guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Affected versions are subject to improper header
OpenZeppelin Contracts is a library for secure smart contract development. A function in the implementation contract may
Zulip is an open-source team collaboration tool. In versions of zulip prior to commit `2f6c5a8` but after commit `04cf68
fish is a smart and user-friendly command line shell for macOS, Linux, and the rest of the family. fish shell uses certa
Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable a
ZITADEL combines the ease of Auth0 and the versatility of Keycloak.**Actions**, introduced in ZITADEL **1.42.0** on the
Zulip is an open source team chat and Zulip Mobile is an app for iOS and Andriod users. In Zulip Mobile through version
cmd/go in Go before 1.16.14 and 1.17.x before 1.17.7 can misinterpret branch names that falsely appear to be version tag
A vulnerability in the implementation of IPv6 VPN over MPLS (6VPE) with Zone-Based Firewall (ZBFW) of Cisco IOS XE Softw
PAN-OS software provides options to exclude specific websites from URL category enforcement and those websites are block
Netty project is an event-driven asynchronous network application framework. Starting in version 4.1.83.Final and prior
Insecure method vulnerability in which allowed HTTP methods are disclosed. E.g., OPTIONS, DELETE, TRACE, and PUT
Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. When displaying
silverstripe-omnipay is a SilverStripe integration with Omnipay PHP payments library. For a subset of Omnipay gateways (
Microsoft SharePoint Server Remote Code Execution Vulnerability
A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as
A vulnerability in the TrustSec CLI parser of Cisco IOS and Cisco IOS XE Software could allow an authenticated, remote a
An improper interpretation conflict of certain data between certain software components within the Juniper Networks Juno
go-ethereum is the official Go implementation of the Ethereum protocol. In affected versions a consensus-vulnerability i
xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. xmldom version
The ESET AV parsing engine allows virus-detection bypass via a crafted BZ2 Checksum field in an archive. This affects ve
An issue was discovered in Suricata 5.0.0. It is possible to bypass/evade any tcp based signature by overlapping a TCP s
The Quick Heal AV parsing engine (November 2019) allows virus-detection bypass via a crafted GPFLAG in a ZIP archive. Th
The Sophos AV parsing engine before 2020-01-14 allows virus-detection bypass via a crafted ZIP archive. This affects End
A vulnerability in the Secure Shell (SSH) server code of Cisco IOS Software and Cisco IOS XE Software could allow an aut
ESET Archive Support Module before 1294 allows virus-detection bypass via crafted RAR Compression Information in an arch
Pairing in Bluetooth® Core v5.2 and earlier may permit an unauthenticated attacker to acquire credentials with two pairi
For ABB eSOMS versions 4.0 to 6.0.3, the X-Content-Type-Options Header is missing in the HTTP response, potentially caus
ESET Archive Support Module before 1296 allows virus-detection bypass via a crafted Compression Information Field in a Z
The F-Secure AV parsing engine before 2020-02-05 allows virus-detection bypass via crafted Compression Method data in a
The Avast AV parsing engine allows virus-detection bypass via a crafted ZIP archive. This affects versions before 12 def
A vulnerability in the FTP inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Thr
The Lever PDF Embedder plugin 4.4 for WordPress does not block the distribution of polyglot PDF documents that are valid
The srxpfe process may crash on SRX Series services gateways when the UTM module processes a specific fragmented HTTP pa
Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA
bgpd in FRRouting FRR (aka Free Range Routing) 2.x and 3.x before 3.0.4, 4.x before 4.0.1, 5.x before 5.0.2, and 6.x bef
In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service (host OS crash
Frequently Asked Questions
What is CWE-436?
CWE-436 (CWE-436) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-436?
There are 153 CVE records associated with CWE-436 in our database. Of these, 16 are critical severity, 55 are high severity, and 48 are medium severity.
How can I protect against CWE-436 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-436 using AI-powered security agents.
Detect CWE-436 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-436 vulnerabilities across your infrastructure.
Get Started