VYPR

CWE-241

Improper Handling of Unexpected Data Type

BaseDraft

Description

The product does not handle or incorrectly handles when a particular element is not the expected type, e.g. it expects a digit (0-9) but is provided with a letter (A-Z).

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-48

CVEs mapped to this weakness (34)

page 2 of 2
  • CVE-2025-1004MedFeb 6, 2025
    risk 0.34cvss 5.3epss 0.00

    Certain HP LaserJet Pro printers may potentially experience a denial of service when a user sends a raw JPEG file to the printer via IPP (Internet Printing Protocol).

  • CVE-2024-9423MedOct 2, 2024
    risk 0.34cvss 5.3epss 0.01

    Certain HP LaserJet printers may potentially experience a denial of service when a user sends a raw JPEG file to the printer. The printer displays a “JPEG Unsupported” message which may not clear, potentially blocking queued print jobs.

  • CVE-2024-21935MedSep 23, 2025
    risk 0.33cvss 5.0epss 0.00

    Improper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to manipulate Redfish® API commands to remove files from the local root directory, potentially resulting in data corruption.

  • CVE-2024-21927MedSep 23, 2025
    risk 0.33cvss 5.0epss 0.00

    Improper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to use certain special characters in manipulated Redfish® API commands, causing service processes like OpenBMC to crash and reset, potentially resulting in denial of service.

  • CVE-2021-0243MedApr 22, 2021
    risk 0.31cvss 4.7epss 0.00

    Improper Handling of Unexpected Data in the firewall policer of Juniper Networks Junos OS on EX4300 switches allows matching traffic to exceed set policer limits, possibly leading to a limited Denial of Service (DoS) condition. When the firewall policer discard action fails on a…

  • CVE-2022-20730MedMay 3, 2022
    risk 0.26cvss 4.0epss 0.01

    A vulnerability in the Security Intelligence feed feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the Security Intelligence DNS feed. This vulnerability is due to incorrect feed update processing. An attacker…

  • CVE-2021-32655LowJun 1, 2021
    risk 0.23cvss 3.5epss 0.01

    Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.11, 20.0.10, and 21.0.2, an attacker is able to convert a Files Drop link to a federated share. This causes an issue on the UI side of the sharing user. When the sharing user opens the…

  • CVE-2024-32268LowApr 29, 2024
    risk 0.21cvss 3.3epss 0.00

    An issue in Tuya Smart camera U6N v.3.2.5 allows a remote attacker to cause a denial of service via a crafted packet to the network connection component.

  • CVE-2022-21164LowMar 16, 2022
    risk 0.17cvss 3.7epss 0.01

    The package node-lmdb before 0.9.7 are vulnerable to Denial of Service (DoS) when defining a non-invokable ToString value, which will cause a crash during type check.

  • CVE-2021-32696LowJun 18, 2021
    risk 0.17cvss 3.7epss 0.01

    The npm package "striptags" is an implementation of PHP's strip_tags in Typescript. In striptags before version 3.2.0, a type-confusion vulnerability can cause `striptags` to concatenate unsanitized strings when an array-like object is passed in as the `html` parameter. This can…

  • CVE-2025-7339LowJul 17, 2025
    risk 0.15cvss 3.4epss 0.00

    on-headers is a node.js middleware for listening to when a response writes headers. A bug in on-headers versions `<1.1.0` may result in response headers being inadvertently modified when an array is passed to `response.writeHead()`. Users should upgrade to version 1.1.0 to…

  • CVE-2023-30591HigSep 29, 2023
    risk 0.04cvss 7.5epss 0.54

    Denial-of-service in NodeBB <= v2.8.10 allows unauthenticated attackers to trigger a crash, when invoking `eventName.startsWith()` or `eventName.toString()`, while processing Socket.IO messages via crafted Socket.IO messages containing array or object type for the event name…

  • CVE-2025-66550MedDec 5, 2025
    risk 0.00cvss 5.7epss 0.00

    Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.17 and 5.2.4, when a malicious user creates a calendar event with a crafted attachment that links to a download link of a file on the same Nextcloud server, the file would be downloaded without the user confirming…

  • CVE-2024-37316MedJun 14, 2024
    risk 0.00cvss 4.6epss 0.00

    Nextcloud Calendar is a calendar app for Nextcloud. Authenticated users could create an event with manipulated attachment data leading to a bad redirect for participants when clicked. It is recommended that the Nextcloud Calendar App is upgraded to 4.6.8 or 4.7.2.