CWE-1284

Improper Validation of Specified Quantity in Input

Parent: CWE-20 - Improper Input Validation

The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

364 vulnerabilities with CWE-1284
CVE-2025-54515 LOW
Versal Adaptive SoC - Privilege Escalation
CVE-2025-48507 HIGH
AMD Kria SOM Zynq UltraScale+ MPSoCs and RFSoCs - Improper Validation of Specified Quantity in Input
CVE-2025-9316 MEDIUM
N-central <2025.4 - Info Disclosure
CVE-2025-10259 MEDIUM
Mitsubishi Electric MELSEC iQ-F - DoS
CVSS 5.3
CVE-2025-36092 MEDIUM
IBM Cloud Pak for Business Automation DoS via Improper Input Length Validation
CVSS 6.5
CVE-2025-11568 MEDIUM
Latchset luksmeta - Data Corruption via Metadata Overflow in LUKS1 Format
CVSS 4.4
CVE-2025-61938 HIGH
F5 BIG-IP Advanced WAF and ASM 17.1.0-17.1.3 - Denial of Service via Data Guard Protection Enforcement URL Length
CVSS 7.5
CVE-2025-11594 MEDIUM
ywxbear PHP-Bookstore-Website-Example <0e0b9f542f7a2d90a8d7f8c83cac...
CVSS 5.3
CVE-2025-0038 MEDIUM
AMD Zynq UltraScale+ - Memory Corruption
CVSS 6.6
CVE-2025-43793 HIGH
Liferay Portal <7.4.3.105 - Info Disclosure
CVSS 7.5
CVE-2025-2256 HIGH
GitLab 7.12-18.1.5, 18.2-18.2.5, 18.3-18.3.1 - Denial of Service via Large SAML Responses
CVSS 7.5
CVE-2025-10094 MEDIUM
GitLab CE/EE <18.1.6-18.3.2 - Privilege Escalation
CVSS 6.5
CVE-2025-32689 HIGH
ThemesGrove WP SmartPay <2.7.13 - Info Disclosure
CVSS 7.5
CVE-2025-39700 MEDIUM
Linux Kernel - Privilege Escalation
CVSS 5.5
CVE-2025-58835 MEDIUM
calliko Bonus for Woo <7.4.1 - Info Disclosure
CVSS 5.3
CVE-2025-5808 HIGH
OpenText Self Service Password Reset <4.8.3 - Auth Bypass
CVE-2025-8424 HIGH
NetScaler ADC & Gateway - Info Disclosure
CVE-2025-55398 CRITICAL
mouse07410 asn1c thru 0.9.29 - Improper Validation of Specified Quantity in UPER Decoder
CVSS 9.8
CVE-2025-8320 HIGH
Tesla Wall Connector Firmware < 24.44.3 - Unauthenticated Remote Code Execution via HTTP Content-Length Header
CVSS 8.8
CVE-2025-43881 MEDIUM
Real-time Bus Tracking System <1.1 - DoS
CVSS 4.3
CVE-2025-41100 MEDIUM
ParkingDoor >=2016.08.11.1 <2016.08.11.1 - Unauthenticated Incorrect Authentication Bypass
CVE-2025-5349 HIGH
NetScaler ADC & Gateway - Info Disclosure
CVSS 8.8
CVE-2025-4365 HIGH
Citrix NetScaler Console and NetScaler SDX - Arbitrary File Read
CVSS 7.5
CVE-2025-49292 MEDIUM
Cozmoslabs Profile Builder <3.13.8 - Info Disclosure
CVSS 4.3
CVE-2025-5257 MEDIUM
Mautic 4.0.0-4.4.15, 4.4.16-5.4.5, 5.4.6-6.0.1 - Unauthenticated Unpublished Page Preview Access via Predictable URLs
CVSS 6.5
Details
Vulnerabilities 364