CWE-130

Improper Handling of Length Parameter Inconsistency

Parent: CWE-240 - Improper Handling of Inconsistent Structural Elements

The product parses a formatted message or structure, but it does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data.

74 vulnerabilities with CWE-130
CVE-2025-48022 MEDIUM
Yokogawa Electric Corporation - DoS
CVSS 6.5
CVE-2026-22861 HIGH
Color Iccdev < 2.3.1.2 - Out-of-Bounds Write
CVSS 8.8
CVE-2026-22255 HIGH
iccDEV <2.3.1.2 - Buffer Overflow
CVSS 8.8
CVE-2026-22047 HIGH
Color Iccdev < 2.3.1.2 - Out-of-Bounds Write
CVSS 8.8
CVE-2026-22046 HIGH
iccDEV <2.3.1.2 - Buffer Overflow
CVSS 8.8
CVE-2025-14847 HIGHKEV
MongoDB Memory Disclosure (CVE-2025-14847) - Mongobleed
CVSS 7.5
CVE-2025-8531 MEDIUM
Mitsubishi Electric MELSEC-Q Series - Buffer Overflow
CVSS 6.8
CVE-2025-10458 HIGH
Product Name - Info Disclosure
CVSS 7.6
CVE-2025-26432 MEDIUM
Google Android - Denial of Service
CVSS 5.5
CVE-2025-5514 MEDIUM
Mitsubishi Electric MELSEC iQ-F Series - DoS
CVSS 5.3
CVE-2025-54646 MEDIUM
BLE Module - Info Disclosure
CVSS 5.1
CVE-2023-53157 MEDIUM
Rosenpass < 0.2.1 - Denial of Service
CVSS 5.3
CVE-2025-52949 MEDIUM
Juniper Junos < 21.4 - Denial of Service
CVSS 6.5
CVE-2025-53604 MEDIUM
Web-Push <0.10.3 - DoS
CVSS 4.0
CVE-2025-23247 MEDIUM
NVIDIA CUDA Toolkit - Buffer Overflow
CVSS 4.4
CVE-2025-29784 HIGH
Nameless < 2.2.0 - Denial of Service
CVSS 7.5
CVE-2025-29931 LOW
TeleControl Server Basic < V3.1.2.2 - Memory Corruption
CVSS 3.7
CVE-2025-30659 HIGH
Juniper Junos - Denial of Service
CVSS 7.5
CVE-2025-32366 MEDIUM
ConnMan <1.44 - Buffer Overflow
CVSS 4.8
CVE-2024-53856 HIGH
rPGP <0.14.1 - Use After Free
CVSS 7.5
CVE-2024-47293 MEDIUM
HAL-WIFI - Buffer Overflow
CVSS 4.7
CVE-2024-41991 HIGH
Django <5.0.8, <4.2.15 - DoS
CVSS 7.5
CVE-2024-41990 HIGH
Django <5.0.8, <4.2.15 - DoS
CVSS 7.5
CVE-2024-42460 MEDIUM
Elliptic 6.5.6 - Info Disclosure
CVSS 5.3
CVE-2024-20416 MEDIUM
Cisco RV340-345 - RCE
CVSS 6.5
Details
Vulnerabilities 74