VYPR

CWE-1284

Improper Validation of Specified Quantity in Input

BaseIncomplete

Description

The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (378)

page 3 of 19
  • CVE-2023-30269HigApr 26, 2023
    risk 0.53cvss 8.1epss 0.01

    CLTPHP <=6.0 is vulnerable to Improper Input Validation via application/admin/controller/Template.php.

  • CVE-2021-31346HigNov 9, 2021
    risk 0.53cvss 8.2epss 0.02

    A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), PLUSCONTROL 1st Gen (All versions), SIMOTICS CONNECT 400 (All versions < V0.5.0.0), SIMOTICS CONNECT 400 (All versions <…

  • CVE-2026-58662CriJul 27, 2026
    risk 0.52cvss 9.1epss 0.01

    Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

  • CVE-2026-41677CriApr 24, 2026
    risk 0.52cvss 9.1epss 0.00

    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.0 to before 0.10.78, the *_from_pem_callback APIs did not validate the length returned by the user's callback. A password callback that returns a value larger than the buffer it was given can…

  • CVE-2021-44158HigJan 3, 2022
    risk 0.52cvss 8.0epss 0.01

    ASUS RT-AX56U Wi-Fi Router is vulnerable to stack-based buffer overflow due to improper validation for httpd parameter length. An authenticated local area network attacker can launch arbitrary code execution to control the system or disrupt service.

  • CVE-2025-9316MedNov 12, 2025
    risk 0.51cvss epss 0.36

    N-central < 2025.4 can generate sessionIDs for unauthenticated users This issue affects N-central: before 2025.4.

  • CVE-2025-25178HigApr 4, 2025
    risk 0.51cvss 7.8epss 0.00

    Software installed and run as a non-privileged user may conduct improper GPU system calls to cause kernel system memory corruption.

  • CVE-2024-45351HigMar 26, 2025
    risk 0.51cvss 7.8epss 0.00

    A code execution vulnerability exists in the Xiaomi Game center application product. The vulnerability is caused by improper input validation and can be exploited by attackers to execute malicious code.

  • CVE-2025-0285HigMar 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Various Paragon Software products contain an arbitrary kernel memory mapping vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to perform privilege escalation exploits.

  • CVE-2024-55407HigJan 6, 2025
    risk 0.51cvss 7.8epss 0.00

    An issue in the DeviceloControl function of ITE Tech. Inc ITE IO Access v1.0.0.0 allows attackers to perform arbitrary port read and write actions via supplying crafted IOCTL requests.

  • CVE-2021-47251HigMay 21, 2024
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: mac80211: fix skb length check in ieee80211_scan_rx() Replace hard-coded compile-time constants for header length check with dynamic determination based on the frame type. Otherwise, we hit a validation…

  • CVE-2022-47029HigMay 30, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue was found in Action Launcher v50.5 allows an attacker to escalate privilege via modification of the intent string to function update.

  • CVE-2022-20493HigJan 26, 2023
    risk 0.51cvss 7.8epss 0.00

    In Condition of Condition.java, there is a possible way to grant notification access due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2022-20491HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20488HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-36620HigAug 31, 2022
    risk 0.51cvss 7.5epss 0.23

    D-link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img is vulnerable to Buffer Overflow via /goform/addRouting.

  • CVE-2022-25793HigAug 10, 2022
    risk 0.51cvss 7.8epss 0.00

    A Stack-based Buffer Overflow Vulnerability in Autodesk 3ds Max 2022, 2021, and 2020 may lead to code execution through the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer when parsing ActionScript Byte Code…

  • CVE-2022-22072HigJun 14, 2022
    risk 0.51cvss 7.8epss 0.00

    Buffer overflow can occur due to improper validation of NDP application information length in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

  • CVE-2022-26128HigMar 3, 2022
    risk 0.51cvss 7.8epss 0.01

    A buffer overflow vulnerability exists in FRRouting through 8.1.0 due to a wrong check on the input packet length in the babel_packet_examin function in babeld/message.c.

  • CVE-2022-26127HigMar 3, 2022
    risk 0.51cvss 7.8epss 0.01

    A buffer overflow vulnerability exists in FRRouting through 8.1.0 due to missing a check on the input packet length in the babel_packet_examin function in babeld/message.c.