CWE-130

Improper Handling of Length Parameter Inconsistency

Parent: CWE-240 - Improper Handling of Inconsistent Structural Elements

The product parses a formatted message or structure, but it does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data.

104 vulnerabilities with CWE-130
CVE-2020-16224 MEDIUM
Philips Patient Information Center iX C.02 C.03 - Denial of Service via Length Parameter Inconsistency
CVSS 6.5
CVE-2019-0055 HIGH
Juniper Junos OS - Denial of Service via SIP ALG Packet Processing
CVSS 7.5
CVE-2019-3862 HIGH
libssh2 < 1.8.1 - Out-of-bounds Read via SSH_MSG_CHANNEL_REQUEST Packet Parsing
CVSS 7.3
CVE-2018-5453 HIGH
Moxa OnCell G3100-HSPA <1.4 Build 16062919 - Info Disclosure
CVSS 7.5
Details
Vulnerabilities 104