CWE-150
Improper Neutralization of Escape, Meta, or Control Sequences
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as escape, meta, or control character sequences when they are sent to a downstream component.
68 vulnerabilities with CWE-150
CVE-2024-56201
HIGH
Jinja 3.0.0-3.1.4 - Remote Code Execution via Template Filename Control
CVSS 8.8
CVE-2024-43785
LOW
gitoxide-core - Improper Neutralization of Control Sequences in Repository Metadata
CVSS 2.5
CVE-2024-36052
HIGH
WinRAR < 7.00 - Screen Output Spoofing via ANSI Escape Sequences
CVSS 7.5
CVE-2024-32986
CRITICAL
PWAsForFirefox < 2.12.0 - Arbitrary Code Execution via XDG Desktop Entry Injection
CVSS 9.6
CVE-2024-33899
HIGH
RARLAB WinRAR < 7.00 - ANSI Escape Sequence Injection
CVSS 7.1
CVE-2024-28085
LOW
util-linux <2.40 - Privilege Escalation
CVSS 3.3
CVE-2024-27936
HIGH
Deno 1.32.1-1.40.0 - Permission Prompt Spoofing via ANSI Escape Sequence Injection
CVSS 8.8
CVE-2023-40185
MEDIUM
Shescape <1.7.4 - Privilege Escalation
CVSS 6.5
CVE-2023-3265
CRITICAL
CyberPower PowerPanel Enterprise < 2.6.9 - Unauthenticated Authentication Bypass via Username Meta-Character Injection
CVSS 9.8
CVE-2023-39342
LOW
Dangerzone <0.4.2 - Privilege Escalation
CVSS 3.6
CVE-2023-30844
LOW
Mutagen <0.16.6-0.17.1 - Info Disclosure
CVSS 3.0
CVE-2023-28446
HIGH
Deno < 1.31.2 - Terminal Prompt Spoofing via ANSI Escape Sequence Injection
CVSS 8.8
CVE-2023-26055
CRITICAL
XWiki Commons <3.1-milestone-1 - Code Injection
CVSS 9.9
CVE-2022-30123
CRITICAL
Rack <2.0.9.1-<2.2.3.1 - Command Injection
CVSS 10.0
CVE-2021-25743
LOW
kubernetes < 1.25.0 and >= 1.26.0-alpha.3 - Terminal Escape Sequence Injection via kubectl Output
CVSS 3.0
CVE-2021-25310
HIGH
Belkin Linksys WRT160NL 1.0.04.002_US_20130619 - RCE
CVSS 8.8
CVE-2020-6932
CRITICAL
BlackBerry QNX SDP 6.4.0-6.6.0 - Info Disclosure & RCE in Slinger Web Server
CVSS 10.0
CVE-2017-0899
CRITICAL
RubyGems < 2.6.13 - Terminal Escape Sequence Injection via Gem Specification
CVSS 9.8
Details
Vulnerabilities
68