VYPR

CWE-1284

Improper Validation of Specified Quantity in Input

BaseIncomplete

Description

The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (378)

page 17 of 19
  • CVE-2022-0174MedJan 10, 2022
    risk 0.21cvss 4.3epss 0.01

    Improper Validation of Specified Quantity in Input vulnerability in dolibarr dolibarr/dolibarr.

  • CVE-2026-59997MedJul 8, 2026
    risk 0.20cvss 4.2epss 0.00

    internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.

  • CVE-2023-31331LowFeb 11, 2025
    risk 0.20cvss 3.0epss 0.00

    Improper access control in the DRTM firmware could allow a privileged attacker to perform multiple driver initializations, resulting in stack memory corruption that could potentially lead to loss of integrity or availability.

  • CVE-2026-53720medJul 9, 2026
    risk 0.19cvss epss

    ### Impact The argon2i_32 implementation does not check the nb_blocks size. If the caller does not provide a sufficiently large buffer based on the API contract, then argon2i_32 will write past the end of the buffer and possibly corrupt the heap. ### Patches Fixed in 4.0.2.8,…

  • CVE-2026-57062LowJun 23, 2026
    risk 0.19cvss 2.9epss 0.00

    CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.

  • CVE-2026-57053MedJun 23, 2026
    risk 0.19cvss 4.0epss 0.00

    GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The affected code is not present in libidn2.

  • CVE-2026-27171LowFeb 18, 2026
    risk 0.19cvss 2.9epss 0.00

    zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.

  • CVE-2025-32415LowApr 17, 2025
    risk 0.19cvss 2.9epss 0.01

    In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer under-read. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be…

  • CVE-2026-44459LowMay 13, 2026
    risk 0.18cvss 3.8epss 0.00

    Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, improper validation of the JWT NumericDate claims exp, nbf, and iat in hono/utils/jwt allows tokens with non-spec-compliant claim values to silently bypass time-based checks.…

  • CVE-2026-0925LowJan 26, 2026
    risk 0.18cvss 2.7epss 0.00

    Tanium addressed an improper input validation vulnerability in Discover.

  • CVE-2024-53879LowFeb 25, 2025
    risk 0.18cvss 2.8epss 0.00

    NVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in the cuobjdump binary, where a user could cause a crash by passing a malformed ELF file to cuobjdump. A successful exploit of this vulnerability might lead to a partial denial of service.

  • CVE-2024-53878LowFeb 25, 2025
    risk 0.18cvss 2.8epss 0.00

    NVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in the cuobjdump binary, where a user could cause a crash by passing a malformed ELF file to cuobjdump. A successful exploit of this vulnerability might lead to a partial denial of service.

  • CVE-2023-23549LowNov 15, 2023
    risk 0.18cvss 2.7epss 0.01

    Improper Input Validation in Checkmk <2.2.0p15, <2.1.0p37, <=2.0.0p39 allows priviledged attackers to cause partial denial of service of the UI via too long hostnames.

  • CVE-2022-46143LowDec 13, 2022
    risk 0.18cvss 2.7epss 0.01

    Affected devices do not check the TFTP blocksize correctly. This could allow an authenticated attacker to read from an uninitialized buffer that potentially contains previously allocated data.

  • CVE-2026-53540LowJun 22, 2026
    risk 0.17cvss 3.7epss 0.00

    Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.31, parse_form() did not validate the Content-Length header before using it to bound its chunked read of the request body. A negative Content-Length turned the bounded read into a read-until-EOF, so the…

  • CVE-2025-2826LowMay 27, 2025
    risk 0.17cvss 2.6epss 0.00

    n affected platforms running Arista EOS, ACL policies may not be enforced. IPv4 ingress ACL, MAC ingress ACL, or IPv6 standard ingress ACL enabled on one or more ethernet or LAG interfaces may result in ACL policies not being enforced for ingress packets. This can cause incoming…

  • CVE-2023-20581LowFeb 11, 2025
    risk 0.16cvss 2.5epss 0.00

    Improper access control in the IOMMU may allow a privileged attacker to bypass RMP checks, potentially leading to a loss of guest memory integrity.

  • CVE-2023-31304LowAug 13, 2024
    risk 0.15cvss 2.3epss 0.00

    Improper input validation in SMU may allow an attacker with privileges and a compromised physical function (PF)     to modify the PCIe® lane count and speed, potentially leading to a loss of availability.

  • CVE-2022-20543LowDec 16, 2022
    risk 0.15cvss 2.3epss 0.00

    In multiple locations, there is a possible display crash loop due to improper input validation. This could lead to local denial of service with system execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID:…

  • CVE-2023-0195LowApr 1, 2023
    risk 0.13cvss 2.0epss 0.00

    NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer driver nvlddmkm.sys, where an can cause CWE-1284, which may lead to hypothetical Information leak of unimportant data such as local variable data of the driver