CWE-237
Improper Handling of Structural Elements
Description
The product does not handle or incorrectly handles inputs that are related to complex structures.
Hierarchy (View 1000)
CVEs mapped to this weakness (5)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-45411 | Cri | 0.57 | 9.8 | 0.01 | May 13, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.3, it is possible to catch a host exception using the yield* expression inside an async generator. When the generator is closed using the return function, the value is awaited on and exceptions thrown in the then call… | ||
| CVE-2023-34429 | Hig | 0.49 | 7.5 | 0.01 | Jul 19, 2023 | Weintek Weincloud v0.13.6 could allow an attacker to cause a denial-of-service condition for Weincloud by sending a forged JWT token. | ||
| CVE-2019-1000007 | Hig | 0.41 | 7.4 | 0.01 | Feb 4, 2019 | aioxmpp version 0.10.2 and earlier contains a Improper Handling of Structural Elements vulnerability in Stanza Parser, rollback during error processing, aioxmpp.xso.model.guard function that can result in Denial of Service, Other. This attack appears to be exploitable via… | ||
| CVE-2023-6110 | Med | 0.29 | 5.5 | 0.00 | Nov 17, 2024 | A flaw was found in OpenStack. When a user tries to delete a non-existing access rule in it's scope, it deletes other existing access rules which are not associated with any application credentials. | ||
| CVE-2025-24336 | Low | 0.21 | 3.3 | 0.00 | Jan 31, 2025 | SXF Common Library handles input data improperly. If a product using the library reads a crafted file, the product may be crashed. |
- risk 0.57cvss 9.8epss 0.01
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.3, it is possible to catch a host exception using the yield* expression inside an async generator. When the generator is closed using the return function, the value is awaited on and exceptions thrown in the then call…
- risk 0.49cvss 7.5epss 0.01
Weintek Weincloud v0.13.6 could allow an attacker to cause a denial-of-service condition for Weincloud by sending a forged JWT token.
- risk 0.41cvss 7.4epss 0.01
aioxmpp version 0.10.2 and earlier contains a Improper Handling of Structural Elements vulnerability in Stanza Parser, rollback during error processing, aioxmpp.xso.model.guard function that can result in Denial of Service, Other. This attack appears to be exploitable via…
- risk 0.29cvss 5.5epss 0.00
A flaw was found in OpenStack. When a user tries to delete a non-existing access rule in it's scope, it deletes other existing access rules which are not associated with any application credentials.
- risk 0.21cvss 3.3epss 0.00
SXF Common Library handles input data improperly. If a product using the library reads a crafted file, the product may be crashed.