CWE-1284

Improper Validation of Specified Quantity in Input

Parent: CWE-20 - Improper Input Validation

The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

321 vulnerabilities with CWE-1284
CVE-2026-27171 LOW
zlib < 1.3.2 - Denial of Service via crc32_combine64 Function
CVSS 2.9
CVE-2026-2474 HIGH
Crypt::URandom 0.41-0.54 - Buffer Overflow
CVSS 7.5
CVE-2026-0925 LOW
Tanium Discover 4.10-4.10.134 - Improper Input Validation
CVSS 2.7
CVE-2026-21485 HIGH
iccdev < 2.3.1.2 - Out-of-bounds Read
CVSS 8.8
CVE-2025-15645 MEDIUM
Ledger Nano X, Flex, Stax MCU Firmware Update Denial of Service
CVSS 4.6
CVE-2025-66660 LOW
Amd Radeon™ RX 6000 Series Graphics Products - Improper Validation of Specified Quantity in Input
CVE-2025-14869 HIGH
Improper Validation of Specified Quantity in Input in GitLab
CVSS 7.5
CVE-2025-14688 MEDIUM
IBM® Db2® is vulnerable to a denial of service when fetching from certain tables under specific configurations
CVSS 5.3
CVE-2025-3756 MEDIUM
Denial of Service Vulnerabilities in System 800xA, Symphony® Plus IEC 61850
CVSS 6.5
CVE-2025-12664 HIGH
Improper Validation of Specified Quantity in Input in GitLab
CVSS 7.5
CVE-2025-13078 MEDIUM
Improper Validation of Specified Quantity in Input in GitLab
CVSS 6.5
CVE-2025-14513 HIGH
GitLab 16.11-18.7.5, 18.8-18.8.5, 18.9-18.9.1 - DoS via Protected Branches API
CVSS 7.5
CVE-2025-14511 HIGH
GitLab 12.2-18.7.4, 18.8-18.8.4, 18.9-18.9.0 - Unauthenticated Denial of Service via Container Registry Event Endpoint
CVSS 7.5
CVE-2025-14689 MEDIUM
IBM Db2 12.1.0-12.1.3 - Authenticated Denial of Service via Federated Object Query Logic
CVSS 6.5
CVE-2025-13867 MEDIUM
IBM Db2 11.5.0-11.5.9/12.1.0-12.1.3 - DoS
CVSS 6.5
CVE-2025-52534 MEDIUM
AMD CPU microcode - Memory Corruption
CVE-2025-15080 HIGH
Mitsubishi Electric MELSEC iQ-R Series - Info Disclosure
CVE-2025-36094 MEDIUM
IBM Cloud Pak for Business Automation <25.0.0-24.0.1 - DoS
CVSS 5.4
CVE-2025-36428 MEDIUM
IBM Db2 11.5.0-11.5.9 and 12.1.0-12.1.3 - Authenticated Denial of Service via RPSCAN Feature
CVSS 5.3
CVE-2025-36427 MEDIUM
IBM Db2 11.5.0-11.5.8 - Denial of Service via Insufficient Data Query Validation
CVSS 6.5
CVE-2025-36424 MEDIUM
IBM Db2 11.5.0-11.5.8 - Denial of Service via Improper Data Query Logic Neutralization
CVSS 6.5
CVE-2025-36423 MEDIUM
IBM Db2 12.1.0-12.1.3 - Denial of Service via Data Query Logic
CVSS 6.5
CVE-2025-36407 MEDIUM
IBM Db2 11.5.0-11.5.8 - Denial of Service via ALTER TABLE Query
CVSS 6.5
CVE-2025-36009 MEDIUM
IBM Db2 11.5.0-11.5.8 - Authenticated Denial of Service via Global Variable Exhaustion
CVSS 6.5
CVE-2025-11743 HIGH
Rockwell Automation CompactLogix 5370 - Denial of Service via Malformed CIP Forward Open Message
Details
Vulnerabilities 321