The product receives input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.
146 vulnerabilities with CWE-1287
CVE-2023-32651
MEDIUM
Intel PROSet/Wireless and Killer Wi-Fi < 22.240 - Unauthenticated Denial of Service via Adjacent Access
CVSS 4.3
CVE-2023-3904
MEDIUM
GitLab EE <16.4.4-16.5.4-16.6.2 - Buffer Overflow
CVSS 4.3
CVE-2023-3917
MEDIUM
GitLab < 16.2.8, 16.3 < 16.3.5, 16.4 < 16.4.1 - Denial of Service in Pipelines
CVSS 4.3
CVE-2023-3906
LOW
GitLab EE <16.2.8-16.4.1 - Auth Bypass
CVSS 3.5
CVE-2023-4522
MEDIUM
GitLab < 16.2.0 - Denial of Service via Directory Names with LF Characters
CVSS 4.3
CVE-2023-3900
MEDIUM
GitLab 16.1-16.1.3 and 16.2-16.2.2 - Denial of Service via Invalid 'start_sha' Value
CVSS 4.3
CVE-2023-28799
HIGH
Zscaler Client Connector < 1.4, < 1.9.3, < 1.10.1, < 1.10.2, < 3.7, < 3.9 - Open Redirect via Login URL Parameter
CVSS 8.2
CVE-2023-2431
LOW
Kubernetes < 1.24.14 - Seccomp Profile Enforcement Bypass via Empty Profile Field
CVSS 3.4
CVE-2023-2673
MEDIUM
PHOENIX CONTACT FL/TC MGUARD Family - UDP Packet Filter Bypass via Improper Input Validation
CVSS 5.3
CVE-2022-43723
HIGH
SICAM PAS/PQS < V7.0 or >= 7.0 < V8.06 - DoS
CVSS 7.5
CVE-2022-39369
HIGH
phpCAS <1.6.0 - Account Access via Host Header Service URL Confusion
CVSS 8.0
CVE-2022-22228
HIGH
Juniper Networks Junos OS <21.1R3-S2-21.4 - DoS
CVSS 7.5
CVE-2022-31007
MEDIUM
eLabFTW <4.3.0 - Privilege Escalation
CVSS 4.9
CVE-2022-20783
HIGH
Cisco TelePresence <9.15.10.8 & RoomOS <2022 - DoS via H.323
CVSS 7.5
CVE-2022-22168
MEDIUM
Juniper Junos OS < 19.1 - Unauthenticated Use-After-Free via Kernel Input Validation
CVSS 6.5
CVE-2021-47156
MEDIUM
Net::IPAddress::Util <5.000 - Info Disclosure
CVSS 6.5
CVE-2021-44694
MEDIUM
SIMATIC S7-1200 CPU and S7-PLCSIM Advanced Firmware - Denial of Service via Crafted Packets to Port 102/tcp
CVSS 5.5
CVE-2021-32024
CRITICAL
BlackBerry QNX SDP 6.4.0-7.1 - Remote Code Execution via BMP Image Codec
CVSS 9.8
CVE-2021-43802
CRITICAL
Etherpad <1.8.16 - Privilege Escalation
CVSS 9.9
CVE-2021-20329
MEDIUM
MongoDB GO Driver <1.5.0 - Code Injection
CVSS 6.8
CVE-2019-25596
MEDIUM
SpotAuditor 5.2.6 Name Field Denial of Service
CVSS 6.2
Details
Vulnerabilities
146