CWE-116
High likelihoodImproper Encoding or Escaping of Output
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
482 vulnerabilities with CWE-116
CVE-2019-9852
HIGH
LibreOffice - Code Injection
CVSS 7.8
CVE-2019-10362
MEDIUM
Jenkins Configuration as Code Plugin <1.24 - Info Disclosure
CVSS 5.4
CVE-2019-11717
MEDIUM
Firefox ESR <60.8-Firefox <68-Thunderbird <60.8 - SSRF
CVSS 5.3
CVE-2019-3571
MEDIUM
WhatsApp Desktop <0.3.3793 - Info Disclosure
CVSS 5.3
CVE-2019-11268
MEDIUM
Cloud Foundry UAA < 73.3.0 - Authenticated Information Disclosure via Improper Escaping
CVSS 4.3
CVE-2019-0971
MEDIUM
Azure DevOps Server - Info Disclosure
CVSS 6.5
CVE-2019-0956
MEDIUM
Microsoft SharePoint Server - Info Disclosure
CVSS 6.5
CVE-2019-10249
HIGH
Xtext & Xtend <2.18.0 - Info Disclosure
CVSS 8.1
CVE-2019-0857
MEDIUM
Azure DevOps Server - Info Disclosure
CVSS 6.5
CVE-2019-6109
MEDIUM
OpenSSH < 7.9 - Terminal Output Manipulation via ANSI Control Codes in Progress Display
CVSS 6.8
CVE-2018-9433
HIGH
Android - Remote Code Execution via ArrayConcatVisitor Type Confusion
CVSS 8.8
CVE-2018-20586
MEDIUM
Bitcoin Core - Arbitrary Data Injection into Debug Log via RPC Call
CVSS 5.3
CVE-2018-16386
HIGH
SWIFT Alliance Web Platform 7.1.23 - Log Injection
CVSS 7.5
CVE-2018-18838
HIGH
Netdata 1.10.0 - Log Injection via URL Parameter
CVSS 7.5
CVE-2018-8920
HIGH
Synology DiskStation Manager < 6.1.6-15266 - Arbitrary Content Injection via Log Exporter CSV Export
CVSS 7.2
CVE-2018-8609
HIGH
Microsoft Dynamics 365 8.0-8.2.3.0003 - Remote Code Execution via Improper Web Request Sanitization
CVSS 8.8
CVE-2018-15494
CRITICAL
Dojo Toolkit <1.14 - Code Injection
CVSS 9.8
CVE-2018-9246
CRITICAL
PGObject::Util::DBAdmin <0.120.0 - Code Injection
CVSS 9.8
CVE-2018-2389
MEDIUM
SAP Internet Graphics Server 7.20, 7.20EXT, 7.45, 7.49, 7.53 - Log File Injection
CVSS 5.7
CVE-2018-1048
HIGH
JBoss EAP 7.1.0.GA - Path Traversal and Information Disclosure via AJP Connector
CVSS 7.5
CVE-2017-18892
MEDIUM
Mattermost Server <4.2.0-4.0.5 - XSS
CVSS 6.1
CVE-2017-12340
MEDIUM
Cisco NX-OS - Authenticated Bash Shell Access via Python Scripting Sandbox Escape
CVSS 4.2
CVE-2017-12064
HIGH
OpenEMR 5.0.0 and prior - Improper Encoding or Escaping of Output in csv_log_html Function
CVSS 7.5
CVE-2017-8303
CRITICAL
Accellion File Transfer Appliance < 9_12_180 - Remote Code Execution via seos/1000/find.api Method Parameter
CVSS 9.8
CVE-2016-2568
HIGH
polkit - Local Privilege Escalation via TIOCSTI ioctl Call
CVSS 7.8
Details
Vulnerabilities
482
Exploit Likelihood
High