CWE-1284

Improper Validation of Specified Quantity in Input

Parent: CWE-20 - Improper Input Validation

The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

364 vulnerabilities with CWE-1284
CVE-2022-41877 MEDIUM
FreeRDP < 2.9.0 - Out-of-Bounds Read via Drive Channel
CVSS 4.6
CVE-2022-25727 CRITICAL
Qualcomm AR8031 and other Firmware - Memory Corruption via Improper Length Check
CVSS 9.8
CVE-2022-26047 MEDIUM
Intel Killer WiFi Software < 3.1122.3158 - Unauthenticated Denial of Service via Improper Input Validation
CVSS 4.3
CVE-2022-36938 CRITICAL
Facebook Redex < 2022-11-04 - Out-of-bounds Read in DexLoader get_stringidx_fromdex()
CVSS 9.8
CVE-2022-20445 HIGH
Android - Remote Information Disclosure via Improper Input Validation in sdp_discovery.cc
CVSS 7.5
CVE-2022-39294 HIGH
conduit-hyper 0.2.0-0.4.1 - Denial of Service via Unbounded Content-Length Request
CVSS 7.5
CVE-2022-39313 HIGH
Parse Server < 4.10.17 and 5.x < 5.2.8 - Denial of Service via Invalid Byte Range in File Download Request
CVSS 7.5
CVE-2022-39272 MEDIUM
Flux2 < 0.35.0 - Denial of Service via Invalid Interval or Timeout Input
CVSS 5.0
CVE-2022-2592 MEDIUM
GitLab < 15.1.6, 15.2 < 15.2.4, 15.3 < 15.3.2 - Authenticated Denial of Service via Snippet Description Length
CVSS 6.5
CVE-2022-36063 HIGH
eclipse/threadx_usbx < 6.1.11 - Integer Underflow and Buffer Overflow in _ux_host_class_cdc_ecm_mac_address_get
CVSS 7.6
CVE-2022-31629 MEDIUM
PHP <7.4.31, 8.0.24, 8.1.11 - Info Disclosure
CVSS 6.5
CVE-2022-40761 HIGH
Samsung mTower < 0.3.0 - Denial of Service via TEE_AllocateOperation Heap Layout Manipulation
CVSS 7.5
CVE-2022-2277 HIGH
Hitachi Energy MicroSCADA X SYS600 <10.3.1 - DoS
CVSS 7.5
CVE-2022-20385 CRITICAL
Android - Out-of-Bounds Access in nla_parse Function
CVSS 9.8
CVE-2022-36086 HIGH
linked_list_allocator <0.10.2 - Memory Corruption
CVSS 8.4
CVE-2022-36078 HIGH
binary < 0.7.1 - Denial of Service via Unchecked Slice Length in Decode Method
CVSS 8.8
CVE-2022-28199 MEDIUM
NVIDIA DPDK 19.11_1.0.0-20.11_5.0.0 DoS & Data Integrity via Input Validation
CVSS 6.5
CVE-2022-36620 HIGH
D-Link DIR-816 A2_v1.10CNB04 and DIR-878 - Buffer Overflow via addRouting Endpoint
CVSS 7.5
CVE-2022-21208 HIGH
node-opcua < 2.74.0 - Denial of Service via Unlimited Chunk Reception
CVSS 7.5
CVE-2022-37134 CRITICAL
D-Link DIR-816 A2_v1.10CNB04 - Buffer Overflow via form2Wan.cgi l2tp_usrname Parameter
CVSS 9.8
CVE-2022-2868 MEDIUM
libtiff - Denial of Service via Crafted File in tiffcrop
CVSS 5.5
CVE-2022-2845 HIGH
vim/vim <9.0.0218 - Info Disclosure
CVSS 7.8
CVE-2022-25793 HIGH
Autodesk 3ds Max 2020-2022 < 2020.3.6 - Stack-based Buffer Overflow via ActionScript Byte Code Parsing
CVSS 7.8
CVE-2022-35928 HIGH
AES Crypt 3.11 - Buffer Overflow via Command-Line Password Prompt
CVSS 8.4
CVE-2022-22072 HIGH
Qualcomm APQ8009 Firmware - Buffer Overflow via NDP Application Information Length
CVSS 7.8
Details
Vulnerabilities 364