cvekit
LIVE
All CWEs

CWE-237

Improper Handling of Structural Elements

BaseIncompleteSimple4 CVEs
The product does not handle or incorrectly handles inputs that are related to complex structures.

Common consequences1

  • IntegrityUnexpected State

Relationships1

CVEs referencing this CWE4

CVEDescriptionSeverityEPSSFlagsModified
CVE-2019-1000007

aioxmpp version 0.10.2 and earlier contains a Improper Handling of Structural Elements vulnerability in Stanza Parser, rollback during error processing, aioxmpp.xso.model.guard function that can result in Denial of Service, Other. This attack appears to be exploitable via Remote. A crafted stanza can be sent to an application which uses the vulnerable components to either inject data in a different context or cause the application to reconnect (potentially losing data). This vulnerability appears to have been fixed in 0.10.3.

HIGH7.4
1.16%p63
2024-11-21
CVE-2023-34429

Weintek Weincloud v0.13.6 could allow an attacker to cause a denial-of-service condition for Weincloud by sending a forged JWT token.

HIGH7.5
0.53%p41
2024-11-21
CVE-2023-6110

A flaw was found in OpenStack. When a user tries to delete a non-existing access rule in it's scope, it deletes other existing access rules which are not associated with any application credentials.

MEDIUM5.5
0.49%p38
2026-04-15
CVE-2025-24336

SXF Common Library handles input data improperly. If a product using the library reads a crafted file, the product may be crashed.

NONE
0.15%p4
2026-04-15