Threats Tagged 'cwe-838'
View all threats tagged with 'cwe-838'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-838'
Click on any threat for detailed analysis and mitigation recommendations
0 MariaDB Connector/R2DBC versions prior to 1.4.1 improperly handle mid-session changes to the character_set_client encoding when it is changed from UTF-8 to another character set. This causes a mismatch between client and server character encoding, leading to silent data corruption and potential bypass of byte-wise quoting or escaping. The issue is fixed in version 1.4.1 by restricting accepted character sets to utf8, utf8mb3, or utf8mb4 after initialization, closing the connection otherwise. Join the discussion | CVE Database V5 | 08/28/2026, 22:48:41 UTC Added: 08/28/2026, 23:07:38 UTC |
0 MariaDB Connector/J versions prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9 have a vulnerability where the connector incorrectly assumes the connection character set is UTF-8 throughout the session. If the server changes the character_set_client to a non-UTF-8 encoding mid-session, the driver continues to encode/decode as UTF-8, causing silent data corruption and charset confusion. This can defeat client-side escaping and quoting mechanisms. The issue is fixed by restricting allowed character sets after initialization to utf8, utf8mb3, or utf8mb4, with other values causing the connection to close with an error. Join the discussion | CVE Database V5 | 08/28/2026, 22:46:40 UTC Added: 08/28/2026, 22:52:45 UTC |
0 CVE-2026-47079 is a vulnerability in the joshnuss xml_builder library where certain characters are not properly escaped in XML output. This allows attacker-supplied input containing entity-like tokens to be emitted verbatim, potentially leading to content spoofing or cross-site scripting when downstream XML parsers decode the entities. The issue affects versions from 0.0.6 up to but not including 2.4.1. Join the discussion | CVE Database V5 | 08/21/2026, 09:52:44 UTC Added: 08/21/2026, 10:07:50 UTC |
0 Proofpoint Enterprise Protection contains a vulnerability in the email delivery agent that allows an unauthenticated attacker to inject improperly encoded HTML into the email body of a message through the email subject. The vulnerability is caused by inappropriate encoding when rewriting the email before delivery.This issue affects Proofpoint Enterprise Protection: from 8.20.2 before patch 4809, from 8.20.0 before patch 4805, from 8.18.6 before patch 4804 and all other prior versions. Join the discussion | CVE Database V5 | 01/09/2024, 22:02:03 UTC Added: 06/03/2025, 14:44:01 UTC |
Showing 1 to 4 of 4 results