CWE-150

Improper Neutralization of Escape, Meta, or Control Sequences

Parent: CWE-138 - Improper Neutralization of Special Elements

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as escape, meta, or control character sequences when they are sent to a downstream component.

68 vulnerabilities with CWE-150
CVE-2024-56201 HIGH
Jinja 3.0.0-3.1.4 - Remote Code Execution via Template Filename Control
CVSS 8.8
CVE-2024-43785 LOW
gitoxide-core - Improper Neutralization of Control Sequences in Repository Metadata
CVSS 2.5
CVE-2024-36052 HIGH
WinRAR < 7.00 - Screen Output Spoofing via ANSI Escape Sequences
CVSS 7.5
CVE-2024-32986 CRITICAL
PWAsForFirefox < 2.12.0 - Arbitrary Code Execution via XDG Desktop Entry Injection
CVSS 9.6
CVE-2024-33899 HIGH
RARLAB WinRAR < 7.00 - ANSI Escape Sequence Injection
CVSS 7.1
CVE-2024-28085 LOW
util-linux <2.40 - Privilege Escalation
CVSS 3.3
CVE-2024-27936 HIGH
Deno 1.32.1-1.40.0 - Permission Prompt Spoofing via ANSI Escape Sequence Injection
CVSS 8.8
CVE-2023-40185 MEDIUM
Shescape <1.7.4 - Privilege Escalation
CVSS 6.5
CVE-2023-3265 CRITICAL
CyberPower PowerPanel Enterprise < 2.6.9 - Unauthenticated Authentication Bypass via Username Meta-Character Injection
CVSS 9.8
CVE-2023-39342 LOW
Dangerzone <0.4.2 - Privilege Escalation
CVSS 3.6
CVE-2023-30844 LOW
Mutagen <0.16.6-0.17.1 - Info Disclosure
CVSS 3.0
CVE-2023-28446 HIGH
Deno < 1.31.2 - Terminal Prompt Spoofing via ANSI Escape Sequence Injection
CVSS 8.8
CVE-2023-26055 CRITICAL
XWiki Commons <3.1-milestone-1 - Code Injection
CVSS 9.9
CVE-2022-30123 CRITICAL
Rack <2.0.9.1-<2.2.3.1 - Command Injection
CVSS 10.0
CVE-2021-25743 LOW
kubernetes < 1.25.0 and >= 1.26.0-alpha.3 - Terminal Escape Sequence Injection via kubectl Output
CVSS 3.0
CVE-2021-25310 HIGH
Belkin Linksys WRT160NL 1.0.04.002_US_20130619 - RCE
CVSS 8.8
CVE-2020-6932 CRITICAL
BlackBerry QNX SDP 6.4.0-6.6.0 - Info Disclosure & RCE in Slinger Web Server
CVSS 10.0
CVE-2017-0899 CRITICAL
RubyGems < 2.6.13 - Terminal Escape Sequence Injection via Gem Specification
CVSS 9.8
Details
Vulnerabilities 68