Vulnerabilities > Interpretation Conflict

DATE CVE VULNERABILITY TITLE RISK
2020-03-05 CVE-2020-10180 Interpretation Conflict vulnerability in Eset products
The ESET AV parsing engine allows virus-detection bypass via a crafted BZ2 Checksum field in an archive.
network
low complexity
eset CWE-436
critical
9.8
2020-02-28 CVE-2020-9399 Interpretation Conflict vulnerability in Avast products
The Avast AV parsing engine allows virus-detection bypass via a crafted ZIP archive.
local
low complexity
avast CWE-436
5.5
2020-02-24 CVE-2020-9363 Interpretation Conflict vulnerability in Sophos products
The Sophos AV parsing engine before 2020-01-14 allows virus-detection bypass via a crafted ZIP archive.
local
low complexity
sophos CWE-436
7.8
2020-02-24 CVE-2020-9362 Interpretation Conflict vulnerability in Quickheal products
The Quick Heal AV parsing engine (November 2019) allows virus-detection bypass via a crafted GPFLAG in a ZIP archive.
local
low complexity
quickheal CWE-436
7.8
2020-02-22 CVE-2020-9342 Interpretation Conflict vulnerability in F-Secure products
The F-Secure AV parsing engine before 2020-02-05 allows virus-detection bypass via crafted Compression Method data in a GZIP archive.
local
low complexity
f-secure CWE-436
5.5
2020-02-18 CVE-2020-9264 Interpretation Conflict vulnerability in Eset products
ESET Archive Support Module before 1296 allows virus-detection bypass via a crafted Compression Information Field in a ZIP archive.
local
low complexity
eset CWE-436
5.5
2020-01-06 CVE-2019-18792 Interpretation Conflict vulnerability in multiple products
An issue was discovered in Suricata 5.0.0.
network
low complexity
oisf debian CWE-436
critical
9.1
2019-12-05 CVE-2019-19589 Interpretation Conflict vulnerability in Wp-Pdf PDF Embedder 4.4
The Lever PDF Embedder plugin 4.4 for WordPress does not block the distribution of polyglot PDF documents that are valid JAR archives.
network
low complexity
wp-pdf CWE-436
critical
9.8
2019-10-24 CVE-2019-17596 Interpretation Conflict vulnerability in multiple products
Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key.
7.5
2019-07-11 CVE-2019-0052 Interpretation Conflict vulnerability in Juniper Junos
The srxpfe process may crash on SRX Series services gateways when the UTM module processes a specific fragmented HTTP packet.
network
low complexity
juniper CWE-436
7.5