CWE-436
Interpretation Conflict
Product A handles inputs or steps differently than Product B, which causes A to perform incorrect actions based on its perception of B's state.
126 vulnerabilities with CWE-436
CVE-2023-29406
MEDIUM
GO < 1.19.11 - Interpretation Conflict
CVSS 6.5
CVE-2023-36456
HIGH
authentik <2023.4.3-2023.5.5 - SSRF
CVSS 8.3
CVE-2023-32708
HIGH
Splunk Enterprise < 9.0.5, < 8.2.11, < 8.1.14 and Splunk Cloud Platform < 9.0.2303.100 - HTTP Response Splitting
CVSS 7.2
CVE-2023-30541
MEDIUM
OpenZeppelin Contracts 3.2.0-4.8.2 - Denial of Service via Proxy Function Selector Clash
CVSS 5.3
CVE-2023-30536
MEDIUM
slim/psr7 < 1.6.1 - HTTP Header Injection via Newline Character
CVSS 6.5
CVE-2023-29197
MEDIUM
guzzlehttp/psr7 <1.9.1, <2.4.5 - XSS
CVSS 5.3
CVE-2023-22998
MEDIUM
Linux Kernel < 6.0.3 - Use-After-Free in virtgpu_object
CVSS 5.5
CVE-2023-24813
CRITICAL
Dompdf <2.0.3 - Arbitrary URL Fetch via SVG href Parsing
CVSS 10.0
CVE-2023-22735
MEDIUM
zulip_server - Cross-Site Scripting via Arbitrary Content-Type Upload in S3 Storage
CVSS 4.4
CVE-2023-22602
HIGH
Apache Shiro < 1.11.0 - Authentication Bypass via Spring Boot Pattern Matching Conflict
CVSS 7.5
CVE-2022-48473
HIGH
Huawei Bisheng-WNM Firmware - Denial of Service via Input Misinterpretation
CVSS 7.5
CVE-2022-48471
HIGH
Huawei Bisheng-WNM Firmware - Denial of Service via Input Misinterpretation
CVSS 7.5
CVE-2022-48261
HIGH
BiSheng-WNM FW 3.0.0.325 - Interpretation Conflict in Printer Service
CVSS 7.5
CVE-2022-48230
HIGH
BiSheng-WNM FW 3.0.0.325 - Denial of Service via Input Misinterpretation
CVSS 7.5
CVE-2022-48279
HIGH
ModSecurity < 2.9.6 and 3.0.0-3.0.7 - Web Application Firewall Bypass via HTTP Multipart Request Parsing
CVSS 7.5
CVE-2022-37436
MEDIUM
Apache HTTP Server < 2.4.55 - HTTP Response Header Injection via CRLF Sequence
CVSS 5.3
CVE-2022-41915
MEDIUM
Netty 4.1.83-4.1.85 - HTTP Response Splitting via DefaultHttpHeaders.set Iterator
CVSS 6.5
CVE-2022-38115
MEDIUM
SolarWinds Security Event Manager < 2022.2 - Insecure HTTP Method Exposure
CVSS 5.3
CVE-2022-20915
HIGH
Cisco IOS XE - Unauthenticated Denial of Service via IPv6 VPN over MPLS with Zone-Based Firewall
CVSS 7.4
CVE-2022-36051
HIGH
ZITADEL 1.42.0-1.87.0 and 2.0.0-2.1.9 - Unauthorized Authorization Grant via Actions Feature
CVSS 8.7
CVE-2022-36048
MEDIUM
Zulip < 5.6 - Information Disclosure via Crafted Remote Image URL
CVSS 4.3
CVE-2022-35962
HIGH
Zulip Mobile <27.189 - Info Disclosure
CVSS 8.0
CVE-2022-29254
LOW
silverstripe-omnipay - Info Disclosure
CVSS 3.7
CVE-2022-23773
HIGH
GO < 1.16.14 - Interpretation Conflict
CVSS 7.5
CVE-2022-0011
MEDIUM
PAN-OS 8.1.0-8.1.20, 9.0.x, 9.1.0-9.1.11, 10.0.0-10.0.7, 10.1.0-10.1.2 & Prisma Access 2.1-2.2 URL Filtering Bypass
CVSS 6.5
Details
Vulnerabilities
126