CWE-436

Interpretation Conflict

Parent: CWE-435 - Improper Interaction Between Multiple Correctly-Behaving Entities

Product A handles inputs or steps differently than Product B, which causes A to perform incorrect actions based on its perception of B's state.

109 vulnerabilities with CWE-436
CVE-2019-25101 MEDIUM
OnShift TurboGears 1.0.11.10 - HTTP Response Splitting
CVSS 6.3
CVE-2019-19089 MEDIUM
Hitachi Energy eSOMS 4.0-6.0.3 - Missing X-Content-Type-Options Header
CVSS 6.1
CVE-2019-18792 CRITICAL
Suricata 5.0.0 - TCP Signature Bypass via Overlapping FIN Packet
CVSS 9.1
CVE-2019-19589 CRITICAL
Lever PDF Embedder Plugin 4.4 - Info Disclosure
CVSS 9.8
CVE-2019-17596 HIGH
GO < 1.12.11 - Interpretation Conflict
CVSS 7.5
CVE-2019-0052 HIGH
Juniper Junos OS - Denial of Service via Fragmented HTTP Packet Misinterpretation
CVSS 7.5
CVE-2019-5892 MEDIUM
FRRouting 2.x-3.x < 3.0.4, 4.x < 4.0.1, 5.x < 5.0.2, 6.x < 6.0.2 - Denial of Service via BGP UPDATE Attribute 255
CVSS 6.5
CVE-2018-19966 HIGH
Xen 4.11.0-4.11.1 - Denial of Service or Privilege Escalation via Shadow Paging Union Data Structure
CVSS 8.8
CVE-2018-6560 HIGH
Flatpak < 0.8.9 and 0.9.x-0.10.x < 0.10.3 - Sandbox Escape via D-Bus Message Whitespace Handling
CVSS 8.8
Details
Vulnerabilities 109