SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Windows C runtime converts Unicode characters to ANS
node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an
FrankenPHP is a modern application server for PHP. From version 1.11.2 to before version 1.12.3, the splitPos() function
Caddy is an extensible server platform that uses TLS by default. From 2.7.0 until 2.11.3, the FastCGI transport's splitP
XML::Parser versions through 2.45 for Perl could overflow the pre-allocated buffer size cause a heap corruption (double
Text::Minify::XS versions from 0.3.0 before 0.7.8 for Perl have a heap overflow when processing some malformed UTF-8 cha
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.14, Deno's permission system enforces filesystem
Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user t
Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin
In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.26
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, FileStore maps cache keys to fil
A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth
setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to
HashiCorp go-slug 0.4.0 through 0.18.2 could allow a local attacker to bypass .terraformignore exclusions and cause sens
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs includes a
The comm utility in uutils coreutils silently corrupts data by performing lossy UTF-8 conversion on all output lines. Th
A logic error in the ln utility of uutils coreutils causes the program to reject source paths containing non-UTF-8 filen
A logic error in the split utility of uutils coreutils causes the corruption of output filenames when provided with non-
Frequently Asked Questions
What is CWE-176?
CWE-176 (CWE-176) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-176?
There are 18 CVE records associated with CWE-176 in our database. Of these, 1 are critical severity, 7 are high severity, and 7 are medium severity.
How can I protect against CWE-176 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-176 using AI-powered security agents.
Detect CWE-176 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-176 vulnerabilities across your infrastructure.
Get Started