CWE-1284— Improper Validation of Specified Quantity in Input
293 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1284page 3 of 6
- CVE-2022-41877MEDIUMCVSS 4.6EG 4.62022-11-16
FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input length validation in `drive` channel. A malicious server can trick a FreeRDP based client to read out of bound data and send it b…
- CVE-2022-41896MEDIUMCVSS 4.8EG 4.82022-11-18
TensorFlow is an open source platform for machine learning. If `ThreadUnsafeUnigramCandidateSampler` is given input `filterbank_channel_count` greater than the allowed max size, TensorFlow will crash. We have patched the issue in GitHub co…
- CVE-2022-41968LOWCVSS 3.5EG 3.52022-12-01
Nextcloud Server is an open source personal cloud server. Prior to versions 23.0.10 and 24.0.5, calendar name lengths are not validated before writing to a database. As a result, an attacker can send unnecessary amounts of data against the…
- CVE-2022-46143LOWCVSS 2.7EG 2.72022-12-13
Affected devices do not check the TFTP blocksize correctly. This could allow an authenticated attacker to read from an uninitialized buffer that potentially contains previously allocated data.
- CVE-2022-47029HIGHCVSS 7.8EG 7.82023-05-30
An issue was found in Action Launcher v50.5 allows an attacker to escalate privilege via modification of the intent string to function update.
- CVE-2022-48297HIGHCVSS 7.5EG 7.52023-02-09
The geofencing kernel code has a vulnerability of not verifying the length of the input data. Successful exploitation of this vulnerability may cause out-of-bounds memory access.
- CVE-2022-48298HIGHCVSS 7.5EG 7.52023-02-09
The geofencing kernel code does not verify the length of the input data. Successful exploitation of this vulnerability may cause out-of-bounds memory access.
- CVE-2022-4904HIGHCVSS 8.6EG 8.62023-03-06
A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact o…
- CVE-2022-50020MEDIUMCVSS 5.5EG 5.52025-06-18
In the Linux kernel, the following vulnerability has been resolved: ext4: avoid resizing to a partial cluster size This patch avoids an attempt to resize the filesystem to an unaligned cluster boundary. An online resize to a size that i…
- CVE-2023-0194LOWCVSS 2.0EG 4.62023-04-01
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer driver, where an invalid display configuration may lead to denial of service.
- CVE-2023-0195LOWCVSS 2.0EG 2.42023-04-01
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer driver nvlddmkm.sys, where an can cause CWE-1284, which may lead to hypothetical Information leak of unimportant data such as local variable data of th…
- CVE-2023-20508MEDIUMCVSS 5.0EG 5.02025-02-12
Improper access control in the ASP could allow a privileged attacker to perform an out-of-bounds write to a memory location not controlled by the attacker, potentially leading to loss of confidentiality, integrity, or availability.
- CVE-2023-20515MEDIUMCVSS 5.7EG 5.72025-02-11
Improper access control in the fTPM driver in the trusted OS could allow a privileged attacker to corrupt system memory, potentially leading to loss of integrity, confidentiality, or availability.
- CVE-2023-20581LOWCVSS 2.5EG 2.52025-02-11
Improper access control in the IOMMU may allow a privileged attacker to bypass RMP checks, potentially leading to a loss of guest memory integrity.
- CVE-2023-20582MEDIUMCVSS 5.3EG 5.32025-02-11
Improper handling of invalid nested page table entries in the IOMMU may allow a privileged attacker to induce page table entry (PTE) faults to bypass RMP checks in SEV-SNP, potentially leading to a loss of guest memory integrity.
- CVE-2023-20704MEDIUMCVSS 5.5EG 5.52023-05-15
In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07…
- CVE-2023-20705MEDIUMCVSS 5.5EG 5.52023-05-15
In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07…
- CVE-2023-20707MEDIUMCVSS 6.7EG 6.72023-05-15
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0762855…
- CVE-2023-20708MEDIUMCVSS 6.7EG 6.72023-05-15
In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0…
- CVE-2023-20709MEDIUMCVSS 4.4EG 4.42023-05-15
In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07…
- CVE-2023-20710MEDIUMCVSS 4.4EG 4.42023-05-15
In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07…
- CVE-2023-20722MEDIUMCVSS 6.7EG 6.72023-05-15
In m4u, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0777…
- CVE-2023-21111MEDIUMCVSS 5.5EG 5.52023-05-15
In several functions of PhoneAccountRegistrar.java, there is a possible way to prevent an access to emergency services due to improper input validation. This could lead to local denial of service with no additional execution privileges nee…
- CVE-2023-22409MEDIUMCVSS 5.5EG 5.52023-01-13
An Unchecked Input for Loop Condition vulnerability in a NAT library of Juniper Networks Junos OS allows a local authenticated attacker with low privileges to cause a Denial of Service (DoS). When an inconsistent "deterministic NAT" config…
- CVE-2023-23549LOWCVSS 2.7EG 2.72023-11-15
Improper Input Validation in Checkmk <2.2.0p15, <2.1.0p37, <=2.0.0p39 allows priviledged attackers to cause partial denial of service of the UI via too long hostnames.
- CVE-2023-23626MEDIUMCVSS 5.9EG 5.92023-02-09
go-bitfield is a simple bitfield package for the go language aiming to be more performant that the standard library. When feeding untrusted user input into the size parameter of `NewBitfield` and `FromBytes` functions, an attacker can trig…
- CVE-2023-25731HIGHCVSS 8.8EG 8.82023-06-02
Due to URL previews in the network panel of developer tools improperly storing URLs, query parameters could potentially be used to overwrite global objects in privileged code. This vulnerability affects Firefox < 110.
- CVE-2023-27941MEDIUMCVSS 5.5EG 5.52023-05-08
A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Ventura 13.3, iOS 15.7.4 and iPadOS 15.7.4, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. An app may be able to disclose kernel memory.
- CVE-2023-27961MEDIUMCVSS 5.5EG 5.52023-05-08
Multiple validation issues were addressed with improved input sanitization. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, macOS Monterey 12.6.4, watchOS 9.4, macOS Big Sur 11.7.5. Import…
- CVE-2023-30082HIGHCVSS 7.5EG 7.52023-06-14
A denial of service attack might be launched against the server if an unusually lengthy password (more than 10000000 characters) is supplied using the osTicket application. This can cause the website to go down or stop responding. When a l…
- CVE-2023-30269HIGHCVSS 8.1EG 8.12023-04-26
CLTPHP <=6.0 is vulnerable to Improper Input Validation via application/admin/controller/Template.php.
- CVE-2023-31304LOWCVSS 2.3EG 2.32024-08-13
Improper input validation in SMU may allow an attacker with privileges and a compromised physical function (PF) to modify the PCIe® lane count and speed, potentially leading to a loss of availability.
- CVE-2023-31310MEDIUMCVSS 5.0EG 5.02024-08-13
Improper input validation in Power Management Firmware (PMFW) may allow an attacker with privileges to send a malformed input for the "set temperature input selection" command, potentially resulting in a loss of integrity and/or availabili…
- CVE-2023-31331LOWCVSS 3.0EG 3.02025-02-11
Improper access control in the DRTM firmware could allow a privileged attacker to perform multiple driver initializations, resulting in stack memory corruption that could potentially lead to loss of integrity or availability.
- CVE-2023-34188HIGHCVSS 7.5EG 7.52023-06-23
The HTTP server in Mongoose before 7.10 accepts requests containing negative Content-Length headers. By sending a single attack payload over TCP, an attacker can cause an infinite loop in which the server continuously reparses that payload…
- CVE-2023-35932HIGHCVSS 7.1EG 7.12023-06-23
jcvi is a Python library to facilitate genome assembly, annotation, and comparative genomics. A configuration injection happens when user input is considered by the application in an unsanitized format and can reach the configuration file.…
- CVE-2023-36839MEDIUMCVSS 6.5EG 6.52023-10-12
An Improper Validation of Specified Quantity in Input vulnerability in the Layer-2 control protocols daemon (l2cpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker who sends specific LLDP pack…
- CVE-2023-38709HIGHCVSS 7.3EG 7.32024-04-04
Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.4.58.
- CVE-2023-38744HIGHCVSS 7.5EG 7.52023-08-03
Denial-of-service (DoS) vulnerability due to improper validation of specified type of input issue exists in the built-in EtherNet/IP port of the CJ Series CJ2 CPU unit and the communication function of the CS/CJ Series EtherNet/IP unit. If…
- CVE-2023-41164HIGHCVSS 7.5EG 7.52023-11-03
In Django 3.2 before 3.2.21, 4.1 before 4.1.11, and 4.2 before 4.2.5, django.utils.encoding.uri_to_iri() is subject to a potential DoS (denial of service) attack via certain inputs with a very large number of Unicode characters.
- CVE-2023-42444HIGHCVSS 8.6EG 8.62023-09-19
phonenumber is a library for parsing, formatting and validating international phone numbers. Prior to versions `0.3.3+8.13.9` and `0.2.5+8.11.3`, the phonenumber parsing code may panic due to a panic-guarded out-of-bounds access on the pho…
- CVE-2023-42447HIGHCVSS 8.6EG 8.62023-09-19
blurhash-rs is a pure Rust implementation of Blurhash, software for encoding images into ASCII strings that can be turned into a gradient of colors representing the original image. In version 0.1.1, the blurhash parsing code may panic due …
- CVE-2023-42448HIGHCVSS 8.1EG 8.12023-10-04
Hydra is the layer-two scalability solution for Cardano. Prior to version 0.13.0, the specification states that the contestation period in the datum of the UTxO at the head validator must stay unchanged as the state progresses from Open to…
- CVE-2023-43665HIGHCVSS 7.5EG 7.52023-11-03
In Django 3.2 before 3.2.22, 4.1 before 4.1.12, and 4.2 before 4.2.6, the django.utils.text.Truncator chars() and words() methods (when used with html=True) are subject to a potential DoS (denial of service) attack via certain inputs with …
- CVE-2023-4439MEDIUMCVSS 4.3EG 4.32023-08-20
A vulnerability was found in SourceCodester Card Holder Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the component Minus Value Handler. The manipulation leads to improper vali…
- CVE-2023-4518MEDIUMCVSS 6.5EG 6.52023-12-01
A vulnerability exists in the input validation of the GOOSE messages where out of range values received and processed by the IED caused a reboot of the device. In order for an attacker to exploit the vulnerability, goose receiving block…
- CVE-2023-52343MEDIUMCVSS 5.5EG 5.52024-04-08
In SecurityCommand message after as security has been actived., there is a possible improper input validation. This could lead to remote information disclosure no additional execution privileges needed
- CVE-2023-54337CRITICALCVSS 9.1EG 7.52026-01-13
Sysax Multi Server 6.95 contains a denial of service vulnerability in the administrative password field that allows attackers to crash the application. Attackers can overwrite the password field with 800 bytes of repeated characters to tri…
- CVE-2023-7332HIGHCVSS 7.1EG 0.02025-12-31
PocketMine-MP versions prior to 4.18.1 contain an improper input validation vulnerability in inventory transaction handling. A remote attacker with a valid player session can request that the server drop more items than are available in th…
- CVE-2024-0111MEDIUMCVSS 4.4EG 4.42024-08-31
NVIDIA CUDA Toolkit contains a vulnerability in command 'cuobjdump' where a user may cause a crash or produce incorrect output by passing a malformed ELF file. A successful exploit of this vulnerability may lead to a limited denial of serv…
Map vulnerabilities like CWE-1284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →