CWE-1284— Improper Validation of Specified Quantity in Input
293 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1284page 4 of 6
- CVE-2024-1610CRITICALCVSS 9.8EG 9.82024-12-18
In OPPO Store APP, there's a possible escalation of privilege due to improper input validation.
- CVE-2024-1714HIGHCVSS 7.1EG 7.12024-02-21
An issue exists in all supported versions of IdentityIQ Lifecycle Manager that can result if an entitlement with a value containing leading or trailing whitespace is requested by an authenticated user in an access request.
- CVE-2024-20149HIGHCVSS 7.5EG 7.52025-01-06
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY0123134…
- CVE-2024-21953MEDIUMCVSS 5.9EG 0.02026-02-10
Improper input validation in IOMMU could allow a malicious hypervisor to reconfigure IOMMU registers resulting in loss of guest data integrity.
- CVE-2024-23593MEDIUMCVSS 6.7EG 6.72024-04-15
A vulnerability was reported in a system recovery bootloader that was part of the Lenovo preloaded Windows 7 and 8 operating systems from 2012 to 2014 that could allow a privileged attacker with local access to modify the boot manager …
- CVE-2024-24690MEDIUMCVSS 5.4EG 5.42024-02-14
Improper input validation in some Zoom clients may allow an authenticated user to conduct a denial of service via network access.
- CVE-2024-24715MEDIUMCVSS 6.5EG 6.52024-05-17
Improper Validation of Specified Quantity in Input vulnerability in The Events Calendar BookIt allows Manipulating Hidden Fields.This issue affects BookIt: from n/a through 2.4.0.
- CVE-2024-27360MEDIUMCVSS 6.0EG 6.02024-07-09
A vulnerability was discovered in Samsung Mobile Processors Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, and Exynos W930 where they do not properly check length of the data, which can lead to a …
- CVE-2024-27362MEDIUMCVSS 4.4EG 4.42024-07-09
A vulnerability was discovered in Samsung Mobile Processors Exynos 1280, Exynos 2200, Exynos 1330, Exynos 1380, and Exynos 2400 where they do not properly check the length of the data, which can lead to a Information disclosure.
- CVE-2024-3036MEDIUMCVSS 5.7EG 5.72024-06-21
Improper Input Validation vulnerability in ABB 800xA Base. An attacker who successfully exploited this vulnerability could cause services to crash by sending specifically crafted messages. This issue affects 800xA Base: from 6.0.0 through…
- CVE-2024-30516HIGHCVSS 7.5EG 7.52026-01-05
Improper Validation of Specified Quantity in Input vulnerability in SaasProject Booking Package allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Booking Package: from n/a through 1.6.27.
- CVE-2024-30527HIGHCVSS 7.5EG 7.52024-05-17
Improper Validation of Specified Quantity in Input vulnerability in Tips and Tricks HQ WP Express Checkout (Accept PayPal Payments) allows Manipulating Hidden Fields.This issue affects WP Express Checkout (Accept PayPal Payments): from n/a…
- CVE-2024-31416MEDIUMCVSS 5.6EG 5.62024-09-13
The Eaton Foreseer software provides multiple customizable input fields for the users to configure parameters in the tool like alarms, reports, etc. Some of these input fields were not checking the length and bounds of the entered value. T…
- CVE-2024-3185MEDIUMCVSS 6.8EG 6.82024-04-23
A key used in logging.json does not follow the least privilege principle by default and is exposed to local users in the Rapid7 Platform. This allows an attacker with local access to a machine with the logging.json file to use that key t…
- CVE-2024-31957MEDIUMCVSS 6.2EG 6.22024-07-09
A vulnerability was discovered in Samsung Mobile Processors Exynos 2200 and Exynos 2400 where they lack a check for the validation of native handles, which can result in a DoS(Denial of Service) attack by unmapping an invalid length.
- CVE-2024-3317MEDIUMCVSS 6.5EG 6.52024-05-15
An improper access control was identified in the Identity Security Cloud (ISC) message server API that allowed an authenticated user to exfiltrate job processing metadata (opaque messageIDs, work queue depth and counts) for other tenants.
- CVE-2024-35963HIGHCVSS 7.1EG 7.12024-05-20
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sock: Fix not validating setsockopt user input Check user input length before copying data.
- CVE-2024-35964HIGHCVSS 7.1EG 7.12024-05-20
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: Fix not validating setsockopt user input Check user input length before copying data.
- CVE-2024-35965HIGHCVSS 7.1EG 7.12024-05-20
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix not validating setsockopt user input Check user input length before copying data.
- CVE-2024-36346MEDIUMCVSS 6.0EG 6.02025-09-06
Improper input validation in AMD Power Management Firmware (PMFW) could allow a privileged attacker from Guest VM to send arbitrary input data potentially causing a GPU Reset condition.
- CVE-2024-38659HIGHCVSS 7.1EG 7.12024-06-21
In the Linux kernel, the following vulnerability has been resolved: enic: Validate length of nl attributes in enic_set_vf_port enic_set_vf_port assumes that the nl attribute IFLA_PORT_PROFILE is of length PORT_PROFILE_MAX and that the nl…
- CVE-2024-39343HIGHCVSS 7.0EG 7.02024-12-02
An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, Modem 5123, and Modem 5300. The baseband software does not properly check the length specified by the MM (Mob…
- CVE-2024-39697HIGHCVSS 8.6EG 8.62024-07-09
phonenumber is a library for parsing, formatting and validating international phone numbers. Since 0.3.4, the phonenumber parsing code may panic due to a panic-guarded out-of-bounds access on the phonenumber string. In a typical deployment…
- CVE-2024-41991HIGHCVSS 7.5EG 7.52024-08-07
An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize and urlizetrunc template filters, and the AdminURLFieldWidget widget, are subject to a potential denial-of-service attack via certain inputs with a very l…
- CVE-2024-42416HIGHCVSS 8.8EG 8.42024-09-05
The ctl_report_supported_opcodes function did not sufficiently validate a field provided by userspace, allowing an arbitrary write to a limited amount of kernel help memory. Malicious software running in a guest VM that exposes virtio_scs…
- CVE-2024-45351HIGHCVSS 7.8EG 7.82025-03-26
A code execution vulnerability exists in the Xiaomi Game center application product. The vulnerability is caused by improper input validation and can be exploited by attackers to execute malicious code.
- CVE-2024-47257HIGHCVSS 7.5EG 7.52024-11-26
Florent Thiéry has found that selected Axis devices were vulnerable to handling certain ethernet frames which could lead to the Axis device becoming unavailable in the network. Axis has released patched AXIS OS versions for the highlight…
- CVE-2024-48290MEDIUMCVSS 4.3EG 4.32024-11-07
An issue in the Bluetooth Low Energy implementation of Realtek RTL8762E BLE SDK v1.4.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted ll_terminate_ind packet.
- CVE-2024-5102HIGHCVSS 7.0EG 7.02024-06-10
A sym-linked file accessed via the repair function in Avast Antivirus <24.2 on Windows may allow user to elevate privilege to delete arbitrary files or run processes as NT AUTHORITY\SYSTEM. The vulnerability exists within the "Repair" (se…
- CVE-2024-52901MEDIUMCVSS 6.5EG 6.52024-12-12
IBM InfoSphere Information Server 11.7 could allow an authenticated user to GUI to not load or stop working due to improper input validation.
- CVE-2024-53878LOWCVSS 2.8EG 2.82025-02-25
NVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in the cuobjdump binary, where a user could cause a crash by passing a malformed ELF file to cuobjdump. A successful exploit of this vulnerability might lead to a partial d…
- CVE-2024-53879LOWCVSS 2.8EG 2.82025-02-25
NVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in the cuobjdump binary, where a user could cause a crash by passing a malformed ELF file to cuobjdump. A successful exploit of this vulnerability might lead to a partial d…
- CVE-2024-55407HIGHCVSS 7.8EG 7.82025-01-06
An issue in the DeviceloControl function of ITE Tech. Inc ITE IO Access v1.0.0.0 allows attackers to perform arbitrary port read and write actions via supplying crafted IOCTL requests.
- CVE-2024-56716MEDIUMCVSS 5.5EG 5.52024-12-29
In the Linux kernel, the following vulnerability has been resolved: netdevsim: prevent bad user input in nsim_dev_health_break_write() If either a zero count or a large one is provided, kernel can crash.
- CVE-2024-5931MEDIUMCVSS 6.3EG 6.32024-09-13
BT: Unchecked user input in bap_broadcast_assistant
- CVE-2024-6068HIGHCVSS 7.3EG 7.32024-11-14
A memory corruption vulnerability exists in the affected products when parsing DFT files. Local threat actors can exploit this issue to disclose information and to execute arbitrary code. To exploit this vulnerability a legitimate user mu…
- CVE-2024-6768MEDIUMCVSS 6.8EG 0.02024-08-12
A Denial of Service in CLFS.sys in Microsoft Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, and Windows Server 2022 allows a malicious authenticated low-privilege user to cause a Blue Screen of Death via a forced call to…
- CVE-2024-7316MEDIUMCVSS 5.9EG 5.92024-10-17
Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric CNC Series allows a remote unauthenticated attacker to cause Denial of Service (DoS) condition on the product by sending specially crafted packets to T…
- CVE-2024-7488MEDIUMCVSS 5.3EG 5.32024-12-04
Integer Overflow or Wraparound, Improper Validation of Specified Quantity in Input vulnerability in RestApp Inc. Online Ordering System allows Integer Attacks. This issue affects Online Ordering System: 8.2.1. NOTE: Vulnerability…
- CVE-2024-8000MEDIUMCVSS 5.3EG 5.32025-03-04
On affected platforms running Arista EOS with 802.1X configured, certain conditions may occur where a dynamic ACL is received from the AAA server resulting in only the first line of the ACL being installed after an Accelerated Software Upg…
- CVE-2024-8508MEDIUMCVSS 5.3EG 5.32024-10-03
NLnet Labs Unbound up to and including version 1.21.0 contains a vulnerability when handling replies with very large RRsets that it needs to perform name compression for. Malicious upstreams responses with very large RRsets can cause Unbou…
- CVE-2024-8558MEDIUMCVSS 4.3EG 4.32024-09-07
A vulnerability classified as problematic was found in SourceCodester Food Ordering Management System 1.0. This vulnerability affects unknown code of the file /foms/routers/place-order.php of the component Price Handler. The manipulation o…
- CVE-2024-8887CRITICALCVSS 10.0EG 10.02024-09-18
CIRCUTOR Q-SMT in its firmware version 1.0.4, could be affected by a denial of service (DoS) attack if an attacker with access to the web service bypasses the authentication mechanisms on the login page, allowing the attacker to use all th…
- CVE-2024-9369CRITICALCVSS 9.6EG 5.52024-11-27
Insufficient data validation in Mojo in Google Chrome prior to 129.0.6668.89 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: …
- CVE-2024-9448HIGHCVSS 7.5EG 7.52025-05-08
On affected platforms running Arista EOS with Traffic Policies configured the vulnerability will cause received untagged packets not to hit Traffic Policy rules that they are expected to hit. If the rule was to drop the packet, the packet …
- CVE-2025-0038MEDIUMCVSS 6.6EG 6.62025-10-06
In AMD Zynq UltraScale+ devices, the lack of address validation when executing CSU runtime services through the PMU Firmware can allow access to isolated or protected memory spaces resulting in the loss of integrity and confidentiality.
- CVE-2025-0285HIGHCVSS 7.8EG 7.82025-03-03
Various Paragon Software products contain an arbitrary kernel memory mapping vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to perform privil…
- CVE-2025-0286HIGHCVSS 8.4EG 8.42025-03-03
Various Paragon Software products contain an arbitrary kernel memory write vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to execute arbitrar…
- CVE-2025-10094MEDIUMCVSS 6.5EG 6.52025-09-12
An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed authenticated users to disrupt access to token listings and related administrat…
- CVE-2025-10259MEDIUMCVSS 5.3EG 5.32025-11-06
Improper Validation of Specified Quantity in Input vulnerability in TCP Communication Function on Mitsubishi Electric Corporation MELSEC iQ-F Series CPU module allows a remote attacker to disconnect the connection by sending specially craf…
Map vulnerabilities like CWE-1284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →