CWE-116

High likelihood

Improper Encoding or Escaping of Output

Parent: CWE-707 - Improper Neutralization

The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

482 vulnerabilities with CWE-116
CVE-2019-9852 HIGH
LibreOffice - Code Injection
CVSS 7.8
CVE-2019-10362 MEDIUM
Jenkins Configuration as Code Plugin <1.24 - Info Disclosure
CVSS 5.4
CVE-2019-11717 MEDIUM
Firefox ESR <60.8-Firefox <68-Thunderbird <60.8 - SSRF
CVSS 5.3
CVE-2019-3571 MEDIUM
WhatsApp Desktop <0.3.3793 - Info Disclosure
CVSS 5.3
CVE-2019-11268 MEDIUM
Cloud Foundry UAA < 73.3.0 - Authenticated Information Disclosure via Improper Escaping
CVSS 4.3
CVE-2019-0971 MEDIUM
Azure DevOps Server - Info Disclosure
CVSS 6.5
CVE-2019-0956 MEDIUM
Microsoft SharePoint Server - Info Disclosure
CVSS 6.5
CVE-2019-10249 HIGH
Xtext & Xtend <2.18.0 - Info Disclosure
CVSS 8.1
CVE-2019-0857 MEDIUM
Azure DevOps Server - Info Disclosure
CVSS 6.5
CVE-2019-6109 MEDIUM
OpenSSH < 7.9 - Terminal Output Manipulation via ANSI Control Codes in Progress Display
CVSS 6.8
CVE-2018-9433 HIGH
Android - Remote Code Execution via ArrayConcatVisitor Type Confusion
CVSS 8.8
CVE-2018-20586 MEDIUM
Bitcoin Core - Arbitrary Data Injection into Debug Log via RPC Call
CVSS 5.3
CVE-2018-16386 HIGH
SWIFT Alliance Web Platform 7.1.23 - Log Injection
CVSS 7.5
CVE-2018-18838 HIGH
Netdata 1.10.0 - Log Injection via URL Parameter
CVSS 7.5
CVE-2018-8920 HIGH
Synology DiskStation Manager < 6.1.6-15266 - Arbitrary Content Injection via Log Exporter CSV Export
CVSS 7.2
CVE-2018-8609 HIGH
Microsoft Dynamics 365 8.0-8.2.3.0003 - Remote Code Execution via Improper Web Request Sanitization
CVSS 8.8
CVE-2018-15494 CRITICAL
Dojo Toolkit <1.14 - Code Injection
CVSS 9.8
CVE-2018-9246 CRITICAL
PGObject::Util::DBAdmin <0.120.0 - Code Injection
CVSS 9.8
CVE-2018-2389 MEDIUM
SAP Internet Graphics Server 7.20, 7.20EXT, 7.45, 7.49, 7.53 - Log File Injection
CVSS 5.7
CVE-2018-1048 HIGH
JBoss EAP 7.1.0.GA - Path Traversal and Information Disclosure via AJP Connector
CVSS 7.5
CVE-2017-18892 MEDIUM
Mattermost Server <4.2.0-4.0.5 - XSS
CVSS 6.1
CVE-2017-12340 MEDIUM
Cisco NX-OS - Authenticated Bash Shell Access via Python Scripting Sandbox Escape
CVSS 4.2
CVE-2017-12064 HIGH
OpenEMR 5.0.0 and prior - Improper Encoding or Escaping of Output in csv_log_html Function
CVSS 7.5
CVE-2017-8303 CRITICAL
Accellion File Transfer Appliance < 9_12_180 - Remote Code Execution via seos/1000/find.api Method Parameter
CVSS 9.8
CVE-2016-2568 HIGH
polkit - Local Privilege Escalation via TIOCSTI ioctl Call
CVSS 7.8
Details
Vulnerabilities 482
Exploit Likelihood High