CWE-1284
Improper Validation of Specified Quantity in Input
The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
364 vulnerabilities with CWE-1284
CVE-2022-4989
HIGH
Asus AI Suite 3 < v3.03.00 - Improper Validation of Specified Quantity in Input
CVE-2022-50020
MEDIUM
Linux Kernel - Denial of Service via Unaligned Cluster Boundary Resize
CVSS 5.5
CVE-2022-25769
HIGH
Mautic < 3.3.5 - Unauthenticated Arbitrary PHP File Execution via .htaccess Bypass
CVSS 7.2
CVE-2022-47029
HIGH
Action Launcher <50.5 - Privilege Escalation
CVSS 7.8
CVE-2022-4904
HIGH
c-ares < 1.19.0 - Denial of Service via ares_set_sortlist Input Validation
CVSS 8.6
CVE-2022-3411
MEDIUM
GitLab 12.4-15.6.6, 15.7-15.7.5, 15.8-15.8.0 - Authenticated Denial of Service via Large Issue Description
CVSS 6.5
CVE-2022-48298
HIGH
Huawei EMUI and HarmonyOS - Out-of-Bounds Memory Access via Geofencing Kernel Input
CVSS 7.5
CVE-2022-48297
HIGH
Huawei EMUI and HarmonyOS - Out-of-Bounds Memory Access via Geofencing Kernel Input Length
CVSS 7.5
CVE-2022-20493
HIGH
Android - Local Privilege Escalation via Notification Access Input Validation
CVSS 7.8
CVE-2022-37312
MEDIUM
OX App Suite <7.10.6 - DoS
CVSS 5.3
CVE-2022-37311
MEDIUM
OX App Suite <7.10.6 - DoS
CVSS 5.3
CVE-2022-20543
LOW
Android 13 - Denial of Service via Improper Input Validation
CVSS 2.3
CVE-2022-4171
MEDIUM
WordPress demon image annotation <5.0 - Info Disclosure
CVSS 6.5
CVE-2022-46143
LOW
Siemens Ruggedcom RM1224 LTE and Scalance Devices - Uninitialized Buffer Read via TFTP Blocksize Mismatch
CVSS 2.7
CVE-2022-20491
HIGH
Android - Local Privilege Escalation via NotificationChannel Resource Exhaustion
CVSS 7.8
CVE-2022-20488
HIGH
Android - Local Privilege Escalation via NotificationChannel Resource Exhaustion
CVSS 7.8
CVE-2022-20691
MEDIUM
Cisco ATA 190 Series Firmware - Unauthenticated Denial of Service via Cisco Discovery Protocol Packet Header
CVSS 5.3
CVE-2022-20690
MEDIUM
Cisco ATA 190 Series - Memory Corruption
CVSS 5.3
CVE-2022-20689
MEDIUM
Cisco ATA 190 Series - Memory Corruption
CVSS 5.3
CVE-2022-20688
MEDIUM
Cisco ATA 190 Series Firmware - RCE and DoS via Cisco Discovery Protocol
CVSS 5.3
CVE-2022-20687
MEDIUM
Cisco ATA 190/191/192 Firmware - Remote Code Execution and Denial of Service via LLDP Packet Header Length Validation
CVSS 5.3
CVE-2022-20686
MEDIUM
Cisco ATA 190/191/192 Firmware - Unauthenticated Remote Code Execution and Denial of Service via LLDP Packet Header
CVSS 5.3
CVE-2022-41968
LOW
Nextcloud Server 23.0.0-23.0.9 - Denial of Service via Calendar Name Length
CVSS 3.5
CVE-2022-4111
MEDIUM
tooljet < 1.27.0 - Authenticated Denial of Service via Unrestricted Profile Picture Upload
CVSS 6.5
CVE-2022-41896
MEDIUM
TensorFlow < 2.8.4 - Denial of Service via ThreadUnsafeUnigramCandidateSampler Input Validation
CVSS 4.8
Details
Vulnerabilities
364