VYPR

CWE-1284

Improper Validation of Specified Quantity in Input

BaseIncomplete

Description

The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (378)

page 13 of 19
  • CVE-2022-2868MedAug 17, 2022
    risk 0.36cvss 5.5epss 0.00

    libtiff's tiffcrop utility has a improper input validation flaw that can lead to out of bounds read and ultimately cause a crash if an attacker is able to supply a crafted file to tiffcrop.

  • CVE-2021-39690MedMar 16, 2022
    risk 0.36cvss 5.5epss 0.00

    In setDisplayPadding of WallpaperManagerService.java, there is a possible way to cause a persistent DoS due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-23319MedFeb 17, 2022
    risk 0.36cvss 5.5epss 0.01

    A segmentation fault during PCF file parsing in pcf2bdf versions >=1.05 allows an attacker to trigger a program crash via a specially crafted PCF font file. This crash affects the availability of the software and dependent downstream components.

  • CVE-2013-0270MedApr 12, 2013
    risk 0.36cvss 6.5epss 0.03

    A flaw was found in OpenStack Keystone. A remote attacker could exploit this vulnerability by sending a large HTTP request, specifically by providing a long tenant name when requesting a token. This could lead to a denial of service, consuming excessive CPU and memory resources…

  • CVE-2026-19518MedAug 11, 2026
    risk 0.35cvss 6.5epss 0.00

    Improper Validation of Specified Quantity in Input vulnerability in Samsung Open Source rlottie allows Input Data Manipulation.

  • CVE-2026-19517MedAug 11, 2026
    risk 0.35cvss 6.5epss 0.00

    Improper Validation of Specified Quantity in Input and Allocation of Resources Without Limits or Throttling vulnerability in Samsung Open Source rlottie allows Excessive Allocation.

  • CVE-2026-54092MedJun 25, 2026
    risk 0.35cvss 6.5epss 0.00

    File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, unchecked passwords maximums allow for an arbitrarily large password to be passed into the login API. This spikes CPU and…

  • CVE-2026-34756MedApr 6, 2026
    risk 0.35cvss 6.5epss 0.00

    vLLM is an inference and serving engine for large language models (LLMs). From 0.1.0 to before 0.19.0, a Denial of Service vulnerability exists in the vLLM OpenAI-compatible API server. Due to the lack of an upper bound validation on the n parameter in the ChatCompletionRequest…

  • CVE-2025-36094MedFeb 3, 2026
    risk 0.35cvss 5.4epss 0.00

    IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 007 could allow an authenticated user to cause a denial of service or corrupt existing data due to the improper validation of…

  • CVE-2025-68383MedDec 18, 2025
    risk 0.35cvss 6.5epss 0.00

    Improper Validation of Specified Index, Position, or Offset in Input (CWE-1285) in Filebeat Syslog parser and the Libbeat Dissect processor can allow a user to trigger a Buffer Overflow (CAPEC-100) and cause a denial of service (panic/crash) of the Filebeat process via either a…

  • CVE-2024-24690MedFeb 14, 2024
    risk 0.35cvss 5.4epss 0.01

    Improper input validation in some Zoom clients may allow an authenticated user to conduct a denial of service via network access.

  • CVE-2021-28510MedJan 26, 2023
    risk 0.35cvss 5.3epss 0.01

    For certain systems running EOS, a Precision Time Protocol (PTP) packet of a management/signaling message with an invalid Type-Length-Value (TLV) causes the PTP agent to restart. Repeated restarts of the service will make the service unavailable.

  • CVE-2022-37312MedDec 26, 2022
    risk 0.35cvss 5.3epss 0.01

    OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large request body containing a redirect URL to the deferrer servlet.

  • CVE-2022-37311MedDec 26, 2022
    risk 0.35cvss 5.3epss 0.01

    OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large location request parameter to the redirect servlet.

  • CVE-2022-20691MedDec 12, 2022
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Adaptive Telephone Adapter firmware could allow an unauthenticated, adjacent attacker to cause a DoS condition of an affected device. This vulnerability is due to missing length validation of…

  • CVE-2022-20690MedDec 12, 2022
    risk 0.35cvss 5.3epss 0.01

    Multiple vulnerabilities in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, adjacent attacker to cause Cisco Discovery Protocol memory corruption on an affected device. These vulnerabilities…

  • CVE-2022-20689MedDec 12, 2022
    risk 0.35cvss 5.3epss 0.01

    Multiple vulnerabilities in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, adjacent attacker to cause Cisco Discovery Protocol memory corruption on an affected device. These vulnerabilities…

  • CVE-2022-20688MedDec 12, 2022
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device and cause Cisco Discovery Protocol service to restart. This…

  • CVE-2022-20687MedDec 12, 2022
    risk 0.35cvss 5.3epss 0.01

    Multiple vulnerabilities in the Link Layer Discovery Protocol (LLDP) functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device and cause the LLDP service to restart. …

  • CVE-2022-20686MedDec 12, 2022
    risk 0.35cvss 5.3epss 0.01

    Multiple vulnerabilities in the Link Layer Discovery Protocol (LLDP) functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device and cause the LLDP service to restart. …