CWE-116

High likelihood

Improper Encoding or Escaping of Output

Parent: CWE-707 - Improper Neutralization

The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

482 vulnerabilities with CWE-116
CVE-2023-23599 MEDIUM
Firefox < 109, Firefox ESR < 102.7, Thunderbird < 102.7 - Command I...
CVSS 6.5
CVE-2023-32712 HIGH
Splunk Enterprise <9.1.0.2, <9.0.5.1, <8.2.11.2 - Code Injection
CVSS 8.6
CVE-2023-1711 MEDIUM
HitachiEnergy FOXMAN-UN and UNEM - Information Disclosure in Logging Component
CVSS 4.0
CVE-2023-31669 MEDIUM
WebAssembly wat2wasm <1.0.32 - Code Injection
CVSS 5.5
CVE-2023-32071 CRITICAL
XWiki Platform <2.2-14.4.8, <14.10.4, <15.0-rc-1 - XSS
CVSS 9.0
CVE-2023-30844 LOW
Mutagen <0.16.6-0.17.1 - Info Disclosure
CVSS 3.0
CVE-2023-28733 HIGH
AnyMailing Joomla Plugin <8.3.0 - XSS
CVSS 7.2
CVE-2023-28101 MEDIUM
Flatpak <1.10.8, <1.12.8, <1.14.4, <1.15.4 - Privilege Escalation
CVSS 5.0
CVE-2023-28487 MEDIUM
sudo < 1.9.13 - Improper Output Escaping in sudoreplay
CVSS 5.3
CVE-2023-28486 MEDIUM
sudo < 1.9.13 - Log Injection via Unescaped Control Characters
CVSS 5.3
CVE-2023-26472 CRITICAL
XWiki 6.2.1-13.10.9 - Unauthenticated Remote Code Execution via Icon Theme Sheet Injection
CVSS 9.9
CVE-2023-0595 MEDIUM
EcoStruxure Geo SCADA Expert <October 2022 - Info Disclosure
CVSS 5.3
CVE-2022-22399 MEDIUM
IBM Aspera Faspex <5.0.1 - HTTP Header Injection
CVSS 5.4
CVE-2022-36392 HIGH
Intel(R) AMT & Intel(R) Standard Manageability <11.8.94-16.1.27 - DoS
CVSS 8.6
CVE-2022-43713 HIGH
GX Software XperienCentral <10.35.0 - Info Disclosure
CVSS 7.5
CVE-2022-31458 MEDIUM
RTX TRAP v1.0 - Host Header Injection
CVSS 6.1
CVE-2022-30351 HIGH
PDFZorro Online r20220428 - Info Disclosure
CVSS 7.5
CVE-2022-46387 CRITICAL
Cmder < 1.3.2 and ConEmu < 22.08.07 - Command Injection via Terminal Title Control Characters
CVSS 9.8
CVE-2022-42948 CRITICAL KEV
Cobalt Strike 4.7.1 - Remote Code Execution via HTML Injection in Swing UI
CVSS 9.8
CVE-2022-48339 HIGH
GNU Emacs < 28.2 - OS Command Injection in htmlfontify.el
CVSS 7.8
CVE-2022-45102 MEDIUM
Dell EMC Data Protection Central <19.7 - Host Header Injection
CVSS 5.4
CVE-2022-45143 HIGH
Apache Tomcat <10.1.1 - Info Disclosure
CVSS 7.5
CVE-2022-28284 HIGH
Firefox < 99.0 - Cross-Site Scripting via SVG Use Element
CVSS 8.8
CVE-2022-22744 HIGH
Firefox < 96.0 and Firefox ESR < 91.5 - Command Injection via DevTools Copy as curl
CVSS 8.8
CVE-2022-43543 MEDIUM
docomo/softbank/kddi +Message < 3.9.4 - URL Spoofing via Unicode Control Character Mishandling
CVSS 5.4
Details
Vulnerabilities 482
Exploit Likelihood High