CWE-1284

Improper Validation of Specified Quantity in Input

Parent: CWE-20 - Improper Input Validation

The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

364 vulnerabilities with CWE-1284
CVE-2025-2826 LOW
Arista Networks EOS >=4.33.2F <4.33.2F - Improper ACL Policy Enforcement
CVSS 2.6
CVE-2025-20151 MEDIUM
Cisco IOS XE SD-WAN - Authenticated SNMPv3 Access Control Bypass
CVSS 4.3
CVE-2025-32399 MEDIUM
RT-Labs P-Net < 1.0.2 - Denial of Service via Malicious RPC Packet
CVSS 5.3
CVE-2025-46656 LOW
python-markdownify <0.14.1 - Memory Consumption
CVSS 2.9
CVE-2025-3511 HIGH
Mitsubishi Electric Corporation CC-Link IE TSN - Info Disclosure
CVSS 7.5
CVE-2025-43972 MEDIUM
GoBGP < 3.35.0 - Denial of Service via Flowspec Parser Input Validation
CVSS 6.8
CVE-2025-43970 MEDIUM
GoBGP < 3.35.0 - Denial of Service via Improper Input Length Validation in MRT Packet Parser
CVSS 4.3
CVE-2025-43964 LOW
LibRaw < 0.21.4 - Denial of Service via Improper Validation of Tag 0x412
CVSS 2.9
CVE-2025-29784 HIGH
NamelessMC < 2.2.0 - Denial of Service via Forum Search Parameter Length
CVSS 7.5
CVE-2025-32415 LOW
libxml2 < 2.13.8 and 2.14.x < 2.14.2 - Heap-Based Buffer Under-Read in xmlSchemaIDCFillNodeTables
CVSS 2.9
CVE-2025-25178 HIGH
Software <version> - Memory Corruption
CVSS 7.8
CVE-2025-0286 HIGH
Paragon Software - Memory Corruption
CVSS 8.4
CVE-2025-0285 HIGH
Paragon Software - Privilege Escalation
CVSS 7.8
CVE-2025-24100 LOW
macOS Ventura <13.7.3 - Info Disclosure
CVSS 3.3
CVE-2024-21953 MEDIUM
AMD EPYC 9004, 8004, Embedded 9004 - Guest Data Integrity Loss via IOMMU Reconfiguration
CVE-2024-30516 HIGH
SaasProject Booking Package <1.6.27 - Info Disclosure
CVSS 7.5
CVE-2024-36346 MEDIUM
AMD Instinct MI300A and MI300X - Denial of Service via Power Management Firmware Input Validation
CVSS 6.0
CVE-2024-9448 HIGH
Arista EOS 4.30.0-4.30.7M, 4.31.0-4.31.4M, 4.32.0-4.32.2M, 4.33.0 - Traffic Policy Bypass via Untagged Packet Handling
CVSS 7.5
CVE-2024-45351 HIGH
Xiaomi Game center application - Remote Code Execution via Improper Input Validation
CVSS 7.8
CVE-2024-8000 MEDIUM
Arista EOS 4.30.0-4.30.7M, 4.31.0-4.31.4M, 4.32.0-4.32.3M - Improper Validation of Specified Quantity in Input
CVSS 5.3
CVE-2024-53879 LOW
NVIDIA CUDA Toolkit < 12.8.0 - Denial of Service via Malformed ELF File in cuobjdump
CVSS 2.8
CVE-2024-53878 LOW
NVIDIA CUDA Toolkit < 12.8.0 - Denial of Service via Malformed ELF File in cuobjdump
CVSS 2.8
CVE-2024-55407 HIGH
ITE Tech. Inc. ITE IO Access <1.0.0.0 - RCE
CVSS 7.8
CVE-2024-20149 HIGH
MediaTek LR12/LR13/NR15/NR16/NR17 - Denial of Service via Improper Input Validation
CVSS 7.5
CVE-2024-56716 MEDIUM
Linux Kernel 5.5-6.12.7 DoS via nsim_dev_health_break_write Input Validation
CVSS 5.5
Details
Vulnerabilities 364