CWE-436

Interpretation Conflict

Parent: CWE-435 - Improper Interaction Between Multiple Correctly-Behaving Entities

Product A handles inputs or steps differently than Product B, which causes A to perform incorrect actions based on its perception of B's state.

109 vulnerabilities with CWE-436
CVE-2022-38115 MEDIUM
SolarWinds Security Event Manager < 2022.2 - Insecure HTTP Method Exposure
CVSS 5.3
CVE-2022-20915 HIGH
Cisco IOS XE - Unauthenticated Denial of Service via IPv6 VPN over MPLS with Zone-Based Firewall
CVSS 7.4
CVE-2022-36051 HIGH
ZITADEL 1.42.0-1.87.0 and 2.0.0-2.1.9 - Unauthorized Authorization Grant via Actions Feature
CVSS 8.7
CVE-2022-36048 MEDIUM
Zulip < 5.6 - Information Disclosure via Crafted Remote Image URL
CVSS 4.3
CVE-2022-35962 HIGH
Zulip Mobile <27.189 - Info Disclosure
CVSS 8.0
CVE-2022-29254 LOW
silverstripe-omnipay - Info Disclosure
CVSS 3.7
CVE-2022-23773 HIGH
GO < 1.16.14 - Interpretation Conflict
CVSS 7.5
CVE-2022-0011 MEDIUM
PAN-OS 8.1.0-8.1.20, 9.0.x, 9.1.0-9.1.11, 10.0.0-10.0.7, 10.1.0-10.1.2 & Prisma Access 2.1-2.2 URL Filtering Bypass
CVSS 6.5
CVE-2021-45327 CRITICAL
Gitea < 1.11.2 - Remote Code Execution via HTTP Permission Method Trust
CVSS 9.8
CVE-2021-34699 HIGH
Cisco IOS - Authenticated Denial of Service via TrustSec CLI Parser
CVSS 7.7
CVE-2021-1587 HIGH
Cisco NX-OS - Denial of Service via TRILL OAM EtherType Packet Handling
CVSS 8.6
CVE-2021-39137 MEDIUM
go-ethereum 1.10.0-1.10.8 - Consensus Chain Split via Interpretation Conflict
CVSS 6.5
CVE-2021-28474 HIGH
Microsoft SharePoint Server - Remote Code Execution
CVSS 8.8
CVE-2021-21366 MEDIUM
xmldom < 0.5.0 - XML Processing Syntax Manipulation via Malicious Document Parsing
CVSS 4.3
CVE-2021-0207 HIGH
Juniper Junos OS - Denial of Service via Malformed Traffic Handling
CVSS 7.5
CVE-2020-3564 MEDIUM
Cisco ASA & FTD FTP Inspection Bypass via Flow Tracking
CVSS 5.3
CVE-2020-3200 HIGH
Cisco IOS - Authenticated Denial of Service via SSH Connection State Machine
CVSS 7.7
CVE-2020-10134 MEDIUM
Bluetooth Core < 5.2 - Unauthenticated Credential Acquisition via Pairing Method Confusion
CVSS 6.3
CVE-2020-10193 HIGH
ESET Cyber Security < 1294 - Virus Detection Bypass via Crafted RAR Compression Information
CVSS 7.5
CVE-2020-10180 CRITICAL
ESET Cyber Security < 1294 - Virus Detection Bypass via Crafted BZ2 Checksum
CVSS 9.8
CVE-2020-9399 MEDIUM
Avast Antivirus < 12.0 - Virus Detection Bypass via Crafted ZIP Archive
CVSS 5.5
CVE-2020-9363 HIGH
Sophos Cloud Optix < 2020-01-14 - Virus Detection Bypass via Crafted ZIP Archive
CVSS 7.8
CVE-2020-9362 HIGH
Quick Heal AntiVirus Products - Virus Detection Bypass via Malformed ZIP Archive GPFLAG
CVSS 7.8
CVE-2020-9342 MEDIUM
F-Secure Cloud Protection < 17.0.605.474 - Virus Detection Bypass via GZIP
CVSS 5.5
CVE-2020-9264 MEDIUM
ESET Cyber Security < 1296 - Virus Detection Bypass via ZIP Archive Compression Information Field
CVSS 5.5
Details
Vulnerabilities 109