CWE-1284
357 CVEs • Abstraction: Base
Improper Validation of Specified Quantity in Input
The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
CVEs (357)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, `istiod`, is vulnerable to a request processing error, allowing a malicious attacker that sends a spec...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Feb 20, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in drivers/usb/gadget/function/rndis.c in the Linux kernel before 5.16.10. The RNDIS USB gadget lacks validation of the size of the RNDIS_MSG_SET command. Attackers can obtain sensitive informatio...Show more |
A segmentation fault during PCF file parsing in pcf2bdf versions >=1.05 allows an attacker to trigger a program crash via a specially crafted PCF font file. This crash affects the availability of the software and depende...Show more |
Improper Validation of Specified Quantity in Input in Packagist microweber/microweber prior to 1.2.11. |
1Custom Popup Builder Project 1Custom Popup Builder Jun 17, 2026 Feb 14, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Custom Popup Builder WordPress plugin before 1.3.1 autoload data from its popup on every pages, as such data can be sent by unauthenticated user, and is not validated in length, this could cause a denial of service o...Show more |
1Cisco 4Rv340 Firmware Rv340w FirmwareRv345 Firmware+1 moreJun 17, 2026 Feb 10, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypa...Show more |
A vulnerability has been identified in Simcenter Femap V2020.2 (All versions), Simcenter Femap V2021.1 (All versions). Affected application contains a stack based buffer overflow vulnerability while parsing NEU files. Th...Show more |
Tensorflow is an Open Source Machine Learning Framework. During shape inference, TensorFlow can allocate a large vector based on a value from a tensor controlled by the user. The fix will be included in TensorFlow 2.8.0....Show more |
1Sealevel 1Seaconnect 370w Firmware Jun 17, 2026 Feb 4, 2022 N/A· v4 10.0 CRITICAL· v3 7.5 HIGH· v2 A stack-based buffer overflow vulnerability exists in both the LLMNR functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted network packet can lead to remote code execution. An attacker can...Show more |
Improper Validation of Specified Quantity in Input in Packagist dolibarr/dolibarr prior to 16.0. |
An Improper Validation of Specified Quantity in Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS allows an unauthenticated networked attacker to cause an rdp crash and thereby a Denia...Show more |
2Fedoraproject Pypa2Fedora PipenvJun 17, 2026 Jan 10, 2022 N/A· v4 8.6 HIGH· v3 9.3 HIGH· v2 pipenv is a Python development workflow tool. Starting with version 2018.10.9 and prior to version 2022.1.8, a flaw in pipenv's parsing of requirements files allows an attacker to insert a specially crafted string inside...Show more |
Improper Validation of Specified Quantity in Input vulnerability in dolibarr dolibarr/dolibarr. |
ASUS RT-AX56U Wi-Fi Router is vulnerable to stack-based buffer overflow due to improper validation for httpd parameter length. An authenticated local area network attacker can launch arbitrary code execution to control t...Show more |
2Debian Giftrans Project2Debian Linux GiftransJun 17, 2026 Jan 1, 2022 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 The giftrans function in giftrans 1.12.2 contains a stack-based buffer overflow because a value inside the input file determines the amount of data to write. This allows an attacker to overwrite up to 250 bytes outside o...Show more |
In Open5GS 2.4.0, a crafted packet from UE can crash SGW-U/UPF. |
1Anker 1Eufy Homebase 2 Firmware Jun 17, 2026 Dec 8, 2021 N/A· v4 10.0 CRITICAL· v3 10.0 HIGH· v2 An out-of-bounds write vulnerability exists in the CMD_DEVICE_GET_SERVER_LIST_REQUEST functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h in function read_udp_push_config_file. A specially-crafted...Show more |
1Anker 1Eufy Homebase 2 Firmware Jun 17, 2026 Dec 8, 2021 N/A· v4 10.0 CRITICAL· v3 10.0 HIGH· v2 An out-of-bounds write vulnerability exists in the CMD_DEVICE_GET_SERVER_LIST_REQUEST functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h in function recv_server_device_response_msg_process. A spe...Show more |
1Siemens 11Apogee Modular Building Controller Firmware Apogee Modular Equiment Controller FirmwareApogee Pxc Compact Firmware+8 moreJun 17, 2026 Nov 9, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), PLUSCONTROL 1st Gen (All versions), SIMOTICS CONNECT 400 (All versions...Show more |
1Siemens 10Apogee Modular Building Controller Firmware Apogee Modular Equiment Controller FirmwareApogee Pxc Compact Firmware+7 moreJun 17, 2026 Nov 9, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), PLUSCONTROL 1st Gen (All versions). The total length of an UDP payload...Show more |