CWE-178

Improper Handling of Case Sensitivity

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product does not properly account for differences in case sensitivity when accessing or determining the properties of a resource, leading to inconsistent results.

62 vulnerabilities with CWE-178
CVE-2024-23331 HIGH
Vite < 2.9.17 - Information Disclosure
CVSS 7.5
CVE-2023-46218 MEDIUM
curl - SSRF
CVSS 6.5
CVE-2023-3545 CRITICAL
Chamilo LMS <=1.11.20 - RCE
CVSS 9.8
CVE-2023-4759 HIGH
Eclipse Jgit - Symlink Following
CVSS 8.8
CVE-2022-29604 CRITICAL
ONOS 2.5.1 - Info Disclosure
CVSS 9.8
CVE-2022-22968 MEDIUM
Spring Framework <5.3.18,<5.2.20 - Info Disclosure
CVSS 5.3
CVE-2021-45893 HIGH
Softwarebuero Zauner ARC 4.2.0.4 - Info Disclosure
CVSS 7.5
CVE-2021-25036 HIGH
All in One SEO WordPress <4.1.5.3 - Privilege Escalation
CVSS 8.8
CVE-2021-0973 MEDIUM
Android <12 - Info Disclosure
CVSS 5.0
CVE-2021-39134 HIGH
@npmcli/arborist - Info Disclosure
CVSS 8.2
CVE-2021-39155 HIGH
Istio < 1.9.8 - Incorrect Authorization
CVSS 8.3
CVE-2021-24347 HIGH
SP Project & Document Manager <4.22 - Path Traversal
CVSS 8.8
CVE-2021-28323 MEDIUM
Windows DNS - Info Disclosure
CVSS 6.5
CVE-2021-25920 MEDIUM
OpenEMR <6.0.0 - Privilege Escalation
CVSS 6.5
CVE-2020-15234 MEDIUM
ORY Fosite <0.34.1 - Open Redirect
CVSS 6.1
CVE-2020-12812 CRITICAL KEV
FortiOS <6.4.0 - Auth Bypass
CVSS 9.8
CVE-2020-5301 LOW
Simplesamlphp < 1.18.6 - Information Disclosure
CVSS 3.0
CVE-2019-6289 HIGH
DedeCMS V57_UTF8_SP2 - RCE
CVSS 8.8
CVE-2018-8337 MEDIUM
Windows Subsystem for Linux - Auth Bypass
CVSS 5.3
CVE-2018-9845 CRITICAL
Etherpad Lite <1.6.4 - Privilege Escalation
CVSS 9.8
CVE-2017-8493 MEDIUM
Microsoft - Privilege Escalation
CVSS 5.5
CVE-2007-3365 HIGH
MyServer <0.8.9 - Info Disclosure
CVSS 7.5
CVE-2005-0269 CRITICAL
GNUBoard <3.40 - Info Disclosure
CVSS 9.8
CVE-2004-2154 CRITICAL
CUPS <1.1.21rc1 - Auth Bypass
CVSS 9.8
CVE-2004-2214 CRITICAL
Mbedthis AppWeb <1.1.3 - Auth Bypass
CVSS 9.8
Details
Vulnerabilities 62