CWE-1284

Improper Validation of Specified Quantity in Input

Parent: CWE-20 - Improper Input Validation

The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

321 vulnerabilities with CWE-1284
CVE-2023-20704 MEDIUM
Android - Local Information Disclosure via Missing Bounds Check in APU
CVSS 5.5
CVE-2023-27961 MEDIUM
iPadOS < 15.7.4 - Information Exfiltration via Malicious Calendar Invitation
CVSS 5.5
CVE-2023-27941 MEDIUM
iPadOS < 15.7.4 - Kernel Memory Disclosure via Input Validation Issue
CVSS 5.5
CVE-2023-30269 HIGH
cltphp <=6.0 - Improper Input Validation in Template Controller
CVSS 8.1
CVE-2023-0195 LOW
NVIDIA GPU Display Driver - Info Disclosure
CVSS 2.0
CVE-2023-0194 LOW
NVIDIA Virtual GPU < 11.12 - Denial of Service via Invalid Display Configuration
CVSS 2.0
CVE-2023-23626 MEDIUM
go-bitfield < 1.1.0 - Denial of Service via Invalid Size Parameter in NewBitfield and FromBytes
CVSS 5.9
CVE-2023-22409 MEDIUM
Juniper Junos OS Multiple Versions - Authenticated DoS via NAT Configuration CLI
CVSS 5.5
CVE-2022-50020 MEDIUM
Linux Kernel - Denial of Service via Unaligned Cluster Boundary Resize
CVSS 5.5
CVE-2022-25769 HIGH
Mautic < 3.3.5 - Unauthenticated Arbitrary PHP File Execution via .htaccess Bypass
CVSS 7.2
CVE-2022-47029 HIGH
Action Launcher <50.5 - Privilege Escalation
CVSS 7.8
CVE-2022-4904 HIGH
c-ares < 1.19.0 - Denial of Service via ares_set_sortlist Input Validation
CVSS 8.6
CVE-2022-3411 MEDIUM
GitLab 12.4-15.6.6, 15.7-15.7.5, 15.8-15.8.0 - Authenticated Denial of Service via Large Issue Description
CVSS 6.5
CVE-2022-48298 HIGH
Huawei EMUI and HarmonyOS - Out-of-Bounds Memory Access via Geofencing Kernel Input
CVSS 7.5
CVE-2022-48297 HIGH
Huawei EMUI and HarmonyOS - Out-of-Bounds Memory Access via Geofencing Kernel Input Length
CVSS 7.5
CVE-2022-20493 HIGH
Android - Local Privilege Escalation via Notification Access Input Validation
CVSS 7.8
CVE-2022-37312 MEDIUM
OX App Suite <7.10.6 - DoS
CVSS 5.3
CVE-2022-37311 MEDIUM
OX App Suite <7.10.6 - DoS
CVSS 5.3
CVE-2022-20543 LOW
Android 13 - Denial of Service via Improper Input Validation
CVSS 2.3
CVE-2022-4171 MEDIUM
WordPress demon image annotation <5.0 - Info Disclosure
CVSS 6.5
CVE-2022-46143 LOW
Siemens Ruggedcom RM1224 LTE and Scalance Devices - Uninitialized Buffer Read via TFTP Blocksize Mismatch
CVSS 2.7
CVE-2022-20491 HIGH
Android - Local Privilege Escalation via NotificationChannel Resource Exhaustion
CVSS 7.8
CVE-2022-20488 HIGH
Android - Local Privilege Escalation via NotificationChannel Resource Exhaustion
CVSS 7.8
CVE-2022-20691 MEDIUM
Cisco ATA 190 Series Firmware - Unauthenticated Denial of Service via Cisco Discovery Protocol Packet Header
CVSS 5.3
CVE-2022-20690 MEDIUM
Cisco ATA 190 Series - Memory Corruption
CVSS 5.3
Details
Vulnerabilities 321