CWE-130

Improper Handling of Length Parameter Inconsistency

Parent: CWE-240 - Improper Handling of Inconsistent Structural Elements

The product parses a formatted message or structure, but it does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data.

93 vulnerabilities with CWE-130
CVE-2025-8531 MEDIUM
Mitsubishi Electric MELSEC-Q Series - Buffer Overflow
CVSS 6.8
CVE-2025-10458 HIGH
Zephyr < 4.1.0 - Improper Handling of Length Parameter Inconsistency
CVSS 7.6
CVE-2025-26432 MEDIUM
Android - Denial of Service via Missing Length Check
CVSS 5.5
CVE-2025-5514 MEDIUM
Mitsubishi Electric MELSEC iQ-F Series - DoS
CVSS 5.3
CVE-2025-54646 MEDIUM
Huawei EMUI and HarmonyOS - Denial of Service via BLE Packet Length Check
CVSS 5.1
CVE-2025-52949 MEDIUM
Juniper Junos OS and Junos OS Evolved - Denial of Service via Malformed BGP Packet in rpd
CVSS 6.5
CVE-2025-53604 MEDIUM
web-push < 0.10.3 - Denial of Service via Large Content-Length Header
CVSS 4.0
CVE-2025-23247 MEDIUM
NVIDIA CUDA Toolkit - Buffer Overflow
CVSS 4.4
CVE-2025-29784 HIGH
NamelessMC < 2.2.0 - Denial of Service via Forum Search Parameter Length
CVSS 7.5
CVE-2025-29931 LOW
TeleControl Server Basic < V3.1.2.2 - Memory Corruption
CVSS 3.7
CVE-2025-30659 HIGH
Juniper Junos OS SRX Series DoS via Malformed SVR Packet
CVSS 7.5
CVE-2025-32366 MEDIUM
ConnMan < 1.44 - Information Disclosure via DNS Response Parsing
CVSS 4.8
CVE-2024-53856 HIGH
rPGP < 0.14.1 - Denial of Service via Crafted Data
CVSS 7.5
CVE-2024-47293 MEDIUM
Huawei EMUI and HarmonyOS - Out-of-bounds Write in HAL-WIFI Module
CVSS 4.7
CVE-2024-41991 HIGH
Django 4.2-4.2.14 and 5.0-5.0.7 - Denial of Service via Unicode Character Input
CVSS 7.5
CVE-2024-41990 HIGH
Django 4.2-4.2.14 and 5.0-5.0.7 - Denial of Service via urlize() and urlizetrunc() Template Filters
CVSS 7.5
CVE-2024-42460 MEDIUM
elliptic 2.0.0-6.5.6 - ECDSA Signature Malleability via Missing Leading Zero Check
CVSS 5.3
CVE-2024-20416 MEDIUM
Cisco Small Business RV Series Router Firmware - Authenticated RCE via HTTP Request Boundary Check Bypass
CVSS 6.5
CVE-2024-39614 HIGH
Django 4.2-4.2.13 and 5.0-5.0.6 - Denial of Service in get_supported_language_variant()
CVSS 7.5
CVE-2024-38875 HIGH
Django 4.2-4.2.13 and 5.0-5.0.6 - Denial of Service via urlize and urlizetrunc Bracket Handling
CVSS 7.5
CVE-2024-38011 HIGH
Windows 10 1507-22H2, Windows 11 21H2-23H2, Windows Server 2012-2022 - Secure Boot Security Feature Bypass
CVSS 8.0
CVE-2024-38010 HIGH
Windows 10 1507-22H2, Windows 11 21H2-23H2, Windows Server 2012-2022 - Secure Boot Security Feature Bypass
CVSS 8.0
CVE-2024-37989 HIGH
Windows 10 1507-22H2, Windows 11 21H2-23H2, Windows Server 2012-2022 - Secure Boot Security Feature Bypass
CVSS 8.0
CVE-2024-37988 HIGH
Windows 10 1507-22H2, Windows 11 21H2-23H2, Windows Server 2012-2022 - Secure Boot Security Feature Bypass
CVSS 8.0
CVE-2024-37305 HIGH
oqs-provider < 0.6.1 - Buffer Overflow via DECODE_UINT32 Length Handling
CVSS 8.2
Details
Vulnerabilities 93