CWE-1284
Improper Validation of Specified Quantity in Input
The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
321 vulnerabilities with CWE-1284
CVE-2026-27171
LOW
zlib < 1.3.2 - Denial of Service via crc32_combine64 Function
CVSS 2.9
CVE-2026-2474
HIGH
Crypt::URandom 0.41-0.54 - Buffer Overflow
CVSS 7.5
CVE-2026-0925
LOW
Tanium Discover 4.10-4.10.134 - Improper Input Validation
CVSS 2.7
CVE-2026-21485
HIGH
iccdev < 2.3.1.2 - Out-of-bounds Read
CVSS 8.8
CVE-2025-15645
MEDIUM
Ledger Nano X, Flex, Stax MCU Firmware Update Denial of Service
CVSS 4.6
CVE-2025-66660
LOW
Amd Radeon™ RX 6000 Series Graphics Products - Improper Validation of Specified Quantity in Input
CVE-2025-14869
HIGH
Improper Validation of Specified Quantity in Input in GitLab
CVSS 7.5
CVE-2025-14688
MEDIUM
IBM® Db2® is vulnerable to a denial of service when fetching from certain tables under specific configurations
CVSS 5.3
CVE-2025-3756
MEDIUM
Denial of Service Vulnerabilities in System 800xA, Symphony® Plus IEC 61850
CVSS 6.5
CVE-2025-12664
HIGH
Improper Validation of Specified Quantity in Input in GitLab
CVSS 7.5
CVE-2025-13078
MEDIUM
Improper Validation of Specified Quantity in Input in GitLab
CVSS 6.5
CVE-2025-14513
HIGH
GitLab 16.11-18.7.5, 18.8-18.8.5, 18.9-18.9.1 - DoS via Protected Branches API
CVSS 7.5
CVE-2025-14511
HIGH
GitLab 12.2-18.7.4, 18.8-18.8.4, 18.9-18.9.0 - Unauthenticated Denial of Service via Container Registry Event Endpoint
CVSS 7.5
CVE-2025-14689
MEDIUM
IBM Db2 12.1.0-12.1.3 - Authenticated Denial of Service via Federated Object Query Logic
CVSS 6.5
CVE-2025-13867
MEDIUM
IBM Db2 11.5.0-11.5.9/12.1.0-12.1.3 - DoS
CVSS 6.5
CVE-2025-52534
MEDIUM
AMD CPU microcode - Memory Corruption
CVE-2025-15080
HIGH
Mitsubishi Electric MELSEC iQ-R Series - Info Disclosure
CVE-2025-36094
MEDIUM
IBM Cloud Pak for Business Automation <25.0.0-24.0.1 - DoS
CVSS 5.4
CVE-2025-36428
MEDIUM
IBM Db2 11.5.0-11.5.9 and 12.1.0-12.1.3 - Authenticated Denial of Service via RPSCAN Feature
CVSS 5.3
CVE-2025-36427
MEDIUM
IBM Db2 11.5.0-11.5.8 - Denial of Service via Insufficient Data Query Validation
CVSS 6.5
CVE-2025-36424
MEDIUM
IBM Db2 11.5.0-11.5.8 - Denial of Service via Improper Data Query Logic Neutralization
CVSS 6.5
CVE-2025-36423
MEDIUM
IBM Db2 12.1.0-12.1.3 - Denial of Service via Data Query Logic
CVSS 6.5
CVE-2025-36407
MEDIUM
IBM Db2 11.5.0-11.5.8 - Denial of Service via ALTER TABLE Query
CVSS 6.5
CVE-2025-36009
MEDIUM
IBM Db2 11.5.0-11.5.8 - Authenticated Denial of Service via Global Variable Exhaustion
CVSS 6.5
CVE-2025-11743
HIGH
Rockwell Automation CompactLogix 5370 - Denial of Service via Malformed CIP Forward Open Message
Details
Vulnerabilities
321