CWE-176
CWE-176 · 3 records · 2 with a public proof-of-concept
Records the NVD classes under CWE-176, highest CVSS first.
- HIGH 7.5CVE-2026-93990public PoC
Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units, hiding marku…
- UNSCOREDCVE-2026-19954public PoC
Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command-line tool that queries WHOIS for the wrong domain for unicode domain names. pwhois encodes each non-ASCII label directly using Net::IDN::Punycode and prepends xn--. Apart from lowercasing …
- UNSCOREDCVE-2026-86105
An improper authorization vulnerability in Fireware OS's Access Portal reverse proxy allows an authenticated, low-privileged Access Portal user to access other web applications they are not authorized for by sending a specially crafted request for a different …