VYPR

CWE-241

Improper Handling of Unexpected Data Type

BaseDraft

Description

The product does not handle or incorrectly handles when a particular element is not the expected type, e.g. it expects a digit (0-9) but is provided with a letter (A-Z).

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-48

CVEs mapped to this weakness (34)

page 1 of 2
  • CVE-2021-40116HigOct 27, 2021
    risk 0.56cvss 8.6epss 0.01

    Multiple Cisco products are affected by a vulnerability in Snort rules that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.The vulnerability is due to improper handling of the Block with Reset or Interactive…

  • CVE-2022-39064HigOct 14, 2022
    risk 0.53cvss 8.1epss 0.00

    An attacker sending a single malformed IEEE 802.15.4 (Zigbee) frame makes the TRÅDFRI bulb blink, and if they replay (i.e. resend) the same frame multiple times, the bulb performs a factory reset. This causes the bulb to lose configuration information about the Zigbee network…

  • CVE-2025-63548HigMay 1, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in Eprosima Micro-XREC-DDS Agent v.3.0.1 allows a remote attacker to cause a denial of service via a packet specially crafted to bear a non-valid value in any Boolean field.

  • CVE-2025-2268HigMar 14, 2025
    risk 0.49cvss 7.5epss 0.00

    The HP LaserJet MFP M232-M237 Printer Series may be vulnerable to a denial of service attack when a specially crafted request message is sent via Internet Printing Protocol (IPP).

  • CVE-2024-21526HigJul 10, 2024
    risk 0.49cvss 7.5epss 0.01

    All versions of the package speaker are vulnerable to Denial of Service (DoS) when providing unexpected input types to the channels property of the Speaker object makes it possible to reach an assert macro. Exploiting this vulnerability can lead to a process crash.

  • CVE-2024-21523HigJul 10, 2024
    risk 0.49cvss 7.5epss 0.01

    All versions of the package images are vulnerable to Denial of Service (DoS) due to providing unexpected input types to several different functions. This makes it possible to reach an assert macro, leading to a process crash. **Note:** By providing some specific integer values…

  • CVE-2022-29181HigMay 20, 2022
    risk 0.47cvss 8.2epss 0.03

    Nokogiri is an open source XML and HTML library for Ruby. Nokogiri prior to version 1.13.6 does not type-check all inputs into the XML and HTML4 SAX parsers, allowing specially crafted untrusted inputs to cause illegal memory access errors (segfault) or reads from unrelated…

  • CVE-2024-0151MedApr 24, 2024
    risk 0.42cvss 6.5epss 0.00

    Insufficient argument checking in Secure state Entry functions in software using Cortex-M Security Extensions (CMSE), that has been compiled using toolchains that implement 'Arm v8-M Security Extensions Requirements on Development Tools' prior to version 1.4, allows an attacker…

  • CVE-2022-39065MedOct 14, 2022
    risk 0.42cvss 6.5epss 0.00

    A single malformed IEEE 802.15.4 (Zigbee) frame makes the TRÅDFRI gateway unresponsive, such that connected lighting cannot be controlled with the IKEA Home Smart app and TRÅDFRI remote control. The malformed Zigbee frame is an unauthenticated broadcast message, which means…

  • CVE-2022-3029HigSep 13, 2022
    risk 0.42cvss 7.5epss 0.01

    In NLnet Labs Routinator 0.9.0 up to and including 0.11.2, due to a mistake in error handling, data in RRDP snapshot and delta files that isn’t correctly base 64 encoded is treated as a fatal error and causes Routinator to exit. Worst case impact of this vulnerability is…

  • CVE-2022-1642HigJun 16, 2022
    risk 0.42cvss 7.5epss 0.01

    A program using swift-corelibs-foundation is vulnerable to a denial of service attack caused by a potentially malicious source producing a JSON document containing a type mismatch. This vulnerability is caused by the interaction between a deserialization mechanism offered by the…

  • CVE-2022-24668HigFeb 9, 2022
    risk 0.42cvss 7.5epss 0.01

    A program using swift-nio-http2 is vulnerable to a denial of service attack caused by a network peer sending ALTSVC or ORIGIN frames. This attack affects all swift-nio-http2 versions from 1.0.0 to 1.19.1. This vulnerability is caused by a logical error after frame parsing but…

  • CVE-2021-39131HigAug 17, 2021
    risk 0.42cvss 7.5epss 0.02

    ced detects character encoding using Google’s compact_enc_det library. In ced v0.1.0, passing data types other than `Buffer` causes the Node.js process to crash. The problem has been patched in ced v1.0.0. As a workaround, before passing an argument to ced, verify it’s a…

  • CVE-2021-0242MedApr 22, 2021
    risk 0.42cvss 6.5epss 0.00

    A vulnerability due to the improper handling of direct memory access (DMA) buffers on EX4300 switches on Juniper Networks Junos OS allows an attacker sending specific unicast frames to trigger a Denial of Service (DoS) condition by exhausting DMA buffers, causing the FPC to…

  • CVE-2023-28961MedApr 17, 2023
    risk 0.38cvss 5.8epss 0.00

    An Improper Handling of Unexpected Data Type vulnerability in IPv6 firewall filter processing of Juniper Networks Junos OS on the ACX Series devices will prevent a firewall filter with the term 'from next-header ah' from being properly installed in the packet forwarding engine…

  • CVE-2022-22219MedOct 18, 2022
    risk 0.38cvss 5.9epss 0.01

    Due to the Improper Handling of an Unexpected Data Type in the processing of EVPN routes on Juniper Networks Junos OS and Junos OS Evolved, an attacker in direct control of a BGP client connected to a route reflector, or via a machine in the middle (MITM) attack, can send a…

  • CVE-2022-22193MedApr 14, 2022
    risk 0.36cvss 5.5epss 0.00

    An Improper Handling of Unexpected Data Type vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenticated attacker with low privileges to cause a Denial of Service (DoS). Continued execution of this command…

  • CVE-2026-47110MedJun 24, 2026
    risk 0.35cvss 6.5epss 0.00

    Tiptap for PHP before version 2.1.1 contains an input validation vulnerability that allows authenticated attackers to cause a denial of service by submitting Tiptap JSON with the attrs.href field set to an array instead of a string, causing an unhandled TypeError in the…

  • CVE-2024-25966MedMay 14, 2024
    risk 0.35cvss 5.3epss 0.01

    Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains an improper handling of unexpected data type vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service.

  • CVE-2023-5215MedSep 28, 2023
    risk 0.35cvss 5.3epss 0.01

    A flaw was found in libnbd. A server can reply with a block size larger than 2^63 (the NBD spec states the size is a 64-bit unsigned value). This issue could lead to an application crash or other unintended behavior for NBD clients that doesn't treat the return value of the…