CWE-1284

Improper Validation of Specified Quantity in Input

Parent: CWE-20 - Improper Input Validation

The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

321 vulnerabilities with CWE-1284
CVE-2024-6768 MEDIUM
Windows 10, 11, Server 2016, 2019, 2022 - Authenticated Denial of Service via CLFS.sys KeBugCheckEx Call
CVE-2024-41991 HIGH
Django 4.2-4.2.14 and 5.0-5.0.7 - Denial of Service via Unicode Character Input
CVSS 7.5
CVE-2024-31957 MEDIUM
Samsung Mobile Processors Exynos 2200-2400 - DoS
CVSS 6.2
CVE-2024-27362 MEDIUM
Samsung Mobile Processors - Info Disclosure
CVSS 4.4
CVE-2024-27360 MEDIUM
Samsung Exynos 850 1080 2100 2200 1280 1380 1330 W930 Firmware - Denial of Service via Improper Length Validation
CVSS 6.0
CVE-2024-39697 HIGH
phonenumber 0.3.4-0.3.5 - Denial of Service via Malformed Phone Number String
CVSS 8.6
CVE-2024-3036 MEDIUM
ABB 800xA Base 6.0.0-6.1.1-2 - Denial of Service via Crafted Messages
CVSS 5.7
CVE-2024-38659 HIGH
Linux Kernel - Out-of-Bounds Read via enic_set_vf_port Netlink Attribute Length Validation
CVSS 7.1
CVE-2024-5102 HIGH
Avast Antivirus <24.2 - Privilege Escalation
CVSS 7.0
CVE-2024-35965 HIGH
Linux Kernel 2.6.39-5.10.226, 5.11.0-6.1.86, 6.2.0-6.6.54, 6.7.0-6.8.6 - Integer Overflow via Bluetooth L2CAP setsockopt
CVSS 7.1
CVE-2024-35964 HIGH
Linux Kernel 6.0-6.1.118, 6.2-6.6.54, 6.7-6.8.6 - Improper Input Validation in Bluetooth ISO Setsockopt
CVSS 7.1
CVE-2024-35963 HIGH
Linux Kernel 5.16-6.1.112, 6.2-6.6.54, 6.7-6.8.6 - Improper Input Validation in Bluetooth HCI Socket Setsockopt
CVSS 7.1
CVE-2024-30527 HIGH
Tips and Tricks HQ WP Express Checkout <2.3.7 - Info Disclosure
CVSS 7.5
CVE-2024-24715 MEDIUM
The Events Calendar BookIt <2.4.0 - Info Disclosure
CVSS 6.5
CVE-2024-3317 MEDIUM
Identity Security Cloud - Info Disclosure
CVSS 6.5
CVE-2024-3185 MEDIUM
Rapid7 Platform - Privilege Escalation
CVSS 6.8
CVE-2024-23593 MEDIUM
Lenovo Preloaded Windows - Privilege Escalation
CVSS 6.7
CVE-2024-24690 MEDIUM
Zoom < 5.16.5 - Authenticated Denial of Service via Network Input
CVSS 5.4
CVE-2023-54337 CRITICAL
Sysax Multi Server 6.95 - Denial of Service via Administrative Password Field Overflow
CVSS 9.1
CVE-2023-7332 HIGH
PocketMine-MP < 4.18.1 - Denial of Service via Inventory Transaction Handling
CVE-2023-20508 MEDIUM
AMD Radeon RX 6000 Series Graphics Products - Out-of-Bounds Write via ASP
CVSS 5.0
CVE-2023-31331 LOW
AMD Ryzen Processors - Stack Memory Corruption via Multiple Driver Initializations
CVSS 3.0
CVE-2023-20582 MEDIUM
AMD EPYC 9004 Processors - Improper Validation of Specified Quantity in Input
CVSS 5.3
CVE-2023-20581 LOW
AMD EPYC 9004 Processors - Improper Access Control in IOMMU
CVSS 2.5
CVE-2023-20515 MEDIUM
AMD Ryzen 3000/4000/5000/7000 and Athlon 3000 Series Desktop Processors - Memory Corruption via fTPM Driver
CVSS 5.7
Details
Vulnerabilities 321