38 vulnerabilities classified as CWE-349 (在可信数据中接受外来的不可信数据). AI Chinese analysis included.
CWE-349 represents a critical input validation weakness where software incorrectly processes untrusted data embedded alongside trusted inputs, treating the malicious elements as legitimate. Attackers typically exploit this by injecting harmful payloads, such as SQL commands or script tags, into fields that are otherwise expected to contain safe, verified information. Because the application fails to distinguish between the two data sources, it executes the untrusted content, leading to severe vulnerabilities like injection attacks or data corruption. Developers can prevent this by implementing strict input sanitization and validation routines that isolate and verify each data component independently. By explicitly defining allowed formats and rejecting any unexpected characters or structures, even those hidden within trusted streams, engineers ensure that only verified, safe data influences the application’s logic, thereby maintaining system integrity.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2023-51655 | JetBrains IntelliJ IDEA 安全漏洞 — IntelliJ IDEA | 6.3 | Medium | 2023-12-21 |
| CVE-2023-44317 | Siemens SCALANCE 多款产品安全漏洞 — RUGGEDCOM RM1224 LTE(4G) EU | 7.2 | High | 2023-11-14 |
| CVE-2023-5548 | Moodle: cache poisoning risk with endpoint revision numbers | 3.3 | Low | 2023-11-09 |
| CVE-2023-3749 | VideoEdge config — VideoEdge | 7.1 | High | 2023-08-03 |
| CVE-2020-8023 | Local privilege escalation from ldap to root when using OPENLDAP_CONFIG_BACKEND=ldap in openldap2 — SUSE Enterprise Storage 5 | 7.7 | High | 2020-09-01 |
| CVE-2020-10751 | Linux kernel 数据伪造问题漏洞 — kernel | 6.1 | Medium | 2020-05-26 |
| CVE-2019-9535 | iTerm2, up to and including version 3.3.5, with tmux integration is vulnerable to remote command execution — iTerm2 | 9.8 | - | 2019-10-09 |
| CVE-2018-1131 | Infinispan 安全漏洞 — infinispan | 8.8 | - | 2018-05-15 |
Vulnerabilities classified as CWE-349 (在可信数据中接受外来的不可信数据) represent 38 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.