CWE-1287

Improper Validation of Specified Type of Input

Parent: CWE-20 - Improper Input Validation

The product receives input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.

134 vulnerabilities with CWE-1287
CVE-2024-20494 HIGH
Cisco Adaptive Security Appliance Software - Denial of Service via TLS 1.3 Handshake
CVSS 8.6
CVE-2024-20408 HIGH
Cisco ASA Software DoS via Dynamic Access Policies HTTPS POST Request
CVSS 7.7
CVE-2024-47504 HIGH
Juniper Junos OS - Unauthenticated Denial of Service via Malformed Packet in Packet Forwarding Engine
CVSS 7.5
CVE-2024-1578 MEDIUM
rf IDEAS MiCard PLUS Ci/MiCard PLUS BLE - Info Disclosure
CVSS 5.3
CVE-2024-3175 MEDIUM
Google Chrome <120.0.6099.62 - Privilege Escalation
CVSS 6.3
CVE-2024-4879 CRITICAL KEV
ServiceNow Vancouver and Washington DC - Unauthenticated Remote Code Execution
CVSS 9.8
CVE-2024-6298 CRITICAL
ABB ASPECT Enterprise, NEXUS Series, MATRIX Series <3.08.01 - Unauthorized File Access
CVSS 10.0
CVE-2024-35213 CRITICAL
QNX Software Development Platform 6.6-7.1 - Denial of Service or Remote Code Execution in SGI Image Codec
CVSS 9.0
CVE-2024-30395 HIGH
Junos OS and Junos OS Evolved - Unauthenticated Denial of Service via Malformed BGP Tunnel Encapsulation TLV
CVSS 7.5
CVE-2024-31948 MEDIUM
FRRouting < 9.1 - Denial of Service via Malformed Prefix SID Attribute in BGP UPDATE Packet
CVSS 6.5
CVE-2023-29126 MEDIUM
Enel X Waybox Pro Firmware < 2.1.1.0_jb3vu096a - Authentication Bypass via PHP Type Juggling
CVSS 4.2
CVE-2023-47726 HIGH
IBM QRadar Suite Software <1.10.21.0 - Command Injection
CVSS 7.1
CVE-2023-47727 MEDIUM
IBM Cloud Pak for Security <1.10.11.0 & QRadar Suite Software <1.10...
CVSS 4.3
CVE-2023-32651 MEDIUM
Intel PROSet/Wireless and Killer Wi-Fi < 22.240 - Unauthenticated Denial of Service via Adjacent Access
CVSS 4.3
CVE-2023-3904 MEDIUM
GitLab EE <16.4.4-16.5.4-16.6.2 - Buffer Overflow
CVSS 4.3
CVE-2023-3917 MEDIUM
GitLab < 16.2.8, 16.3 < 16.3.5, 16.4 < 16.4.1 - Denial of Service in Pipelines
CVSS 4.3
CVE-2023-3906 LOW
GitLab EE <16.2.8-16.4.1 - Auth Bypass
CVSS 3.5
CVE-2023-4522 MEDIUM
GitLab < 16.2.0 - Denial of Service via Directory Names with LF Characters
CVSS 4.3
CVE-2023-3900 MEDIUM
GitLab 16.1-16.1.3 and 16.2-16.2.2 - Denial of Service via Invalid 'start_sha' Value
CVSS 4.3
CVE-2023-28799 HIGH
Zscaler Client Connector < 1.4, < 1.9.3, < 1.10.1, < 1.10.2, < 3.7, < 3.9 - Open Redirect via Login URL Parameter
CVSS 8.2
CVE-2023-2431 LOW
Kubernetes < 1.24.14 - Seccomp Profile Enforcement Bypass via Empty Profile Field
CVSS 3.4
CVE-2023-2673 MEDIUM
PHOENIX CONTACT FL/TC MGUARD Family - UDP Packet Filter Bypass via Improper Input Validation
CVSS 5.3
CVE-2022-43723 HIGH
SICAM PAS/PQS < V7.0 or >= 7.0 < V8.06 - DoS
CVSS 7.5
CVE-2022-39369 HIGH
phpCAS <1.6.0 - Account Access via Host Header Service URL Confusion
CVSS 8.0
CVE-2022-22228 HIGH
Juniper Networks Junos OS <21.1R3-S2-21.4 - DoS
CVSS 7.5
Details
Vulnerabilities 134