CWE-130
Improper Handling of Length Parameter Inconsistency
The product parses a formatted message or structure, but it does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data.
104 vulnerabilities with CWE-130
CVE-2022-20686
MEDIUM
Cisco ATA 190/191/192 Firmware - Unauthenticated Remote Code Execution and Denial of Service via LLDP Packet Header
CVSS 5.3
CVE-2022-41586
HIGH
Communication Framework - Info Disclosure
CVSS 7.5
CVE-2022-20870
HIGH
Cisco IOS XE - Denial of Service via Malformed MPLS Egress Packet
CVSS 8.6
CVE-2022-3290
HIGH
GitHub ikus060/rdiffweb <2.4.8 - Info Disclosure
CVSS 7.5
CVE-2022-3272
HIGH
GitHub ikus060/rdiffweb <2.4.8 - Info Disclosure
CVSS 7.5
CVE-2022-2714
CRITICAL
GitHub francoisjacquet/rosariosis <10.0 - Info Disclosure
CVSS 9.8
CVE-2022-1543
HIGH
erudika/scoold <1.49.4 - Memory Corruption
CVSS 8.8
CVE-2022-0677
HIGH
Bitdefender Update Server <3.4.0.276 - DoS
CVSS 7.5
CVE-2022-0618
HIGH
swift-nio-http2 1.0.0-1.19.9 - Denial of Service via Malformed HTTP/2 HEADERS or PUSH_PROMISE Frame
CVSS 7.5
CVE-2022-24666
HIGH
swift-nio-http2 1.0.0-1.19.1 - Denial of Service via Malformed HTTP/2 HEADERS Frame
CVSS 7.5
CVE-2021-27862
MEDIUM
IEEE 802.2 < 802.2h-1997 - Authentication Bypass via LLC/SNAP Header Spoofing
CVSS 4.7
CVE-2021-27861
MEDIUM
IEEE 802.2 < 802.2h-1997 - Authentication Bypass via LLC/SNAP Header Spoofing
CVSS 4.7
CVE-2021-38445
HIGH
OpenDDS < 3.18.1 - Remote Code Execution via Length Parameter Inconsistency
CVSS 7.0
CVE-2021-43666
HIGH
mbed TLS < 3.0.0 - Denial of Service in mbedtls_pkcs12_derivation
CVSS 7.5
CVE-2021-20610
HIGH
Mitsubishi Electric MELSEC iQ-R - Length Parameter Inconsistency
CVSS 7.5
CVE-2021-26329
MEDIUM
AMD EPYC 7001 Series Firmware < naplespi-sp3_1.0.0.g - Integer Overflow in System Management Unit
CVSS 5.5
CVE-2021-3454
MEDIUM
Zephyr 2.4.0-2.5.9 - Denial of Service via Truncated L2CAP K-frame
CVSS 4.3
CVE-2021-36374
MEDIUM
Apache Ant <1.9.16, 1.10.11 - Memory Corruption
CVSS 5.5
CVE-2021-36373
MEDIUM
Apache Ant <1.9.16, 1.10.11 - Memory Corruption
CVSS 5.5
CVE-2021-36090
HIGH
Apache Commons Compress 1.0-1.20 - Denial of Service via Malicious ZIP Archive
CVSS 7.5
CVE-2021-35517
HIGH
Apache Commons Compress 1.1-1.19 - Denial of Service via Malicious TAR Archive
CVSS 7.5
CVE-2021-35516
HIGH
Apache Commons Compress 1.6-1.19 - Denial of Service via Malicious 7Z Archive
CVSS 7.5
CVE-2021-20588
HIGH
Mitsubishi Electric FA Engineering Software - Buffer Overflow
CVSS 7.5
CVE-2020-10065
LOW
Zephyr < 1.14.2 - Improper Handling of Length Parameter Inconsistency in Bluetooth HCI over SPI
CVSS 3.8
CVE-2020-8927
MEDIUM
Brotli < 1.0.8 - Denial of Service via One-Shot Decompression Buffer Overflow
CVSS 5.3
Details
Vulnerabilities
104