CWE-172: Encoding Error
ID
CWE-172
Abstraction
Class
Structure
Simple
Status
Draft
Number of CVEs
12
The product does not properly encode or decode the data, resulting in unexpected values.
Modes of Introduction
Phase | Note |
---|---|
Implementation |
Applicable Platforms
Type | Class | Name | Prevalence |
---|---|---|---|
Language | Not Language-Specific |
Relationships
View | Weakness | |||||||
---|---|---|---|---|---|---|---|---|
# ID | View | Status | # ID | Name | Abstraction | Structure | Status | |
CWE-1000 | Research Concepts | Draft | CWE-707 | Improper Neutralization | Pillar | Simple | Incomplete | |
CWE-1000 | Research Concepts | Draft | CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Base | Simple | Stable | |
CWE-1000 | Research Concepts | Draft | CWE-41 | Improper Resolution of Path Equivalence | Base | Simple | Incomplete |
Common Attack Pattern Enumeration and Classification (CAPEC)
The Common Attack Pattern Enumeration and Classification (CAPECâ„¢) effort provides a publicly available catalog of common attack patterns that helps users understand how adversaries exploit weaknesses in applications and other cyber-enabled capabilities.
CAPEC at Mitre.org# ID | Name | Weaknesses |
---|---|---|
CAPEC-3 | Using Leading 'Ghost' Character Sequences to Bypass Input Filters | CWE-172 |
CAPEC-52 | Embedding NULL Bytes | CWE-172 |
CAPEC-53 | Postfix, Null Terminate, and Backslash | CWE-172 |
CAPEC-64 | Using Slashes and URL Encoding Combined to Bypass Validation Logic | CWE-172 |
CAPEC-71 | Using Unicode Encoding to Bypass Validation Logic | CWE-172 |
CAPEC-72 | URL Encoding | CWE-172 |
CAPEC-78 | Using Escaped Slashes in Alternate Encoding | CWE-172 |
CAPEC-80 | Using UTF-8 Encoding to Bypass Validation Logic | CWE-172 |
CAPEC-120 | Double Encoding | CWE-172 |
CAPEC-267 | Leverage Alternate Encoding | CWE-172 |
CVEs Published
CVSS Severity
CVSS Severity - By Year
CVSS Base Score
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |
Loading...