CWE-1284

Improper Validation of Specified Quantity in Input

Parent: CWE-20 - Improper Input Validation

The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

364 vulnerabilities with CWE-1284
CVE-2024-1610 CRITICAL
OPPO Store APP - Privilege Escalation
CVSS 9.8
CVE-2024-52901 MEDIUM
IBM InfoSphere Information Server 11.7 - Info Disclosure
CVSS 6.5
CVE-2024-7488 MEDIUM
RestApp Inc. Online Ordering System <8.2.2 - Integer Overflow
CVSS 5.3
CVE-2024-39343 HIGH
Samsung Exynos and Modem Firmware - Denial of Service via MM Module Length Mismatch
CVSS 7.0
CVE-2024-9369 CRITICAL
Google Chrome < 129.0.6668.89 - Out of Bounds Memory Write via Mojo
CVSS 9.6
CVE-2024-47257 HIGH
AXIS Q6128-E and P1428-E Network Cameras 6.50 - Denial of Service via Ethernet Frame Handling
CVSS 7.5
CVE-2024-6068 HIGH
Rockwell Automation Arena Input Analyzer <= 16.20.03 - Memory Corruption via DFT File Parsing
CVSS 7.3
CVE-2024-48290 MEDIUM
Realtek RTL8762E BLE SDK <1.4.0 - DoS
CVSS 4.3
CVE-2024-7316 MEDIUM
Mitsubishi Electric CNC Series - DoS
CVSS 5.9
CVE-2024-8508 MEDIUM
Unbound <= 1.21.0 - Denial of Service via Malicious RRset Name Compression
CVSS 5.3
CVE-2024-8887 CRITICAL
CIRCUTOR Q-SMT Firmware 1.0.4 - Denial of Service via Authentication Bypass
CVSS 10.0
CVE-2024-5931 MEDIUM
Zephyr < 3.6.0 - Improper Validation of Specified Quantity in Input via BT Broadcast Assistant
CVSS 6.3
CVE-2024-31416 MEDIUM
Eaton Foreseer Electrical Power Monitoring System < 7.8.600 - Integer Overflow via Unbounded Input Fields
CVSS 5.6
CVE-2024-8558 MEDIUM
SourceCodester Food Ordering Management System 1.0 - Info Disclosure
CVSS 4.3
CVE-2024-42416 HIGH
FreeBSD 13.0-13.2 - Use-After-Free in ctl_report_supported_opcodes
CVSS 8.8
CVE-2024-0111 MEDIUM
NVIDIA CUDA Toolkit < 12.6.0 - Denial of Service via Malformed ELF File in cuobjdump
CVSS 4.4
CVE-2024-6768 MEDIUM
Windows 10, 11, Server 2016, 2019, 2022 - Authenticated Denial of Service via CLFS.sys KeBugCheckEx Call
CVE-2024-41991 HIGH
Django 4.2-4.2.14 and 5.0-5.0.7 - Denial of Service via Unicode Character Input
CVSS 7.5
CVE-2024-31957 MEDIUM
Samsung Mobile Processors Exynos 2200-2400 - DoS
CVSS 6.2
CVE-2024-27362 MEDIUM
Samsung Mobile Processors - Info Disclosure
CVSS 4.4
CVE-2024-27360 MEDIUM
Samsung Exynos 850 1080 2100 2200 1280 1380 1330 W930 Firmware - Denial of Service via Improper Length Validation
CVSS 6.0
CVE-2024-39697 HIGH
phonenumber 0.3.4-0.3.5 - Denial of Service via Malformed Phone Number String
CVSS 8.6
CVE-2024-3036 MEDIUM
ABB 800xA Base 6.0.0-6.1.1-2 - Denial of Service via Crafted Messages
CVSS 5.7
CVE-2024-38659 HIGH
Linux Kernel - Out-of-Bounds Read via enic_set_vf_port Netlink Attribute Length Validation
CVSS 7.1
CVE-2024-5102 HIGH
Avast Antivirus <24.2 - Privilege Escalation
CVSS 7.0
Details
Vulnerabilities 364