CWE-130
111 CVEs • Abstraction: Base
Improper Handling of Length Parameter Inconsistency
The product parses a formatted message or structure, but it does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data.
CVEs (111)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Apache Oracle33Agile Plm Agile Product Lifecycle ManagementAnt+30 moreAug 25, 2026 Jul 14, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds usi...Show more |
3Apache NetappOracle34Active Iq Unified Manager Banking ApisBanking Digital Experience+31 moreJun 17, 2026 Jul 13, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of serv...Show more |
3Apache NetappOracle27Active Iq Unified Manager Banking ApisBanking Digital Experience+24 moreJun 17, 2026 Jul 13, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of serv...Show more |
3Apache NetappOracle24Active Iq Unified Manager Banking Digital ExperienceBanking Enterprise Default Management+21 moreJun 17, 2026 Jul 13, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of servi...Show more |
Missing Size Checks in Bluetooth HCI over SPI. Zephyr versions >= v1.14.2, >= v2.2.0 contain Improper Handling of Length Parameter Inconsistency (CWE-130). For more information, see https://github.com/zephyrproject-rtos/...Show more |
1Mitsubishielectric 41C Controller Module Setting And Monitoring Tool Cpu Module Logging Configuration ToolCw Configurator+38 moreJun 17, 2026 Feb 19, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior...Show more |
6Canonical DebianFedoraproject+3 more10.net .net CoreBrotli+7 moreJun 17, 2026 Sep 15, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over...Show more |
1Philips 1Patient Information Center Ix Jun 17, 2026 Sep 11, 2020 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 In Patient Information Center iX (PICiX) Versions C.02, C.03, the software parses a formatted message or structure but does not handle or incorrectly handles a length field that is inconsistent with the actual length...Show more |
A vulnerability in the SIP ALG packet processing service of Juniper Networks Junos OS allows an attacker to cause a Denial of Service (DoS) to the device by sending specific types of valid SIP traffic to the device. In t...Show more |
5Debian FedoraprojectLibssh2+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Mar 21, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message and no payload are parsed. A remote attacker who compromises a SSH server may be ab...Show more |
1Moxa 4Oncell G3110 Hspa T Firmware Oncell G3110 Hspa FirmwareOncell G3150 Hspa T Firmware+1 moreJun 17, 2026 Mar 5, 2018 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 An Improper Handling of Length Parameter Inconsistency issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. An attacker may be able to edit the element of an HTTP request, causing t...Show more |