CWE-170— Improper Null Termination
The product does not terminate or incorrectly terminates a string or array with a null character or equivalent terminator.— MITRE CWE catalog
57 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-170page 1 of 2
- CVE-2021-1418CRITICALCVSS 9.9EG 9.92021-03-24
Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access s…
- CVE-2021-1417CRITICALCVSS 9.9EG 9.92021-03-24
Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access s…
- CVE-2021-1411CRITICALCVSS 9.9EG 9.92021-03-24
Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access s…
- CVE-2021-1471CRITICALCVSS 9.9EG 9.92021-03-24
Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access s…
- CVE-2021-1469CRITICALCVSS 9.9EG 9.92021-03-24
Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access s…
- CVE-2026-5067CRITICALCVSS 9.8EG 9.82026-06-09
A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server WebSocket upgrade path by sending a crafted Sec-WebSocket-Key header. The HTTP/1 header parser copies the header into a fixed-size buffer using a boun…
- CVE-2026-8721CRITICALCVSS 9.8EG 9.82026-05-17
Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl truncates passwords with embedded NULLs. Password parameters in PKCS12.xs are declared char *, which routes through Perl's default typemap to SvPV_nolen. The Perl length is discarded.…
- CVE-2026-42010CRITICALCVSS 9.8EG 9.82026-05-07
A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a …
- CVE-2021-31886CRITICALCVSS 9.8EG 9.82021-11-09
A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BA…
- CVE-2021-31884CRITICALCVSS 9.8EG 9.82021-11-09
A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BA…
- CVE-2021-22931CRITICALCVSS 9.8EG 9.82021-08-16
Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can lead to output of w…
- CVE-2019-8275CRITICALCVSS 9.8EG 9.82019-03-08
UltraVNC revision 1211 has multiple improper null termination vulnerabilities in VNC server code, which result in out-of-bound data being accessed by remote users. This attack appears to be exploitable via network connectivity. These vulne…
- CVE-2023-24021CRITICALCVSS 7.5EG 9.82023-01-20
Incorrect handling of '\0' bytes in file uploads in ModSecurity before 2.9.7 may allow for Web Application Firewall bypasses and buffer over-reads on the Web Application Firewall when executing rules that read the FILES_TMP_CONTENT collect…
- CVE-2026-55738HIGHCVSS 8.8EG 8.82026-06-17
A stack-based buffer overflow exists in the raw_to_header function in src/microtar.c in rxi microtar 0.1.0. The function copies the 100-byte name and linkname fields of a TAR header with strcpy without guaranteeing null termination of the …
- CVE-2026-34464HIGHCVSS 8.8EG 8.82026-05-05
Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, NamedPipeServer::OpenHandler copies the server field from NAMED_PIPE_OPEN_REQ into a fixed WCHAR pipename[160] stack buffer usin…
- CVE-2021-31888HIGHCVSS 8.8EG 8.82021-11-09
A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BA…
- CVE-2021-31887HIGHCVSS 8.8EG 8.82021-11-09
A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BA…
- CVE-2024-45288HIGHCVSS 8.4EG 8.42024-09-05
A missing null-termination character in the last element of an nvlist array string can lead to writing outside the allocated buffer.
- CVE-2026-24852HIGHCVSS 8.1EG 8.12026-01-28
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, a heap buffer over-read when the strlen() function attempts to read a no…
- CVE-2026-34462HIGHCVSS 7.8EG 7.82026-05-05
Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, several ProcessServer handlers (KillAllHandler, SuspendAllHandler, and RunSandboxedHandler) copy a WCHAR boxname[34] field from …
- CVE-2024-31484HIGHCVSS 7.8EG 7.82024-05-14
A vulnerability has been identified in CPC80 Central Processing/Communication (All versions < V16.41), CPCI85 Central Processing/Communication (All versions < V5.30), CPCX26 Central Processing/Communication (All versions < V06.02), ETA4 Et…
- CVE-2024-21442HIGHCVSS 7.8EG 7.82024-03-12
Windows USB Print Driver Elevation of Privilege Vulnerability
- CVE-2024-43474HIGHCVSS 7.5EG 7.62024-09-10
Microsoft SQL Server Information Disclosure Vulnerability
- CVE-2026-70587HIGHCVSS 7.5EG 7.52026-09-08
Improper null termination in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.
- CVE-2026-45798HIGHCVSS 7.5EG 7.52026-08-19
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.5.0 until 4.14.6 and 5.0.0-beta2, compare_wazuh_versions() in src/shared/version_op.c copies the attacker-controlled enrollment V: field i…
- CVE-2025-67790HIGHCVSS 7.5EG 7.52025-12-17
An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. An unprivileged user could cause occasionally a Blue Screen Of Death (BSOD) on Windows computers by using an IOCTL and an unterminated str…
- CVE-2025-62792HIGHCVSS 7.5EG 7.52025-10-29
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.12.0, a buffer over-read occurs in w_expression_match() when strlen() is called on str_test, because the corresponding buffer is not b…
- CVE-2023-36907HIGHCVSS 7.5EG 7.52023-08-08
Windows Cryptographic Services Information Disclosure Vulnerability
- CVE-2023-36906HIGHCVSS 7.5EG 7.52023-08-08
Windows Cryptographic Services Information Disclosure Vulnerability
- CVE-2022-47515HIGHCVSS 7.5EG 7.52022-12-18
An issue was discovered in drachtio-server before 0.8.20. It allows remote attackers to cause a denial of service (daemon crash) via a long message in a TCP request that leads to std::length_error.
- CVE-2019-11044HIGHCVSS 7.5EG 7.52019-12-23
In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 on Windows, PHP link() function accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in appl…
- CVE-2026-27692HIGHCVSS 7.1EG 7.12026-02-25
iccDEV provides a set of libraries and tools for working with ICC color management profiles. In versions up to and including 2.3.1.4, heap-buffer-overflow read occurs during CIccTagTextDescription::Release() when strlen() reads past a heap…
- CVE-2025-67733HIGHCVSS 7.1EG 7.12026-02-23
Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use scripting commands to inject arbitrary information into the response stream for the given client, potentially corruptin…
- CVE-2026-21488HIGHCVSS 7.1EG 7.12026-01-06
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below are vulnerable to Out-of-bounds Read, Heap-based Buffer Overflow and Improper Null Termination through its CIccTagText:…
- CVE-2025-2026HIGHCVSS 7.1EG 7.12025-12-31
The NPort 6100-G2/6200-G2 Series is affected by a high-severity vulnerability (CVE-2025-2026) that allows remote attackers to execute a null byte injection through the device’s web API. This may lead to an unexpected device reboot and re…
- CVE-2025-66220HIGHCVSS 7.1EG 7.12025-12-03
Envoy is a high-performance edge/middle/service proxy. In 1.33.12, 1.34.10, 1.35.6, 1.36.2, and earlier, Envoy’s mTLS certificate matcher for match_typed_subject_alt_names may incorrectly treat certificates containing an embedded null by…
- CVE-2021-1120HIGHCVSS 7.0EG 7.02021-10-29
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a string provided by the guest OS may not be properly null terminated. The guest OS or attacker has no ability to push content to the plugin thro…
- CVE-2023-48674MEDIUMCVSS 6.8EG 6.82024-03-01
Dell Platform BIOS contains an Improper Null Termination vulnerability. A high privilege user with network access to the system could potentially send malicious data to the device in order to cause some services to cease to function.
- CVE-2026-2239MEDIUMCVSS 6.5EG 6.52026-03-26
A flaw was found in GIMP. Heap-buffer-overflow vulnerability exists in the fread_pascal_string function when processing a specially crafted PSD (Photoshop Document) file. This occurs because the buffer allocated for a Pascal string is not …
- CVE-2023-35321MEDIUMCVSS 6.5EG 6.52023-07-11
Windows Deployment Services Denial of Service Vulnerability
- CVE-2020-27736MEDIUMCVSS 6.5EG 6.52021-04-22
A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20), APOGEE PXC Modular (BACnet) (All versions < V3.5.5), APOGEE PXC Modular (P2 Ethernet) (A…
- CVE-2026-73324MEDIUMCVSS 4.3EG 6.52026-09-09
Certain VLC media player builds in versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing media from an attacker-controlled network source. Exploitation requires user interaction and may disclose a li…
- CVE-2026-81882MEDIUMCVSS 6.1EG 6.12026-09-22
radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's binary property-list Unicode parser was vulnerable because the binary-property-list Unicode parser underallocated an uninitialized UTF…
- CVE-2026-44452MEDIUMCVSS 5.9EG 5.92026-07-16
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 8dc37cb, when h2o receives a ClientHello message over TLS or QUIC and it contains a zero-length SNI extension, the h2o server runs over the zero-length hos…
- CVE-2019-11045MEDIUMCVSS 5.9EG 5.92019-12-23
In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applica…
- CVE-2026-78506MEDIUMCVSS 5.5EG 5.52026-09-08
Improper null termination in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- CVE-2026-32837MEDIUMCVSS 5.5EG 5.52026-03-17
miniaudio version 0.11.25 and earlier (fixed in commits 1df46ae and 1df46ae) contain a heap out-of-bounds read vulnerability in the WAV BEXT metadata parser that allows attackers to trigger memory access violations by processing crafted WA…
- CVE-2023-28263MEDIUMCVSS 5.5EG 5.52023-04-11
Visual Studio Information Disclosure Vulnerability
- CVE-2020-14323MEDIUMCVSS 5.5EG 5.52020-10-29
A null pointer dereference flaw was found in samba's Winbind service in versions before 4.11.15, before 4.12.9 and before 4.13.1. A local user could use this flaw to crash the winbind service causing denial of service.
- CVE-2026-34032MEDIUMCVSS 5.3EG 5.32026-05-04
Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
Map vulnerabilities like CWE-170 to your infrastructure
EchelonGraph correlates every CVE — across CWE-170 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →