Vulnerabilities > Interpretation Conflict

DATE CVE VULNERABILITY TITLE RISK
2023-06-01 CVE-2023-32708 Interpretation Conflict vulnerability in Splunk and Splunk Cloud Platform
In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform versions below 9.0.2303.100, a low-privileged user can trigger an HTTP response splitting vulnerability with the ‘rest’ SPL command that lets them potentially access other REST endpoints in the system arbitrarily.
network
low complexity
splunk CWE-436
8.8
2023-04-17 CVE-2023-30541 Interpretation Conflict vulnerability in Openzeppelin Contracts Upgradeable
OpenZeppelin Contracts is a library for secure smart contract development.
network
low complexity
openzeppelin CWE-436
5.3
2023-02-28 CVE-2023-22998 Interpretation Conflict vulnerability in Linux Kernel
In the Linux kernel before 6.0.3, drivers/gpu/drm/virtio/virtgpu_object.c misinterprets the drm_gem_shmem_get_sg_table return value (expects it to be NULL in the error case, whereas it is actually an error pointer).
local
low complexity
linux CWE-436
5.5
2023-02-27 CVE-2022-48230 Interpretation Conflict vulnerability in Huawei Bisheng-Wnm Firmware 3.0.0.325
There is a misinterpretation of input vulnerability in BiSheng-WNM FW 3.0.0.325.
network
low complexity
huawei CWE-436
7.5
2023-02-27 CVE-2022-48261 Interpretation Conflict vulnerability in Huawei Bisheng-Wnm Firmware 3.0.0.325
There is a misinterpretation of input vulnerability in BiSheng-WNM FW 3.0.0.325.
network
low complexity
huawei CWE-436
7.5
2023-02-04 CVE-2019-25101 Interpretation Conflict vulnerability in Turbogears Project Turbogears 1.0.11.10
A vulnerability classified as critical has been found in OnShift TurboGears 1.0.11.10.
network
low complexity
turbogears-project CWE-436
critical
9.8
2023-01-20 CVE-2022-48279 Interpretation Conflict vulnerability in multiple products
In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall.
network
low complexity
trustwave debian CWE-436
7.5
2022-11-23 CVE-2022-38115 Interpretation Conflict vulnerability in Solarwinds Security Event Manager
Insecure method vulnerability in which allowed HTTP methods are disclosed.
network
low complexity
solarwinds CWE-436
5.3
2022-10-10 CVE-2022-20915 Interpretation Conflict vulnerability in Cisco IOS XE
A vulnerability in the implementation of IPv6 VPN over MPLS (6VPE) with Zone-Based Firewall (ZBFW) of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device.
low complexity
cisco CWE-436
7.4
2022-02-11 CVE-2022-23773 Interpretation Conflict vulnerability in multiple products
cmd/go in Go before 1.16.14 and 1.17.x before 1.17.7 can misinterpret branch names that falsely appear to be version tags.
network
low complexity
golang netapp CWE-436
7.5