CWE-1284— Improper Validation of Specified Quantity in Input
The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.— MITRE CWE catalog
439 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1284page 2 of 9
- CVE-2025-12385HIGHCVSS 8.7EG 8.72025-12-03
Allocation of Resources Without Limits or Throttling, Improper Validation of Specified Quantity in Input vulnerability in The Qt Company Qt on Windows, MacOS, Linux, iOS, Android, x86, ARM, 64 bit, 32 bit allows Excessive Allocation. Thi…
- CVE-2025-8424HIGHCVSS 8.7EG 8.72025-08-26
Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway when an attacker can get access to the appliance NSIP, Cluster Management IP or local GSLB Site IP or SNIP with Management Access
- CVE-2026-102730HIGHCVSS 8.6EG 8.62026-09-29
Mounting an attacker-controlled NAND flash image (`lx_nand_flash_open()`) triggers an unbounded out-of-bounds heap **write** in LevelX's NAND flash-translation-layer metadata parser that overwrites a driver function pointer in the control …
- CVE-2026-56035HIGHCVSS 8.6EG 8.62026-06-26
Unauthenticated Multiple Vulnerabilities in BitFire Security <= 5.0.3 versions.
- CVE-2025-48507HIGHCVSS 8.6EG 8.62025-11-23
The security state of the calling processor into Trusted Firmware (TF-A) is not used and could potentially allow non-secure processors access to secure memories, access to crypto operations, and the ability to turn on and off subsystems wi…
- CVE-2024-39697HIGHCVSS 8.6EG 8.62024-07-09
phonenumber is a library for parsing, formatting and validating international phone numbers. Since 0.3.4, the phonenumber parsing code may panic due to a panic-guarded out-of-bounds access on the phonenumber string. In a typical deployment…
- CVE-2022-4904HIGHCVSS 8.6EG 8.62023-03-06
A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact o…
- CVE-2022-4989HIGHCVSS 8.5EG 8.52026-07-03
** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to access unintended memory regions via crafted IOCTL requests, leading to privilege escalation. Refer t…
- CVE-2022-24754HIGHCVSS 8.5EG 8.52022-03-11
PJSIP is a free and open source multimedia communication library written in C language. In versions prior to and including 2.12 PJSIP there is a stack-buffer overflow vulnerability which only impacts PJSIP users who accept hashed digest cr…
- CVE-2025-0286HIGHCVSS 8.4EG 8.42025-03-03
Various Paragon Software products contain an arbitrary kernel memory write vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to execute arbitrar…
- CVE-2022-36086HIGHCVSS 8.4EG 8.42022-09-07
linked_list_allocator is an allocator usable for no_std systems. Prior to version 0.10.2, the heap initialization methods were missing a minimum size check for the given heap size argument. This could lead to out-of-bound writes when a hea…
- CVE-2021-35132HIGHCVSS 8.4EG 8.42022-09-02
Out of bound write in DSP service due to improper bound check for response buffer size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Weara…
- CVE-2022-35928HIGHCVSS 8.4EG 8.42022-08-03
AES Crypt is a file encryption software for multiple platforms. AES Crypt for Linux built using the source on GitHub and having the version number 3.11 has a vulnerability with respect to reading user-provided passwords and confirmations v…
- CVE-2021-30350HIGHCVSS 8.4EG 8.42022-06-14
Lack of MBN header size verification against input buffer can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables
- CVE-2026-82750HIGHCVSS 8.3EG 8.32026-09-06
Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have the sponsor pay for EIP-7702 account dele…
- CVE-2026-82751HIGHCVSS 8.3EG 8.32026-09-06
Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have the sponsor pay for provisioning an acces…
- CVE-2026-59694HIGHCVSS 8.3EG 8.32026-07-17
Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per payment by a large multiplier, degrading the sponsor's operating margin. When the mpp Elixir…
- CVE-2026-59695HIGHCVSS 8.3EG 8.32026-07-17
Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet in a single request by naming an arbitrarily high gas price. When the mpp Elixir library is configured…
- CVE-2026-55706HIGHCVSS 8.3EG 8.32026-06-17
sppp_pap_input in sys/net/if_spppsubr.c in OpenBSD before 076e2b1 allows authentication bypass via certain zero values for lengths.
- CVE-2026-103065HIGHCVSS 8.2EG 8.22026-10-03
Improper Validation of Specified Quantity in Input vulnerability in Themeum Kirki kirki allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Kirki: from n/a through 6.3.1.
- CVE-2026-94636HIGHCVSS 8.2EG 8.22026-10-02
Improper handling of highly compressed data (data amplification), Function call with incorrectly specified arguments, Improper validation of specified quantity in input vulnerability in Apache Thrift py bindings. This issue affects Apac…
- CVE-2026-94645HIGHCVSS 8.2EG 8.22026-10-02
Improper validation of specified quantity in input, Allocation of resources without limits or throttling vulnerability in Apache Thrift nodejs bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrad…
- CVE-2026-59252HIGHCVSS 8.2EG 8.22026-07-17
Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet, resulting in denial of service for legitimate clients. When the mpp Elixir library is configured as f…
- CVE-2026-42013HIGHCVSS 8.2EG 8.22026-05-26
A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker to…
- CVE-2026-5260HIGHCVSS 8.2EG 8.22026-05-26
A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption…
- CVE-2026-66374HIGHCVSS 8.1EG 8.12026-07-25
Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.
- CVE-2026-31971HIGHCVSS 8.1EG 8.12026-03-18
HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data using a variety of encodings and compression methods. When reading data encoded using the `BYTE_A…
- CVE-2026-31970HIGHCVSS 8.1EG 8.12026-03-18
HTSlib is a library for reading and writing bioinformatics file formats. GZI files are used to index block-compressed GZIP [BGZF] files. In the GZI loading function, `bgzf_index_load_hfile()`, it was possible to trigger an integer overflo…
- CVE-2025-36094HIGHCVSS 8.1EG 8.12026-02-03
IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 007 could allow an authenticated user to cause a denial of service or corrupt existin…
- CVE-2023-42448HIGHCVSS 8.1EG 8.12023-10-04
Hydra is the layer-two scalability solution for Cardano. Prior to version 0.13.0, the specification states that the contestation period in the datum of the UTxO at the head validator must stay unchanged as the state progresses from Open to…
- CVE-2023-30269HIGHCVSS 8.1EG 8.12023-04-26
CLTPHP <=6.0 is vulnerable to Improper Input Validation via application/admin/controller/Template.php.
- CVE-2022-24903HIGHCVSS 8.1EG 8.12022-05-06
Rsyslog is a rocket-fast system for log processing. Modules for TCP syslog reception have a potential heap buffer overflow when octet-counted framing is used. This can result in a segfault or some other malfunction. As of our understanding…
- CVE-2022-2868HIGHCVSS 5.5EG 8.12022-08-17
libtiff's tiffcrop utility has a improper input validation flaw that can lead to out of bounds read and ultimately cause a crash if an attacker is able to supply a crafted file to tiffcrop.
- CVE-2022-21668HIGHCVSS 8.0EG 8.02022-01-10
pipenv is a Python development workflow tool. Starting with version 2018.10.9 and prior to version 2022.1.8, a flaw in pipenv's parsing of requirements files allows an attacker to insert a specially crafted string inside a comment anywhere…
- CVE-2021-44158HIGHCVSS 8.0EG 8.02022-01-03
ASUS RT-AX56U Wi-Fi Router is vulnerable to stack-based buffer overflow due to improper validation for httpd parameter length. An authenticated local area network attacker can launch arbitrary code execution to control the system or disrup…
- CVE-2026-12974HIGHCVSS 7.9EG 7.92026-09-23
A Security Policy Bypass vulnerability exists in Forcepoint Security Engine (NGFW). This issue affects Forcepoint Security Engine (NGFW): from 7.1.0 through 7.1.13, from 7.3.0 through 7.3.1, 7.3.3, from 7.4.0 through 7.4.1, and 7.5.0.
- CVE-2026-45201HIGHCVSS 7.8EG 7.82026-08-21
Software installed and run as a non-privileged user may conduct improper GPU system calls to pass invalid log2 page size when allocating physical pages leading to OOB read and/or write due to improper validation of the said value. Such …
- CVE-2025-25178HIGHCVSS 7.8EG 7.82025-04-04
Software installed and run as a non-privileged user may conduct improper GPU system calls to cause kernel system memory corruption.
- CVE-2024-45351HIGHCVSS 7.8EG 7.82025-03-26
A code execution vulnerability exists in the Xiaomi Game center application product. The vulnerability is caused by improper input validation and can be exploited by attackers to execute malicious code.
- CVE-2025-0285HIGHCVSS 7.8EG 7.82025-03-03
Various Paragon Software products contain an arbitrary kernel memory mapping vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to perform privil…
- CVE-2024-55407HIGHCVSS 7.8EG 7.82025-01-06
An issue in the DeviceloControl function of ITE Tech. Inc ITE IO Access v1.0.0.0 allows attackers to perform arbitrary port read and write actions via supplying crafted IOCTL requests.
- CVE-2021-47251HIGHCVSS 7.8EG 7.82024-05-21
In the Linux kernel, the following vulnerability has been resolved: mac80211: fix skb length check in ieee80211_scan_rx() Replace hard-coded compile-time constants for header length check with dynamic determination based on the frame typ…
- CVE-2022-47029HIGHCVSS 7.8EG 7.82023-05-30
An issue was found in Action Launcher v50.5 allows an attacker to escalate privilege via modification of the intent string to function update.
- CVE-2022-20493HIGHCVSS 7.8EG 7.82023-01-26
In Condition of Condition.java, there is a possible way to grant notification access due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is nee…
- CVE-2022-20491HIGHCVSS 7.8EG 7.82022-12-13
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. Us…
- CVE-2022-20488HIGHCVSS 7.8EG 7.82022-12-13
In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. Us…
- CVE-2022-2845HIGHCVSS 7.8EG 7.82022-08-17
Improper Validation of Specified Quantity in Input in GitHub repository vim/vim prior to 9.0.0218.
- CVE-2022-25793HIGHCVSS 7.8EG 7.82022-08-10
A Stack-based Buffer Overflow Vulnerability in Autodesk 3ds Max 2022, 2021, and 2020 may lead to code execution through the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buf…
- CVE-2022-22072HIGHCVSS 7.8EG 7.82022-06-14
Buffer overflow can occur due to improper validation of NDP application information length in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon…
- CVE-2022-26128HIGHCVSS 7.8EG 7.82022-03-03
A buffer overflow vulnerability exists in FRRouting through 8.1.0 due to a wrong check on the input packet length in the babel_packet_examin function in babeld/message.c.
Map vulnerabilities like CWE-1284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →