CWE-436
Interpretation Conflict
Product A handles inputs or steps differently than Product B, which causes A to perform incorrect actions based on its perception of B's state.
126 vulnerabilities with CWE-436
CVE-2025-48384
HIGH
KEV
Git < 2.43.7 - Unauthenticated Arbitrary Code Execution via Submodule Path Traversal
CVSS 8.0
CVE-2025-1217
LOW
PHP <8.1.32, <8.2.28, <8.3.19, <8.4.5 - Info Disclosure
CVSS 3.1
CVE-2025-25292
CRITICAL
ruby-saml <1.12.4,1.18.0 - Auth Bypass
CVSS 9.8
CVE-2025-25291
CRITICAL
ruby-saml <1.12.4,1.18.0 - Auth Bypass
CVSS 9.8
CVE-2025-24013
MEDIUM
CodeIgniter < 4.5.8 - Denial of Service via Malformed HTTP Header Injection
CVSS 5.3
CVE-2024-55629
HIGH
Suricata < 7.0.8 - TCP Urgent Data Interpretation Conflict
CVSS 7.5
CVE-2024-45097
MEDIUM
IBM Aspera Faspex <5.0.9 - Auth Bypass
CVSS 5.9
CVE-2024-42487
MEDIUM
Cilium <1.15.8-1.16.1 - Info Disclosure
CVSS 4.0
CVE-2024-38428
CRITICAL
GNU Wget < 1.24.5 - URI Parsing Interpretation Conflict in url.c
CVSS 9.1
CVE-2024-20293
MEDIUM
Cisco Adaptive Security Appliance and Firepower Threat Defense - Unauthenticated Access Control List Bypass
CVSS 5.8
CVE-2024-34478
HIGH
btcd < 0.24.0 - Consensus Failure via Incorrect Signed Transaction Version Handling
CVSS 7.5
CVE-2024-3386
MEDIUM
Palo Alto Networks PAN-OS - Info Disclosure
CVSS 5.3
CVE-2024-2004
LOW
curl 7.85.0-8.6.0 - Protocol Filter Bypass via Empty Protocol Set
CVSS 3.5
CVE-2024-29034
MEDIUM
CarrierWave < 2.2.6 and 3.0.0-3.0.7 - Cross-Site Scripting via Content-Type Header Bypass
CVSS 6.8
CVE-2024-28054
HIGH
Amavis <2.12.3, 2.13.x <2.13.1 - Info Disclosure
CVSS 7.4
CVE-2024-24754
LOW
Bref < 2.1.13 - Interpretation Conflict in MultiPart Request Parsing
CVSS 3.7
CVE-2024-24753
MEDIUM
Bref < 2.1.13 - Security Feature Bypass via API Gateway v2 Multiple Header Handling
CVSS 4.8
CVE-2024-23644
MEDIUM
Trillium < 0.5.4 and trillium-http < 0.3.12 - HTTP Request/Response Splitting via Header Injection
CVSS 6.8
CVE-2023-52892
HIGH
phpseclib < 1.0.22, 2.x < 2.0.46, 3.x < 3.0.33 - X.509 Certificate Host Verification Bypass
CVSS 7.5
CVE-2023-39481
HIGH
Softing Secure Integration Server < 1.30 - Remote Code Execution via URI Parsing Inconsistency
CVSS 8.8
CVE-2023-45715
LOW
HCL BigFix Platform 9.5-9.5.23 - Denial of Service via Invalid File Name Characters
CVSS 3.5
CVE-2023-50327
MEDIUM
IBM PowerSC 1.3, 2.0, and 2.1 - Unauthorized File Request Modification via Insecure HTTP Methods
CVSS 5.3
CVE-2023-48256
MEDIUM
Bosch NEXO-OS 1000-1500-sp2 - HTTP Response Splitting via Crafted URL
CVSS 5.3
CVE-2023-49284
LOW
fish < 3.6.2 - Denial of Service and Information Disclosure via Unicode Non-Character Handling
CVSS 3.9
CVE-2023-40718
HIGH
Fortinet IPS Engine <7.321-6.158 - Evade IPS
CVSS 7.5
Details
Vulnerabilities
126