CWE-130

Improper Handling of Length Parameter Inconsistency

Parent: CWE-240 - Improper Handling of Inconsistent Structural Elements

The product parses a formatted message or structure, but it does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data.

104 vulnerabilities with CWE-130
CVE-2024-41991 HIGH
Django 4.2-4.2.14 and 5.0-5.0.7 - Denial of Service via Unicode Character Input
CVSS 7.5
CVE-2024-41990 HIGH
Django 4.2-4.2.14 and 5.0-5.0.7 - Denial of Service via urlize() and urlizetrunc() Template Filters
CVSS 7.5
CVE-2024-42460 MEDIUM
elliptic 2.0.0-6.5.6 - ECDSA Signature Malleability via Missing Leading Zero Check
CVSS 5.3
CVE-2024-20416 MEDIUM
Cisco Small Business RV Series Router Firmware - Authenticated RCE via HTTP Request Boundary Check Bypass
CVSS 6.5
CVE-2024-39614 HIGH
Django 4.2-4.2.13 and 5.0-5.0.6 - Denial of Service in get_supported_language_variant()
CVSS 7.5
CVE-2024-38875 HIGH
Django 4.2-4.2.13 and 5.0-5.0.6 - Denial of Service via urlize and urlizetrunc Bracket Handling
CVSS 7.5
CVE-2024-38011 HIGH
Windows 10 1507-22H2, Windows 11 21H2-23H2, Windows Server 2012-2022 - Secure Boot Security Feature Bypass
CVSS 8.0
CVE-2024-38010 HIGH
Windows 10 1507-22H2, Windows 11 21H2-23H2, Windows Server 2012-2022 - Secure Boot Security Feature Bypass
CVSS 8.0
CVE-2024-37989 HIGH
Windows 10 1507-22H2, Windows 11 21H2-23H2, Windows Server 2012-2022 - Secure Boot Security Feature Bypass
CVSS 8.0
CVE-2024-37988 HIGH
Windows 10 1507-22H2, Windows 11 21H2-23H2, Windows Server 2012-2022 - Secure Boot Security Feature Bypass
CVSS 8.0
CVE-2024-37305 HIGH
oqs-provider < 0.6.1 - Buffer Overflow via DECODE_UINT32 Length Handling
CVSS 8.2
CVE-2024-35313 HIGH
Tor Arti < 1.2.3 - Improper Handling of Length Parameter Inconsistency
CVSS 7.3
CVE-2024-29064 MEDIUM
Windows Hyper-V - Denial of Service via Length Parameter Inconsistency
CVSS 6.2
CVE-2024-20685 MEDIUM
Azure Private 5G Core < 2403.0-2 - Denial of Service
CVSS 5.9
CVE-2024-24976 MEDIUM
Open Automation Software OAS Platform <19.00.0057 - DoS
CVSS 4.9
CVE-2023-53157 MEDIUM
rosenpass < 0.2.1 - Denial of Service via One-Byte UDP Packet
CVSS 5.3
CVE-2023-52547 HIGH
Huawei Matebook D16 CREM-WXX9 BIOS v2.26 - Memory Corruption in SMI Handler
CVSS 7.8
CVE-2023-5393 HIGH
Honeywell Experion Server - Stack Overflow and Remote Code Execution via Malformed Hostname Message
CVSS 7.4
CVE-2023-50248 MEDIUM
CKAN <2.9.10-2.10.3 - Memory Corruption
CVSS 4.5
CVE-2023-40167 MEDIUM
Jetty <9.4.52-12.0.1 - Info Disclosure
CVSS 5.3
CVE-2023-33192 HIGH
ntpd-rs 0.3.0-0.3.2 - Denial of Service via NTS Cookie Length Mismatch
CVSS 7.5
CVE-2023-28964 HIGH
Juniper Networks Junos OS/Junos OS Evolved - DoS
CVSS 7.5
CVE-2022-36788 HIGH
libslic3r 1.3.0 and Master Commit b1a5500 - Heap-Based Buffer Overflow via Crafted STL File
CVSS 8.1
CVE-2022-20690 MEDIUM
Cisco ATA 190 Series - Memory Corruption
CVSS 5.3
CVE-2022-20689 MEDIUM
Cisco ATA 190 Series - Memory Corruption
CVSS 5.3
Details
Vulnerabilities 104