CWE-130
102 CVEs • Abstraction: Base
Improper Handling of Length Parameter Inconsistency
The product parses a formatted message or structure, but it does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data.
CVEs (102)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Debian FedoraprojectLibssh2+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Mar 21, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message and no payload are parsed. A remote attacker who compromises a SSH server may be ab...Show more |
1Moxa 4Oncell G3110 Hspa T Firmware Oncell G3110 Hspa FirmwareOncell G3150 Hspa T Firmware+1 moreJun 17, 2026 Mar 5, 2018 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 An Improper Handling of Length Parameter Inconsistency issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. An attacker may be able to edit the element of an HTTP request, causing t...Show more |