Skip to main content

CWE archive

CWE-172 CVEs

Programmatic archive

17 CVEs tagged with CWE-1723 Critical, 2 High, 9 Medium, 3 Low, 0 Unrated.

CVE-2026-48784

Published Jul 14, 2026

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, UrlGenerator::doGenerate() used strt…

CVSS 5.1 · Medium
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2025-12758

Published Nov 27, 2025

Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Special Elements in the isLength() function that does not take…

CVSS 7.7 · High
evidence mentions
5
Buzz score
27.4
Vendor/product tagsBeta · best-effort

CVE-2025-27110

Published Feb 25, 2025

Libmodsecurity is one component of the ModSecurity v3 project. The library codebase serves as an interface to ModSecurity Connectors taking in web traffic and applying traditional…

CVSS 7.9 · High
Vendor/product tagsBeta · best-effort

CVE-2024-48909

Published Oct 14, 2024

SpiceDB is an open source database for scalably storing and querying fine-grained authorization data. Starting in version 1.35.0 and prior to version 1.37.1, clients that have ena…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-33604

Published Jun 24, 2021

URL encoding error in development mode handler in com.vaadin:flow-server versions 2.0.0 through 2.6.1 (Vaadin 14.0.0 through 14.6.1), 3.0.0 through 6.0.9 (Vaadin 15.0.0 through 19…

CVSS 2.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-12677

Published Oct 2, 2019

A vulnerability in the Secure Sockets Layer (SSL) VPN feature of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to cause a denial o…

CVSS 6.5 · Medium

CVE-2018-3777

Published Aug 3, 2018

Insufficient URI encoding in restforce before 3.0.0 allows attacker to inject arbitrary parameters into Salesforce API requests.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-7289

Published Feb 21, 2018

An issue was discovered in armadito-windows-driver/src/communication.c in Armadito 0.12.7.2. Malware with filenames containing pure UTF-16 characters can bypass detection. The use…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-7173

Published Feb 15, 2018

A large loop in JBIG2Stream::readSymbolDictSeg in xpdf 4.00 allows an attacker to cause denial of service via a specific file due to inappropriate decoding.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6691

Published Oct 10, 2016

service/jni/com_android_server_wifi_Gbk2Utf.cpp in the Qualcomm Wi-Fi gbk2utf module in Android before 2016-10-05 allows remote attackers to cause a denial of service (framework c…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-3829

Published Aug 5, 2016

The ih264d decoder in mediaserver in Android 6.x before 2016-08-01 does not initialize certain structure members, which allows remote attackers to cause a denial of service (devic…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-3828

Published Aug 5, 2016

decoder/ih264d_api.c in mediaserver in Android 6.x before 2016-08-01 mishandles invalid PPS and SPS NAL units, which allows remote attackers to cause a denial of service (device h…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-3827

Published Aug 5, 2016

codecs/hevcdec/SoftHEVC.cpp in libstagefright in mediaserver in Android 6.0.1 before 2016-08-01 mishandles decoder errors, which allows remote attackers to cause a denial of servi…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-17 of 17 CVEsPage 1 of 1