CWE-1286

Improper Validation of Syntactic Correctness of Input

Parent: CWE-20 - Improper Input Validation

The product receives input that is expected to be well-formed - i.e., to comply with a certain syntax - but it does not validate or incorrectly validates that the input complies with the syntax.

88 vulnerabilities with CWE-1286
CVE-2023-28985 HIGH
Juniper Junos - Denial of Service via Malformed SSL Packet in IDP
CVSS 7.5
CVE-2023-27043 MEDIUM
Python <3.11.3 - Info Disclosure
CVSS 5.3
CVE-2022-22192 HIGH
Juniper Networks Junos OS Evolved - DoS
CVSS 7.5
CVE-2022-1941 HIGH
ProtocolBuffers <3.16.1-4.21.5 - DoS
CVSS 7.5
CVE-2022-22176 HIGH
Juniper Junos OS - Unauthenticated Denial of Service via Malformed DHCP Packet
CVSS 7.4
CVE-2021-4479 MEDIUM
Dräger Atlan A350 1.00-1.01 DoS via Medibus Interface
CVSS 4.0
CVE-2021-44695 MEDIUM
SIMATIC S7-1200 CPU and S7-PLCSIM Advanced Firmware - Denial of Service via Crafted Packets to Port 102/tcp
CVSS 4.9
CVE-2021-31988 HIGH
AXIS OS Multiple Versions - SMTP Header Injection via CRLF
CVSS 8.8
CVE-2021-31987 HIGH
Axis OS - SMTP Recipient Validation Bypass
CVSS 7.5
CVE-2021-28812 HIGH
QNAP Video Station < 5.5.4 - Remote Command Injection
CVSS 8.8
CVE-2020-16220 MEDIUM
PICiX C.02-C.03, PerformanceBridge Focal Point A.01 - Info Disclosure
CVSS 4.3
CVE-2019-25720 MEDIUM
Dräger SC Monitoring Devices DoS via Malformed Network Packet
CVSS 6.5
CVE-2019-25723 MEDIUM
Dräger Perseus A500 2.00-2.02 DoS via Medibus Interface
CVSS 4.0
Details
Vulnerabilities 88