VYPR

CWE-1284

Improper Validation of Specified Quantity in Input

BaseIncomplete

Description

The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (418)

page 3 of 21
  • CVE-2021-35132HigSep 2, 2022
    risk 0.55cvss 8.4epss 0.00

    Out of bound write in DSP service due to improper bound check for response buffer size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

  • CVE-2022-35928HigAug 3, 2022
    risk 0.55cvss 8.4epss 0.00

    AES Crypt is a file encryption software for multiple platforms. AES Crypt for Linux built using the source on GitHub and having the version number 3.11 has a vulnerability with respect to reading user-provided passwords and confirmations via command-line prompts. Passwords…

  • CVE-2021-30350HigJun 14, 2022
    risk 0.55cvss 8.4epss 0.00

    Lack of MBN header size verification against input buffer can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables

  • CVE-2026-66374HigJul 25, 2026
    risk 0.53cvss 8.1epss 0.01

    Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.

  • CVE-2026-5260HigMay 26, 2026
    risk 0.53cvss 8.2epss 0.01

    A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information…

  • CVE-2023-30269HigApr 26, 2023
    risk 0.53cvss 8.1epss 0.01

    CLTPHP <=6.0 is vulnerable to Improper Input Validation via application/admin/controller/Template.php.

  • CVE-2021-31346HigNov 9, 2021
    risk 0.53cvss 8.2epss 0.02

    A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), PLUSCONTROL 1st Gen (All versions), SIMOTICS CONNECT 400 (All versions < V0.5.0.0), SIMOTICS CONNECT 400 (All versions <…

  • CVE-2026-73194CriAug 15, 2026
    risk 0.52cvss 9.1epss 0.00

    DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the binder counter in preparse. preparse reserves seven output bytes per input byte, the width of the longest ':p99999' expansion. The ':N' branch parses the…

  • CVE-2026-58662CriJul 27, 2026
    risk 0.52cvss 9.1epss 0.01

    Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

  • CVE-2026-41677CriApr 24, 2026
    risk 0.52cvss 9.1epss 0.00

    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.0 to before 0.10.78, the *_from_pem_callback APIs did not validate the length returned by the user's callback. A password callback that returns a value larger than the buffer it was given can…

  • CVE-2021-44158HigJan 3, 2022
    risk 0.52cvss 8.0epss 0.01

    ASUS RT-AX56U Wi-Fi Router is vulnerable to stack-based buffer overflow due to improper validation for httpd parameter length. An authenticated local area network attacker can launch arbitrary code execution to control the system or disrupt service.

  • CVE-2026-45201HigAug 21, 2026
    risk 0.51cvss 7.8epss 0.00

    Software installed and run as a non-privileged user may conduct improper GPU system calls to pass invalid log2 page size when allocating physical pages leading to OOB read and/or write due to improper validation of the said value. Such crafted log2 page size could lead to 4K…

  • CVE-2025-9316MedNov 12, 2025
    risk 0.51cvss —epss 0.36

    N-central < 2025.4 can generate sessionIDs for unauthenticated users This issue affects N-central: before 2025.4.

  • CVE-2025-25178HigApr 4, 2025
    risk 0.51cvss 7.8epss 0.00

    Software installed and run as a non-privileged user may conduct improper GPU system calls to cause kernel system memory corruption.

  • CVE-2024-45351HigMar 26, 2025
    risk 0.51cvss 7.8epss 0.00

    A code execution vulnerability exists in the Xiaomi Game center application product. The vulnerability is caused by improper input validation and can be exploited by attackers to execute malicious code.

  • CVE-2025-0285HigMar 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Various Paragon Software products contain an arbitrary kernel memory mapping vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to perform privilege escalation exploits.

  • CVE-2024-55407HigJan 6, 2025
    risk 0.51cvss 7.8epss 0.00

    An issue in the DeviceloControl function of ITE Tech. Inc ITE IO Access v1.0.0.0 allows attackers to perform arbitrary port read and write actions via supplying crafted IOCTL requests.

  • CVE-2021-47251HigMay 21, 2024
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: mac80211: fix skb length check in ieee80211_scan_rx() Replace hard-coded compile-time constants for header length check with dynamic determination based on the frame type. Otherwise, we hit a validation…

  • CVE-2022-47029HigMay 30, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue was found in Action Launcher v50.5 allows an attacker to escalate privilege via modification of the intent string to function update.

  • CVE-2022-20493HigJan 26, 2023
    risk 0.51cvss 7.8epss 0.00

    In Condition of Condition.java, there is a possible way to grant notification access due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product:…