CWE-1284

Improper Validation of Specified Quantity in Input

Parent: CWE-20 - Improper Input Validation

The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

364 vulnerabilities with CWE-1284
CVE-2025-12664 HIGH
Improper Validation of Specified Quantity in Input in GitLab
CVSS 7.5
CVE-2025-13078 MEDIUM
Improper Validation of Specified Quantity in Input in GitLab
CVSS 6.5
CVE-2025-14513 HIGH
GitLab 16.11-18.7.5, 18.8-18.8.5, 18.9-18.9.1 - DoS via Protected Branches API
CVSS 7.5
CVE-2025-14511 HIGH
GitLab 12.2-18.7.4, 18.8-18.8.4, 18.9-18.9.0 - Unauthenticated Denial of Service via Container Registry Event Endpoint
CVSS 7.5
CVE-2025-14689 MEDIUM
IBM Db2 12.1.0-12.1.3 - Authenticated Denial of Service via Federated Object Query Logic
CVSS 6.5
CVE-2025-13867 MEDIUM
IBM Db2 11.5.0-11.5.9/12.1.0-12.1.3 - DoS
CVSS 6.5
CVE-2025-52534 MEDIUM
AMD CPU microcode - Memory Corruption
CVE-2025-15080 HIGH
Mitsubishi Electric MELSEC iQ-R Series - Info Disclosure
CVE-2025-36094 MEDIUM
IBM Cloud Pak for Business Automation <25.0.0-24.0.1 - DoS
CVSS 5.4
CVE-2025-36428 MEDIUM
IBM Db2 11.5.0-11.5.9 and 12.1.0-12.1.3 - Authenticated Denial of Service via RPSCAN Feature
CVSS 5.3
CVE-2025-36427 MEDIUM
IBM Db2 11.5.0-11.5.8 - Denial of Service via Insufficient Data Query Validation
CVSS 6.5
CVE-2025-36424 MEDIUM
IBM Db2 11.5.0-11.5.8 - Denial of Service via Improper Data Query Logic Neutralization
CVSS 6.5
CVE-2025-36423 MEDIUM
IBM Db2 12.1.0-12.1.3 - Denial of Service via Data Query Logic
CVSS 6.5
CVE-2025-36407 MEDIUM
IBM Db2 11.5.0-11.5.8 - Denial of Service via ALTER TABLE Query
CVSS 6.5
CVE-2025-36009 MEDIUM
IBM Db2 11.5.0-11.5.8 - Authenticated Denial of Service via Global Variable Exhaustion
CVSS 6.5
CVE-2025-11743 HIGH
Rockwell Automation CompactLogix 5370 - Denial of Service via Malformed CIP Forward Open Message
CVE-2025-10933 MEDIUM
Silicon Labs Z-Wave Protocol Controller - Memory Corruption
CVE-2025-68383 MEDIUM
Filebeat 7.0.0-7.17.28 and 7.7.0-8.19.8 - Denial of Service via Malformed Syslog Message or Dissect Tokenizer Pattern
CVSS 6.5
CVE-2025-67901 MEDIUM
openrsync <0.5.0 - Memory Corruption
CVSS 5.3
CVE-2025-36015 MEDIUM
IBM Cognos Controller 11.0.0-11.0.1 FP6 & 11.1.0-11.1.1 Authenticated DoS via Input Validation
CVSS 6.5
CVE-2025-65548 CRITICAL
cashu/nutshell < 0.18.0 - Denial of Service via Unvalidated Preimage Size
CVSS 9.1
CVE-2025-12385 HIGH
Qt <6.5.10, <6.8.5, <6.9.0 - Improper Validation of Specified Quant...
CVE-2025-33211 HIGH
NVIDIA Triton Inference Server < 25.10 - Denial of Service via Improper Input Quantity Validation
CVSS 7.5
CVE-2025-59820 MEDIUM
KDE Krita <5.2.13 - Buffer Overflow
CVSS 6.7
CVE-2025-13507 MEDIUM
MongoDB <7.0.26-8.0.16-8.2.1 - Memory Corruption
CVSS 6.5
Details
Vulnerabilities 364