CWE-1284

Improper Validation of Specified Quantity in Input

Parent: CWE-20 - Improper Input Validation

The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

321 vulnerabilities with CWE-1284
CVE-2025-8424 HIGH
NetScaler ADC & Gateway - Info Disclosure
CVE-2025-55398 CRITICAL
mouse07410 asn1c thru 0.9.29 - Improper Validation of Specified Quantity in UPER Decoder
CVSS 9.8
CVE-2025-8320 HIGH
Tesla Wall Connector Firmware < 24.44.3 - Unauthenticated Remote Code Execution via HTTP Content-Length Header
CVSS 8.8
CVE-2025-43881 MEDIUM
Real-time Bus Tracking System <1.1 - DoS
CVSS 4.3
CVE-2025-41100 MEDIUM
ParkingDoor >=2016.08.11.1 <2016.08.11.1 - Unauthenticated Incorrect Authentication Bypass
CVE-2025-5349 HIGH
NetScaler ADC & Gateway - Info Disclosure
CVSS 8.8
CVE-2025-4365 HIGH
Citrix NetScaler Console and NetScaler SDX - Arbitrary File Read
CVSS 7.5
CVE-2025-49292 MEDIUM
Cozmoslabs Profile Builder <3.13.8 - Info Disclosure
CVSS 4.3
CVE-2025-5257 MEDIUM
Mautic 4.0.0-4.4.15, 4.4.16-5.4.5, 5.4.6-6.0.1 - Unauthenticated Unpublished Page Preview Access via Predictable URLs
CVSS 6.5
CVE-2025-2826 LOW
Arista Networks EOS >=4.33.2F <4.33.2F - Improper ACL Policy Enforcement
CVSS 2.6
CVE-2025-20151 MEDIUM
Cisco IOS XE SD-WAN - Authenticated SNMPv3 Access Control Bypass
CVSS 4.3
CVE-2025-32399 MEDIUM
RT-Labs P-Net < 1.0.2 - Denial of Service via Malicious RPC Packet
CVSS 5.3
CVE-2025-46656 LOW
python-markdownify <0.14.1 - Memory Consumption
CVSS 2.9
CVE-2025-3511 HIGH
Mitsubishi Electric Corporation CC-Link IE TSN - Info Disclosure
CVSS 7.5
CVE-2025-43972 MEDIUM
GoBGP < 3.35.0 - Denial of Service via Flowspec Parser Input Validation
CVSS 6.8
CVE-2025-43970 MEDIUM
GoBGP < 3.35.0 - Denial of Service via Improper Input Length Validation in MRT Packet Parser
CVSS 4.3
CVE-2025-43964 LOW
LibRaw < 0.21.4 - Denial of Service via Improper Validation of Tag 0x412
CVSS 2.9
CVE-2025-29784 HIGH
NamelessMC < 2.2.0 - Denial of Service via Forum Search Parameter Length
CVSS 7.5
CVE-2025-32415 LOW
libxml2 < 2.13.8 and 2.14.x < 2.14.2 - Heap-Based Buffer Under-Read in xmlSchemaIDCFillNodeTables
CVSS 2.9
CVE-2025-25178 HIGH
Software <version> - Memory Corruption
CVSS 7.8
CVE-2025-0286 HIGH
Paragon Software - Memory Corruption
CVSS 8.4
CVE-2025-0285 HIGH
Paragon Software - Privilege Escalation
CVSS 7.8
CVE-2025-24100 LOW
macOS Ventura <13.7.3 - Info Disclosure
CVSS 3.3
CVE-2024-21953 MEDIUM
AMD EPYC 9004, 8004, Embedded 9004 - Guest Data Integrity Loss via IOMMU Reconfiguration
CVE-2024-30516 HIGH
SaasProject Booking Package <1.6.27 - Info Disclosure
CVSS 7.5
Details
Vulnerabilities 321