CWE-1286

Improper Validation of Syntactic Correctness of Input

Parent: CWE-20 - Improper Input Validation

The product receives input that is expected to be well-formed - i.e., to comply with a certain syntax - but it does not validate or incorrectly validates that the input complies with the syntax.

88 vulnerabilities with CWE-1286
CVE-2025-0638 HIGH
Routinator >=0.14.1 - Denial of Service via Manifest File Name Parsing
CVSS 7.5
CVE-2024-51983 HIGH
Brother Printers <1.68 Unauthenticated DoS via WS-Scan SOAP Request
CVSS 7.5
CVE-2024-51982 HIGH
Brother Printer Devices - Denial of Service via Malformed PJL Command
CVSS 7.5
CVE-2024-52362 MEDIUM
IBM App Connect Enterprise Certified Container - DoS
CVSS 4.3
CVE-2024-8772 MEDIUM
AXIS OS 9.80.0-9.80.83, 10.0.0-10.12.248, 11.0.0-11.11.117, 12.0.0-12.1.27 - DoS via VAPIX API Race Condition
CVSS 4.3
CVE-2024-8160 LOW
Axis ftptest.cgi - Command Injection
CVSS 3.8
CVE-2024-6763 LOW
Eclipse Jetty 7.0.0-9.4.56 & 12.0.0-12.0.11 - Open Redirect & SSRF via HttpURI Authority
CVSS 3.7
CVE-2024-6173 MEDIUM
AXIS OS - Denial of Service via Guard Tour VAPIX API Parameter
CVSS 6.5
CVE-2024-7954 CRITICAL
SPIP porte_plume - Unauthenticated PHP Code Execution
CVSS 9.8
CVE-2024-39542 HIGH
Juniper Junos OS and Junos OS Evolved - Unauthenticated Denial-of-Service via Malformed CFM Packet or Transit Traffic
CVSS 7.5
CVE-2024-6284 HIGH
google/nftables 0.1.0 - Improper Validation of Syntactic Correctness of Input
CVSS 7.3
CVE-2024-26507 HIGH
FinalWire AIRDA Extreme <7.00.6700 - Privilege Escalation
CVSS 7.8
CVE-2024-21598 HIGH
Juniper Junos OS and Junos OS Evolved - Unauthenticated Denial of Service via Malformed BGP Tunnel Encapsulation TLV
CVSS 7.5
CVE-2024-3384 HIGH
Palo Alto Networks PAN-OS - NTLM Packet Denial of Service
CVSS 7.5
CVE-2024-0218 HIGH
Nozomi Networks Guardian < 23.4.1 - Unauthenticated Denial of Service via Radius Parsing
CVSS 7.5
CVE-2024-29041 MEDIUM
Express.js < 4.19.2 - Open Redirect via Malformed URL Bypass
CVSS 6.1
CVE-2024-21616 HIGH
Juniper Junos OS - Unauthenticated Denial of Service via SIP ALG Packet Processing
CVSS 7.5
CVE-2024-21595 HIGH
Juniper Junos OS - Unauthenticated Denial of Service via High-Rate ICMP Traffic to VXLAN
CVSS 7.5
CVE-2023-43850 MEDIUM
Aten PE6208 <2.4.232 - Info Disclosure
CVSS 6.5
CVE-2023-6950 LOW
DJI Mini 3 Pro < 01.00.1200 - Denial of Service via FTP SIZE Command Path
CVSS 3.0
CVE-2023-44204 MEDIUM
Juniper Junos OS and Junos OS Evolved - Unauthenticated Denial of Service via Malformed BGP UPDATE Packet
CVSS 6.5
CVE-2023-32649 HIGH
Nozomi Networks CMC and Guardian 22.6.0-22.6.2 - Unauthenticated Denial of Service via Malformed Network Packets
CVSS 7.5
CVE-2023-24015 MEDIUM
Nozomi Networks CMC and Guardian < 22.6.2 - Authenticated Partial Denial of Service via Report Name Null Value
CVSS 4.3
CVE-2023-23903 MEDIUM
Nozomi Networks Guardian and CMC - Denial of Service via Malformed SAML Configuration
CVSS 4.9
CVE-2023-21405 MEDIUM
Axis Network Door Controllers/Intercoms - DoS
CVSS 6.5
Details
Vulnerabilities 88