk 0.35cvss 5.3epss 0.03
In PHP versions 7.2.x below 7.2.29, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using get_headers() with user-supplied URL, if the URL contains zero (\0) character, the URL will be silently truncated at it. This may cause some software to make incorrect assumptions about the…
- risk 0.34cvss 5.3epss 0.00
Improper Null Termination vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of10::Port:unpack. This issue affects libfluid: 0.1.0.
- risk 0.33cvss 5.0epss 0.00
Envoy is a high-performance edge/middle/service proxy. In 1.33.12, 1.34.10, 1.35.6, 1.36.2, and earlier, Envoy’s mTLS certificate matcher for match_typed_subject_alt_names may incorrectly treat certificates containing an embedded null byte (\0) inside an OTHERNAME SAN value as…
- risk 0.31cvss 5.9epss 0.00
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 8dc37cb, when h2o receives a ClientHello message over TLS or QUIC and it contains a zero-length SNI extension, the h2o server runs over the zero-length hostname while trying to copy the hostname,…