CWE-1284

Improper Validation of Specified Quantity in Input

Parent: CWE-20 - Improper Input Validation

The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

364 vulnerabilities with CWE-1284
CVE-2026-40272 HIGH
BlackBerry QNX libtraceparser - Code Execution or Denial of Service via KEV File
CVSS 7.0
CVE-2026-54890 HIGH
BEAM VM crash via integer underflow in binary_to_term BIT_BINARY_EXT decoding
CVE-2026-59532 HIGH
WordPress Booking and Rental Manager plugin <= 2.7.2 - Price Manipulation vulnerability
CVSS 7.5
CVE-2026-59531 HIGH
WordPress Falcon – WordPress Optimizations & Tweaks plugin <= 2.10.0 - Unknown vulnerability
CVSS 7.5
CVE-2026-58662 CRITICAL
Apache Thrift: C++ THeaderTransport::readString() info-header length bounds bypass
CVSS 9.1
CVE-2026-66374 HIGH
NIC Knot Resolver < 6.4.1 - Improper Validation of Specified Quantity in Input
CVSS 8.1
CVE-2026-11721 HIGH
Cache poisoning possible with label count discrepancy, RRSIG, and wildcards
CVSS 7.5
CVE-2026-10822 MEDIUM
Key Record using PRIVATEDNS algorithm may lead to unexpected exit
CVSS 6.5
CVE-2026-32665 HIGH
Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass
CVSS 7.5
CVE-2026-47667 HIGH
CImg Library: Uncontrolled Memory Allocation and Memory Leak in `_load_analyze()` via Crafted NIfTI/Analyze Header
CVSS 7.5
CVE-2026-59695 HIGH
Unbounded max_fee_per_gas in mpp Tempo fee-payer enables single-request wallet drain
CVE-2026-59694 HIGH
Unbounded access list in mpp Tempo fee-payer inflates gas cost per payment
CVE-2026-59252 HIGH
Missing gas_limit validation in mpp Tempo fee-payer enables wallet drain
CVE-2026-57364 MEDIUM
WordPress Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More plugin <= 2.2.0 - Other Vulnerability Type vulnerability
CVSS 6.5
CVE-2026-57023 HIGH
Junos OS: MX with SPC3, SRX Series: A specifically malformed TCP packet causes a flowd crash
CVSS 7.5
CVE-2026-57019 MEDIUM
Junos OS: MX Series: Specific traffic causes an FPC to reset
CVSS 6.5
CVE-2026-59930 MEDIUM
Mistune < 3.3.0 TOC Plugin - Predictable Heading ID Collision
CVSS 4.3
CVE-2026-59879 HIGH
Immutable.js `List` 32-bit trie overflow → unrecoverable DoS
CVSS 7.5
CVE-2026-59997 MEDIUM
Openbsd OpenSSH < 10.4 - Improper Validation of Specified Quantity in Input
CVSS 4.2
CVE-2026-43928 LOW
FOSSBilling: Payment amount not validated in PayPalEmail adapter allows invoice underpayment
CVE-2026-54234 HIGH
vLLM: Remote DoS in vLLM via Invalid Recovered Token Reinjection
CVSS 7.5
CVE-2026-55952 HIGH
TLS 1.3 server denial of service via malformed ClientHello pre-shared key extension
CVSS 7.5
CVE-2026-57623 CRITICAL
WordPress W3 Total Cache plugin <= 2.9.4 - Arbitrary Code Execution vulnerability
CVSS 9.0
CVE-2026-11906 MEDIUM
Db2 11.5.9 and 12.1.4 - Denial of Service
CVSS 6.5
CVE-2026-56035 HIGH
WordPress BitFire Security plugin <= 5.0.3 - Multiple Vulnerabilities vulnerability
CVSS 8.6
Details
Vulnerabilities 364