CWE-1284— Improper Validation of Specified Quantity in Input
185 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1284page 1 of 4
- CVE-2020-27217HIGHCVSS 7.5EG 7.52020-11-13
In Eclipse Hono version 1.3.0 and 1.4.0 the AMQP protocol adapter does not verify the size of AMQP messages received from devices. In particular, a device may send messages that are bigger than the max-message-size that the protocol adapte…
- CVE-2021-0934MEDIUMCVSS 5.5EG 5.52022-12-13
In findAllDeAccounts of AccountsDb.java, there is a possible denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploi…
- CVE-2021-1058HIGHCVSS 7.1EG 7.12021-01-08
NVIDIA vGPU software contains a vulnerability in the guest kernel mode driver and vGPU plugin, in which an input data size is not validated, which may lead to tampering of data or denial of service. This affects vGPU version 8.x (prior to …
- CVE-2021-1062HIGHCVSS 7.1EG 7.12021-01-08
NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which an input data length is not validated, which may lead to tampering of data or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior…
- CVE-2021-1081HIGHCVSS 7.8EG 7.82021-04-29
NVIDIA vGPU software contains a vulnerability in the guest kernel mode driver and Virtual GPU manager (vGPU plugin), in which an input length is not validated, which may lead to information disclosure, tampering of data, or denial of servi…
- CVE-2021-1082HIGHCVSS 7.8EG 7.82021-04-29
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), in which an input length is not validated, which may lead to information disclosure, tampering of data, or denial of service. vGPU version 12.x (prior …
- CVE-2021-1083HIGHCVSS 7.8EG 7.82021-04-29
NVIDIA vGPU software contains a vulnerability in the guest kernel mode driver and Virtual GPU Manager (vGPU plugin), in which an input length is not validated, which may lead to information disclosure, tampering of data, or denial of servi…
- CVE-2021-21943HIGHCVSS 8.8EG 8.82022-04-14
A heap-based buffer overflow vulnerability exists in the XWD parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
- CVE-2021-21950CRITICALCVSS 10.0EG 9.82021-12-08
An out-of-bounds write vulnerability exists in the CMD_DEVICE_GET_SERVER_LIST_REQUEST functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h in function recv_server_device_response_msg_process. A specially-crafted netw…
- CVE-2021-21951CRITICALCVSS 10.0EG 9.82021-12-08
An out-of-bounds write vulnerability exists in the CMD_DEVICE_GET_SERVER_LIST_REQUEST functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h in function read_udp_push_config_file. A specially-crafted network packet can…
- CVE-2021-21960CRITICALCVSS 10.0EG 9.82022-02-04
A stack-based buffer overflow vulnerability exists in both the LLMNR functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted network packet can lead to remote code execution. An attacker can send a malicious pa…
- CVE-2021-26347MEDIUMCVSS 4.7EG 4.72022-05-11
Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service.
- CVE-2021-28510MEDIUMCVSS 5.3EG 7.52023-01-26
For certain systems running EOS, a Precision Time Protocol (PTP) packet of a management/signaling message with an invalid Type-Length-Value (TLV) causes the PTP agent to restart. Repeated restarts of the service will make the service unava…
- CVE-2021-30350HIGHCVSS 8.4EG 7.82022-06-14
Lack of MBN header size verification against input buffer can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables
- CVE-2021-31345HIGHCVSS 7.5EG 9.12021-11-09
A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), PLUSCONTROL 1st Gen (All versions). The total length of an UDP payload (set in the IP hea…
- CVE-2021-31346HIGHCVSS 8.2EG 9.12021-11-09
A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), PLUSCONTROL 1st Gen (All versions), SIMOTICS CONNECT 400 (All versions < V0.5.0.0), SIMOT…
- CVE-2021-31556CRITICALCVSS 9.8EG 9.82021-08-12
An issue was discovered in the Oauth extension for MediaWiki through 1.35.2. MWOAuthConsumerSubmitControl.php does not ensure that the length of an RSA key will fit in a MySQL blob.
- CVE-2021-35132HIGHCVSS 8.4EG 7.82022-09-02
Out of bound write in DSP service due to improper bound check for response buffer size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Weara…
- CVE-2021-3581HIGHCVSS 7.0EG 7.02021-10-05
Buffer Access with Incorrect Length Value in zephyr. Zephyr versions >= >=2.5.0 contain Buffer Access with Incorrect Length Value (CWE-805). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-8q…
- CVE-2021-37674MEDIUMCVSS 5.5EG 5.52021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can trigger a denial of service via a segmentation fault in `tf.raw_ops.MaxPoolGrad` caused by missing validation. The [implementation]…
- CVE-2021-37677MEDIUMCVSS 5.5EG 5.52021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions the shape inference code for `tf.raw_ops.Dequantize` has a vulnerability that could trigger a denial of service via a segfault if an attacker provi…
- CVE-2021-39193MEDIUMCVSS 5.3EG 5.32021-09-03
Frontier is Substrate's Ethereum compatibility layer. Prior to commit number 0b962f218f0cdd796dadfe26c3f09e68f7861b26, a bug in `pallet-ethereum` can cause invalid transactions to be included in the Ethereum block state in `pallet-ethereum…
- CVE-2021-39690MEDIUMCVSS 5.5EG 5.52022-03-16
In setDisplayPadding of WallpaperManagerService.java, there is a possible way to cause a persistent DoS due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User inter…
- CVE-2021-43267CRITICALCVSS 9.8EG 9.82021-11-02
An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. The Transparent Inter-Process Communication (TIPC) functionality allows remote attackers to exploit insufficient validation of user-supplied sizes for the MSG…
- CVE-2021-44158HIGHCVSS 8.0EG 8.02022-01-03
ASUS RT-AX56U Wi-Fi Router is vulnerable to stack-based buffer overflow due to improper validation for httpd parameter length. An authenticated local area network attacker can launch arbitrary code execution to control the system or disrup…
- CVE-2021-44693MEDIUMCVSS 4.9EG 7.52022-12-13
Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device.
- CVE-2021-45462HIGHCVSS 7.5EG 7.52021-12-23
In Open5GS 2.4.0, a crafted packet from UE can crash SGW-U/UPF.
- CVE-2021-45918HIGHCVSS 7.5EG 7.52022-06-20
NHI’s health insurance web service component has insufficient validation for input string length, which can result in heap-based buffer overflow attack. A remote attacker can exploit this vulnerability to flood the memory space reserved …
- CVE-2021-45972HIGHCVSS 7.1EG 7.12022-01-01
The giftrans function in giftrans 1.12.2 contains a stack-based buffer overflow because a value inside the input file determines the amount of data to write. This allows an attacker to overwrite up to 250 bytes outside of the allocated buf…
- CVE-2021-46158HIGHCVSS 7.8EG 7.82022-02-09
A vulnerability has been identified in Simcenter Femap V2020.2 (All versions), Simcenter Femap V2021.1 (All versions). Affected application contains a stack based buffer overflow vulnerability while parsing NEU files. This could allow an a…
- CVE-2021-46893HIGHCVSS 7.5EG 7.52023-07-05
Vulnerability of unstrict data verification and parameter check. Successful exploitation of this vulnerability may affect integrity.
- CVE-2021-47251HIGHCVSS 7.8EG 7.82024-05-21
In the Linux kernel, the following vulnerability has been resolved: mac80211: fix skb length check in ieee80211_scan_rx() Replace hard-coded compile-time constants for header length check with dynamic determination based on the frame typ…
- CVE-2022-0174MEDIUMCVSS 4.3EG 4.32022-01-10
Improper Validation of Specified Quantity in Input vulnerability in dolibarr dolibarr/dolibarr.
- CVE-2022-0214HIGHCVSS 7.5EG 7.52022-02-14
The Custom Popup Builder WordPress plugin before 1.3.1 autoload data from its popup on every pages, as such data can be sent by unauthenticated user, and is not validated in length, this could cause a denial of service on the blog
- CVE-2022-0414MEDIUMCVSS 4.3EG 4.32022-01-31
Improper Validation of Specified Quantity in Input in Packagist dolibarr/dolibarr prior to 16.0.
- CVE-2022-0596MEDIUMCVSS 4.3EG 4.32022-02-15
Improper Validation of Specified Quantity in Input in Packagist microweber/microweber prior to 1.2.11.
- CVE-2022-1174MEDIUMCVSS 4.3EG 7.52022-04-04
A potential DoS vulnerability was discovered in Gitlab CE/EE versions 13.7 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to trigger high CPU usage via a spec…
- CVE-2022-20385CRITICALCVSS 9.8EG 9.82022-09-13
a function called 'nla_parse', do not check the len of para, it will check nla_type (which can be controlled by userspace) with 'maxtype' (in this case, it is GSCAN_MAX), then it access polciy array 'policy[type]', which OOB access happens…
- CVE-2022-20445HIGHCVSS 7.5EG 7.52022-11-08
In process_service_search_rsp of sdp_discovery.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction i…
- CVE-2022-20488HIGHCVSS 7.8EG 7.82022-12-13
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. Us…
- CVE-2022-20491HIGHCVSS 7.8EG 7.82022-12-13
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. Us…
- CVE-2022-20493HIGHCVSS 7.8EG 7.82023-01-26
In Condition of Condition.java, there is a possible way to grant notification access due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is nee…
- CVE-2022-20543LOWCVSS 2.3EG 2.32022-12-16
In multiple locations, there is a possible display crash loop due to improper input validation. This could lead to local denial of service with system execution privileges needed. User interaction is not needed for exploitation.Product: An…
- CVE-2022-20686MEDIUMCVSS 5.3EG 5.32022-12-12
Multiple vulnerabilities in the Link Layer Discovery Protocol (LLDP) functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device an…
- CVE-2022-20687MEDIUMCVSS 5.3EG 5.32022-12-12
Multiple vulnerabilities in the Link Layer Discovery Protocol (LLDP) functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device an…
- CVE-2022-20688MEDIUMCVSS 5.3EG 5.32022-12-12
A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device and cause Cisco Discove…
- CVE-2022-20689MEDIUMCVSS 5.3EG 8.82022-12-12
Multiple vulnerabilities in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, adjacent attacker to cause Cisco Discovery Protocol memory corruption on an af…
- CVE-2022-20690MEDIUMCVSS 5.3EG 8.82022-12-12
Multiple vulnerabilities in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, adjacent attacker to cause Cisco Discovery Protocol memory corruption on an af…
- CVE-2022-20691MEDIUMCVSS 5.3EG 6.52022-12-12
A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Adaptive Telephone Adapter firmware could allow an unauthenticated, adjacent attacker to cause a DoS condition of an affected device. This vulnerabilit…
- CVE-2022-20699CRITICALCVSS 10.0EG 9.8⚠ KEV2022-02-10
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication a…
Map vulnerabilities like CWE-1284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →