CWE-1286

Improper Validation of Syntactic Correctness of Input

Parent: CWE-20 - Improper Input Validation

The product receives input that is expected to be well-formed - i.e., to comply with a certain syntax - but it does not validate or incorrectly validates that the input complies with the syntax.

79 vulnerabilities with CWE-1286
CVE-2024-39542 HIGH
Juniper Junos OS and Junos OS Evolved - Unauthenticated Denial-of-Service via Malformed CFM Packet or Transit Traffic
CVSS 7.5
CVE-2024-6284 HIGH
google/nftables 0.1.0 - Improper Validation of Syntactic Correctness of Input
CVSS 7.3
CVE-2024-26507 HIGH
FinalWire AIRDA Extreme <7.00.6700 - Privilege Escalation
CVSS 7.8
CVE-2024-21598 HIGH
Juniper Junos OS and Junos OS Evolved - Unauthenticated Denial of Service via Malformed BGP Tunnel Encapsulation TLV
CVSS 7.5
CVE-2024-3384 HIGH
Palo Alto Networks PAN-OS - NTLM Packet Denial of Service
CVSS 7.5
CVE-2024-0218 HIGH
Nozomi Networks Guardian < 23.4.1 - Unauthenticated Denial of Service via Radius Parsing
CVSS 7.5
CVE-2024-29041 MEDIUM
Express.js < 4.19.2 - Open Redirect via Malformed URL Bypass
CVSS 6.1
CVE-2024-21616 HIGH
Juniper Junos OS - Unauthenticated Denial of Service via SIP ALG Packet Processing
CVSS 7.5
CVE-2024-21595 HIGH
Juniper Junos OS - Unauthenticated Denial of Service via High-Rate ICMP Traffic to VXLAN
CVSS 7.5
CVE-2023-43850 MEDIUM
Aten PE6208 <2.4.232 - Info Disclosure
CVSS 6.5
CVE-2023-6950 LOW
DJI Mini 3 Pro < 01.00.1200 - Denial of Service via FTP SIZE Command Path
CVSS 3.0
CVE-2023-44204 MEDIUM
Juniper Junos OS and Junos OS Evolved - Unauthenticated Denial of Service via Malformed BGP UPDATE Packet
CVSS 6.5
CVE-2023-32649 HIGH
Nozomi Networks CMC and Guardian 22.6.0-22.6.2 - Unauthenticated Denial of Service via Malformed Network Packets
CVSS 7.5
CVE-2023-24015 MEDIUM
Nozomi Networks CMC and Guardian < 22.6.2 - Authenticated Partial Denial of Service via Report Name Null Value
CVSS 4.3
CVE-2023-23903 MEDIUM
Nozomi Networks Guardian and CMC - Denial of Service via Malformed SAML Configuration
CVSS 4.9
CVE-2023-21405 MEDIUM
Axis Network Door Controllers/Intercoms - DoS
CVSS 6.5
CVE-2023-28985 HIGH
Juniper Junos - Denial of Service via Malformed SSL Packet in IDP
CVSS 7.5
CVE-2023-27043 MEDIUM
Python <3.11.3 - Info Disclosure
CVSS 5.3
CVE-2022-22192 HIGH
Juniper Networks Junos OS Evolved - DoS
CVSS 7.5
CVE-2022-1941 HIGH
ProtocolBuffers <3.16.1-4.21.5 - DoS
CVSS 7.5
CVE-2022-22176 HIGH
Juniper Junos OS - Unauthenticated Denial of Service via Malformed DHCP Packet
CVSS 7.4
CVE-2021-4479 MEDIUM
Dräger Atlan A350 1.00-1.01 DoS via Medibus Interface
CVSS 4.0
CVE-2021-44695 MEDIUM
SIMATIC S7-1200 CPU and S7-PLCSIM Advanced Firmware - Denial of Service via Crafted Packets to Port 102/tcp
CVSS 4.9
CVE-2021-31988 HIGH
AXIS OS Multiple Versions - SMTP Header Injection via CRLF
CVSS 8.8
CVE-2021-31987 HIGH
Axis OS - SMTP Recipient Validation Bypass
CVSS 7.5
Details
Vulnerabilities 79