VYPR

CWE-229

Improper Handling of Values

BaseIncomplete

Description

The product does not properly handle when the expected number of values for parameters, fields, or arguments is not provided in input, or if those values are undefined.

Hierarchy (View 1000)

CVEs mapped to this weakness (19)

  • CVE-2025-7964CriJan 30, 2026
    risk 0.60cvss epss 0.00

    After receiving a malformed 802.15.4 MAC Data Request the Zigbee Coordinator sends a ‘network leave’ request to Zigbee router resulting in the Zigbee Router getting stuck in a non-rejoinable state. If a suitable parent is not available, the end devices will be unable to…

  • CVE-2026-45602CriJun 9, 2026
    risk 0.59cvss 9.1epss 0.00

    No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network.

  • CVE-2022-3409HigOct 27, 2022
    risk 0.53cvss 8.2epss 0.01

    A vulnerability in bmcweb of OpenBMC Project allows user to cause denial of service. This vulnerability was identified during mitigation for CVE-2022-2809. When fuzzing the multipart_parser code using AFL++ with address sanitizer enabled to find smallest memory corruptions…

  • CVE-2022-2809HigOct 27, 2022
    risk 0.53cvss 8.2epss 0.01

    A vulnerability in bmcweb of OpenBMC Project allows user to cause denial of service. When fuzzing the multipart_parser code using AFL++ with address sanitizer enabled to find smallest memory corruptions possible. It detected problem in how multipart_parser handles unclosed http…

  • CVE-2024-39531HigJul 11, 2024
    risk 0.49cvss 7.5epss 0.00

    An Improper Handling of Values vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on ACX 7000 Series allows a network-based, unauthenticated attacker to cause a Denial-of-Service (DoS). If a value is configured for DDoS bandwidth or burst…

  • CVE-2024-36737HigJun 6, 2024
    risk 0.49cvss 7.5epss 0.01

    Improper input validation in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputting a negative value into the oneflow.full parameter.

  • CVE-2022-24412HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.01

    Dell EMC PowerScale OneFS 8.2.x - 9.3.0.x contain an improper handling of value vulnerability. An unprivileged network attacker could potentially exploit this vulnerability, leading to denial-of-service.

  • CVE-2022-22562HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.01

    Dell PowerScale OneFS, versions 8.2.0-9.3.0, contain a improper handling of missing values exploit. An unauthenticated network attacker could potentially exploit this denial-of-service vulnerability.

  • CVE-2024-29460MedApr 10, 2024
    risk 0.43cvss 6.6epss 0.00

    An issue in PX4 Autopilot v.1.14.0 allows an attacker to manipulate the flight path allowing for crashes of the drone via the home point location of the mission_block.cpp component.

  • CVE-2025-59032HigMar 27, 2026
    risk 0.42cvss 7.5epss 0.01

    ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively…

  • CVE-2026-4736HigMar 24, 2026
    risk 0.40cvss epss 0.00

    Improper Handling of Values vulnerability in No-Chicken Echo-Mate (SDK/rv1106-sdk/sysdrv/source/kernel/include/net/netfilter modules). This vulnerability is associated with program files nf_tables.H‎, nft_byteorder.C‎, nft_meta.C‎. This issue affects Echo-Mate: before…

  • CVE-2025-20268MedAug 14, 2025
    risk 0.38cvss 5.8epss 0.00

    A vulnerability in the Geolocation-Based Remote Access (RA) VPN feature of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured policies to allow or deny HTTP connections based on a country or region. This…

  • CVE-2024-20431MedOct 23, 2024
    risk 0.38cvss 5.8epss 0.00

    A vulnerability in the geolocation access control feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass an access control policy. This vulnerability is due to improper assignment of geolocation data. An attacker…

  • CVE-2024-30917MedApr 11, 2024
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in eProsima FastDDS v.2.14.0 and before, allows a local attacker to cause a denial of service (DoS) and obtain sensitive information via a crafted history_depth parameter in DurabilityService QoS component.

  • CVE-2025-35973MedAug 11, 2026
    risk 0.29cvss epss 0.00

    Improper handling of values for some Intel(R) Processors within Ring 0: Kernel, Hypervisor and Bare Metal OS may allow an escalation of privilege. Authorized adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result…

  • CVE-2022-4851MedDec 29, 2022
    risk 0.28cvss 5.3epss 0.01

    Improper Handling of Values in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2025-31648LowFeb 10, 2026
    risk 0.25cvss 3.9epss 0.00

    Improper handling of values in the microcode flow for some Intel(R) Processor Family may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially…

  • CVE-2024-30800MedApr 23, 2024
    risk 0.00cvss 5.6epss 0.00

    PX4 Autopilot v.1.14 allows an attacker to fly the drone into no-fly zones by breaching the geofence using flaws in the function.

  • CVE-2024-0607MedJan 18, 2024
    risk 0.00cvss 6.6epss 0.00

    A flaw was found in the Netfilter subsystem in the Linux kernel. The issue is in the nft_byteorder_eval() function, where the code iterates through a loop and writes to the `dst` array. On each iteration, 8 bytes are written, but `dst` is an array of u32, so each element only…