Skip to main content

Threats Tagged 'cwe-838'

View all threats tagged with 'cwe-838'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-838

Threats Tagged 'cwe-838'

Click on any threat for detailed analysis and mitigation recommendations

MariaDB Connector/R2DBC versions prior to 1.4.1 improperly handle mid-session changes to the character_set_client encoding when it is changed from UTF-8 to another character set. This causes a mismatch between client and server character encoding, leading to silent data corruption and potential bypass of byte-wise quoting or escaping. The issue is fixed in version 1.4.1 by restricting accepted character sets to utf8, utf8mb3, or utf8mb4 after initialization, closing the connection otherwise.

Join the discussion

MariaDB Connector/J versions prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9 have a vulnerability where the connector incorrectly assumes the connection character set is UTF-8 throughout the session. If the server changes the character_set_client to a non-UTF-8 encoding mid-session, the driver continues to encode/decode as UTF-8, causing silent data corruption and charset confusion. This can defeat client-side escaping and quoting mechanisms. The issue is fixed by restricting allowed character sets after initialization to utf8, utf8mb3, or utf8mb4, with other values causing the connection to close with an error.

Join the discussion

CVE-2026-47079 is a vulnerability in the joshnuss xml_builder library where certain characters are not properly escaped in XML output. This allows attacker-supplied input containing entity-like tokens to be emitted verbatim, potentially leading to content spoofing or cross-site scripting when downstream XML parsers decode the entities. The issue affects versions from 0.0.6 up to but not including 2.4.1.

Join the discussion

Proofpoint Enterprise Protection contains a vulnerability in the email delivery agent that allows an unauthenticated attacker to inject improperly encoded HTML into the email body of a message through the email subject. The vulnerability is caused by inappropriate encoding when rewriting the email before delivery.This issue affects Proofpoint Enterprise Protection: from 8.20.2 before patch 4809, from 8.20.0 before patch 4805, from 8.18.6 before patch 4804 and all other prior versions.

Join the discussion

Showing 1 to 4 of 4 results

Filters:Tag: cwe-838
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses