CWE-115
17 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-115page 1 of 1
- CVE-2018-12116HIGHCVSS 7.52018-11-28
Node.js: All versions prior to Node.js 6.15.0 and 8.14.0: HTTP request splitting: If Node.js can be convinced to use unsanitized user-provided Unicode data for the `path` option of an HTTP request, then data can be provided which will trig…
- CVE-2018-12123MEDIUMCVSS 4.32018-11-28
Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Hostname spoofing in URL parser for javascript protocol: If a Node.js application is using url.parse() to determine the URL hostname, that hostname can be spoofed b…
- CVE-2018-7159MEDIUMCVSS 5.32018-05-17
The HTTP parser in all current versions of Node.js ignores spaces in the `Content-Length` header, allowing input such as `Content-Length: 1 2` to be interpreted as having a value of `12`. The HTTP specification does not allow for spaces in…
- CVE-2020-27846CRITICALCVSS 9.8EG 9.82020-12-21
A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
- CVE-2020-29509CRITICALCVSS 9.8EG 9.82020-12-14
The encoding/xml package in Go (all versions) does not correctly preserve the semantics of attribute namespace prefixes during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during differ…
- CVE-2020-29510CRITICALCVSS 9.8EG 9.82020-12-14
The encoding/xml package in Go versions 1.15 and earlier does not correctly preserve the semantics of directives during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different sta…
- CVE-2020-29511CRITICALCVSS 9.8EG 5.62020-12-14
The encoding/xml package in Go (all versions) does not correctly preserve the semantics of element namespace prefixes during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during differen…
- CVE-2021-0207HIGHCVSS 7.5EG 7.52021-01-15
An improper interpretation conflict of certain data between certain software components within the Juniper Networks Junos OS devices does not allow certain traffic to pass through the device upon receipt from an ingress interface filtering…
- CVE-2021-1587HIGHCVSS 8.6EG 8.62021-08-25
A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected devi…
- CVE-2021-21366MEDIUMCVSS 4.3EG 4.32021-03-12
xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. xmldom versions 0.4.0 and older do not correctly preserve system identifiers, FPIs or namespaces when repeatedly parsing and serializ…
- CVE-2022-1233MEDIUMCVSS 6.1EG 6.12022-04-04
URL Confusion When Scheme Not Supplied in GitHub repository medialize/uri.js prior to 1.19.11.
- CVE-2022-20915HIGHCVSS 7.4EG 7.42022-10-10
A vulnerability in the implementation of IPv6 VPN over MPLS (6VPE) with Zone-Based Firewall (ZBFW) of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected devic…
- CVE-2022-21672MEDIUMCVSS 6.5EG 6.52022-01-10
make-ca is a utility to deliver and manage a complete PKI configuration for workstations and servers. Starting with version 0.9 and prior to version 1.10, make-ca misinterprets Mozilla certdata.txt and treats explicitly untrusted certifica…
- CVE-2022-3224MEDIUMCVSS 6.1EG 6.12022-09-15
Misinterpretation of Input in GitHub repository ionicabizau/parse-url prior to 8.1.0.
- CVE-2023-0880HIGHCVSS 8.3EG 8.32023-02-17
Misinterpretation of Input in GitHub repository thorsten/phpmyfaq prior to 3.1.11.
- CVE-2023-32228MEDIUMCVSS 4.6EG 4.62024-04-11
A firmware bug which may lead to misinterpretation of data in the AMC2-4WCF and AMC2-2WCF allowing an adversary to grant access to the last authorized user.
- CVE-2023-32260MEDIUMCVSS 6.5EG 6.52024-03-19
Misinterpretation of Input vulnerability in OpenText™ Service Management Automation X (SMAX), OpenText™ Asset Management X (AMX), and OpenText™ Hybrid Cloud Management X (HCMX) products. The vulnerability could allow Input data manip…
Map vulnerabilities like CWE-115 to your infrastructure
EchelonGraph correlates every CVE — across CWE-115 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →