CWE-1007 3 個 CVE MITRE 定義 ↗

CWE-1007:Insufficient Visual Distinction of Homoglyphs Presented to User

概覽

CWE-1007(Insufficient Visual Distinction of Homoglyphs Presented to User)描述一種在漏洞資料庫與安全評估中使用的弱點類型;定義、背景與對應 CVE 見下方各節。

安全影響
安全影響:因產品與情境而異;請結合 CVE 紀錄、嚴重度評分與 MITRE 說明進行優先級判斷。

描述

The product displays information or identifiers to a user, but the display mechanism does not make it easy for the user to distinguish between visually similar or identical glyphs (homoglyphs), which may cause the user to misinterpret a glyph and perform an unintended, insecure action.

適用平台

類型 名稱 普遍性 OS / CPE
language Not Language-Specific Undetermined
technology Not Technology-Specific Undetermined
technology Web Based Sometimes

本庫相關 CVE

下列 CVE 在本庫中對應到該弱點,並保留以便追溯與檢索。

CVE 公開時間 摘要
CVE-2025-27611 2025-04-30 base-x is a base encoder and decoder of any given alphabet using bitcoin style leading zero compression. Versions 4.0.0, 5.0.0, and all prior to 3.0.11, are vulnerable to attackers potentially deceivi…
CVE-2025-0996 2025-02-15 Inappropriate implementation in Browser UI in Google Chrome on Android prior to 133.0.6943.98 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromiu…
CVE-2021-4221 2022-12-22 If a domain name contained a RTL character, it would cause the domain to be rendered to the right of the path. This could lead to user confusion and spoofing attacks. <br>*This bug only affects Firefo…

內容提交

名稱
CWE Content Team
組織
MITRE
日期
2017-07-24
版本
2.12

內容修訂

日期 名稱 版本 重要性 評論
2018-03-27 CWE Content Team 3.1 updated Demonstrative_Examples, Description, References
2019-01-03 CWE Content Team 3.2 updated Demonstrative_Examples, Description, Related_Attack_Patterns
2020-02-24 CWE Content Team 4.0 updated Applicable_Platforms, Relationships
2020-06-25 CWE Content Team 4.1 updated Observed_Examples
2022-10-13 CWE Content Team 4.9 updated Demonstrative_Examples
2023-01-31 CWE Content Team 4.10 updated Demonstrative_Examples, Description, Related_Attack_Patterns
2023-04-27 CWE Content Team 4.11 updated Relationships
2023-06-29 CWE Content Team 4.12 updated Mapping_Notes
2025-09-09 CWE Content Team 4.18 updated References
2025-12-11 CWE Content Team 4.19 updated Applicable_Platforms
cvelogic Threat Intelligence