VYPR

CWE-1284

Improper Validation of Specified Quantity in Input

BaseIncomplete

Description

The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (378)

page 18 of 19
  • CVE-2023-0194LowApr 1, 2023
    risk 0.13cvss 2.0epss 0.00

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer driver, where an invalid display configuration may lead to denial of service.

  • CVE-2026-0428LowMay 15, 2026
    risk 0.12cvss epss 0.00

    Insufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_COPY_VF_CHIPLET_REGS to write invalid data to a remote Die, potentially resulting in unexpected behavior.

  • CVE-2025-66660LowMay 15, 2026
    risk 0.12cvss epss 0.00

    Insufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_CHECK_TA_COMPAT to cause incorrect shared memory mapping, potentially resulting in unexpected behavior.

  • CVE-2025-46656LowApr 26, 2025
    risk 0.12cvss 2.9epss 0.00

    python-markdownify (aka markdownify) before 0.14.1 allows large headline prefixes such as in addition to through . This causes memory consumption.

  • CVE-2025-54515LowNov 23, 2025
    risk 0.07cvss epss 0.00

    The Secure Flag passed to Versal™ Adaptive SoC’s Trusted Firmware for Cortex®-A processors (TF-A) for Arm’s Power State Coordination Interface (PSCI) commands were incorrectly set to secure instead of using the processor’s actual security state. This would allow the…

  • CVE-2021-43267CriNov 2, 2021
    risk 0.05cvss 9.8epss 0.58

    An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. The Transparent Inter-Process Communication (TIPC) functionality allows remote attackers to exploit insufficient validation of user-supplied sizes for the MSG_CRYPTO message type.

  • CVE-2008-1440Jun 12, 2008
    risk 0.02cvss epss 0.23

    Microsoft Windows XP SP2 and SP3, and Server 2003 SP1 and SP2, does not properly validate the option length field in Pragmatic General Multicast (PGM) packets, which allows remote attackers to cause a denial of service (infinite loop and system hang) via a crafted PGM packet,…

  • CVE-2026-40272HigJul 29, 2026
    risk 0.00cvss 7.0epss 0.00

    Improper Input Validation in the decode() function of the traceparser library could allow an attacker with a corrupted kernel trace event log (.kev) file, to execute arbitrary code or cause a crash in processes that use libtraceparser in QNX hosts or targets.

  • CVE-2026-59532HigJul 27, 2026
    risk 0.00cvss 7.5epss 0.00

    Unauthenticated Other Vulnerability Type in Booking and Rental Manager <= 2.7.2 versions.

  • CVE-2026-59531HigJul 27, 2026
    risk 0.00cvss 7.5epss 0.00

    Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2.10.0 versions.

  • CVE-2026-11721HigJul 22, 2026
    risk 0.00cvss 7.5epss 0.00

    It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes `named` to produce a wildcard name for a zone that is shorter than the attacker's zone, which can result in…

  • CVE-2026-10822MedJul 22, 2026
    risk 0.00cvss 6.5epss 0.00

    If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequently abort and exit. BIND will first need to store a DNS record for a key (KEY, DNSKEY, etc.). That key must specify a PRIVATEDNS algorithm (253), and in the…

  • CVE-2026-59695HigJul 17, 2026
    risk 0.00cvss epss 0.00

    Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet in a single request by naming an arbitrarily high gas price. When the mpp Elixir library is configured as fee payer (fee_payer: true),…

  • CVE-2026-59694HigJul 17, 2026
    risk 0.00cvss epss 0.00

    Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per payment by a large multiplier, degrading the sponsor's operating margin. When the mpp Elixir library is configured as fee payer…

  • CVE-2026-59252HigJul 17, 2026
    risk 0.00cvss epss 0.00

    Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet, resulting in denial of service for legitimate clients. When the mpp Elixir library is configured as fee payer (fee_payer: true), the…

  • CVE-2026-57364MedJul 13, 2026
    risk 0.00cvss 6.5epss 0.00

    Improper Validation of Specified Quantity in Input vulnerability in WPDeveloper Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More better-payment allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Better…

  • CVE-2026-57023HigJul 9, 2026
    risk 0.00cvss 7.5epss 0.00

    An Improper Validation of Specified Quantity in Input vulnerability in the TCP proxy plugin of Juniper Networks Junos OS on MX Series with SPC3, and SRX Series allows an unauthenticated, network-based attacker to cause a complete Denial of Service (DoS). When TCP proxy is…

  • CVE-2026-57019MedJul 9, 2026
    risk 0.00cvss 6.5epss 0.00

    An Improper Validation of Specified Quantity in Input vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS). When a specific packet is received from device…

  • CVE-2026-43928LowJul 6, 2026
    risk 0.00cvss epss 0.00

    FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the PayPalEmail payment adapter accepts PayPal IPN callbacks and credits the IPN-supplied amount (`mc_gross`) to the client's balance without validating it against the invoice total.…

  • CVE-2022-4990HigJul 3, 2026
    risk 0.00cvss epss 0.00

    ** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to bypass security validation and access restricted memory blocks via crafted IOCTL requests, leading to privilege escalation. Refer to the…