CWE-1284— Improper Validation of Specified Quantity in Input
The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.— MITRE CWE catalog
439 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1284page 3 of 9
- CVE-2022-26127HIGHCVSS 7.8EG 7.82022-03-03
A buffer overflow vulnerability exists in FRRouting through 8.1.0 due to missing a check on the input packet length in the babel_packet_examin function in babeld/message.c.
- CVE-2022-26125HIGHCVSS 7.8EG 7.82022-03-03
Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the input packet length in isisd/isis_tlvs.c.
- CVE-2021-46158HIGHCVSS 7.8EG 7.82022-02-09
A vulnerability has been identified in Simcenter Femap V2020.2 (All versions), Simcenter Femap V2021.1 (All versions). Affected application contains a stack based buffer overflow vulnerability while parsing NEU files. This could allow an a…
- CVE-2021-1083HIGHCVSS 7.8EG 7.82021-04-29
NVIDIA vGPU software contains a vulnerability in the guest kernel mode driver and Virtual GPU Manager (vGPU plugin), in which an input length is not validated, which may lead to information disclosure, tampering of data, or denial of servi…
- CVE-2021-1082HIGHCVSS 7.8EG 7.82021-04-29
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), in which an input length is not validated, which may lead to information disclosure, tampering of data, or denial of service. vGPU version 12.x (prior …
- CVE-2021-1081HIGHCVSS 7.8EG 7.82021-04-29
NVIDIA vGPU software contains a vulnerability in the guest kernel mode driver and Virtual GPU manager (vGPU plugin), in which an input length is not validated, which may lead to information disclosure, tampering of data, or denial of servi…
- CVE-2026-48977HIGHCVSS 7.7EG 7.72026-09-17
OpenSlide is a C library for reading whole slide image files. From 3.4.1 until 4.0.1, OpenSlide's parse_level0_xml() processing in src/openslide-vendor-ventana.c accepts nonpositive row or column tile counts from a crafted Ventana BIF file…
- CVE-2026-20313HIGHCVSS 7.7EG 7.72026-08-05
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that ad…
- CVE-2022-36063HIGHCVSS 7.6EG 7.62022-10-10
Azure RTOS USBx is a USB host, device, and on-the-go (OTG) embedded stack, fully integrated with Azure RTOS ThreadX and available for all Azure RTOS ThreadX–supported processors. Azure RTOS USBX implementation of host support for USB CDC…
- CVE-2026-86133HIGHCVSS 7.5EG 7.52026-09-29
An integer underflow vulnerability in the WatchGuard Fireware OS IKE daemon (iked) allows a remote attacker who has completed the initial IKEv2 handshake to crash the iked process by sending a specially crafted encrypted IKEv2 message, res…
- CVE-2026-97057HIGHCVSS 7.5EG 7.52026-09-24
redis-parser through 3.0.0 fails to validate the multi-bulk length value in RESP protocol parsing, allowing attackers to trigger an uncaught RangeError by supplying an excessively large declared length. A malicious or compromised Redis end…
- CVE-2026-94450HIGHCVSS 7.5EG 7.52026-09-22
Improper validation of the Destination Connection ID length in s2n-quic 1.88.0 and earlier may allow an unauthenticated remote user to cause a denial of service by shutting down a server endpoint via a single crafted UDP datagram. Only ser…
- CVE-2026-93345HIGHCVSS 7.5EG 7.52026-09-22
MikroTik RouterOS before 7.25beta4 contains an improper input validation vulnerability in the labelled-VPN NLRI iterators of the routing service that allows an unauthenticated on-path attacker to crash the BGP service by sending a malforme…
- CVE-2026-93749HIGHCVSS 7.5EG 7.52026-09-18
source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attackers to specify arbitrary numeric values. Attackers can supply extremely large offset line values that cause synchronous …
- CVE-2026-83115HIGHCVSS 7.5EG 7.52026-09-15
Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Command Line - RapidClone). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated a…
- CVE-2026-69210HIGHCVSS 7.5EG 7.52026-09-15
Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, WebSocket FrameTranscoder.bodyLength rejects extended payload lengths above Integer.MAX_VALUE but permits negative 64-bit lengths. A remote client that complete…
- CVE-2026-76442HIGHCVSS 7.5EG 7.52026-09-14
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review res…
- CVE-2026-87962HIGHCVSS 7.5EG 7.52026-09-10
t-digest versions 3.1 through 3.3 contain a denial of service vulnerability in MergingDigest.fromBytes that fails to validate length and capacity fields from serialized data. Attackers can supply crafted serialized digests with mismatched …
- CVE-2026-16025HIGHCVSS 7.5EG 7.52026-09-08
Improper validation of specified quantity in input vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API WHMCS Module allows Input Data Manipulation. This issue affects PayTR Virtual Pos iFrame …
- CVE-2026-82397HIGHCVSS 7.5EG 7.52026-08-31
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parses application/x-www-form-urlencoded request bodies with urllib.parse.parse_qs in tornado/escape.py without passing max_num_fields. RequestH…
- CVE-2026-76763HIGHCVSS 7.5EG 7.52026-08-31
A flaw was found in SmallRye GraphQL. The number scalar coercion for BigInteger does not properly validate the magnitude of float or string inputs. An unauthenticated remote attacker can exploit this by sending a GraphQL query containing a…
- CVE-2026-19873HIGHCVSS 7.5EG 7.52026-08-31
HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an unbounded repeat count from the query string in Repeatable elements. When a Repeatable element has counter_name set, its process method reads the repeat count fr…
- CVE-2026-53587HIGHCVSS 7.5EG 7.52026-08-20
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixed-size strncmp in s…
- CVE-2026-75897HIGHCVSS 7.5EG 7.52026-08-18
Improper input validation in the capabilities route handler in OpenSearch Dashboards - the size of the request payload is not bounded - might allow remote attackers to cause a denial of service via a crafted HTTP request.
- CVE-2026-19566HIGHCVSS 7.5EG 7.52026-08-12
Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via unbounded IPv6 prefix lengths. The _encode method accepts any prefix length matching `(0|[1-9][0-9]*)` and passes it to _width2bits(), which…
- CVE-2026-71314HIGHCVSS 7.5EG 7.52026-08-05
Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an unauthenticated attacker can use a server island v-for prop, including vforToArray and , to trigger unbounded SSR memory allocation until M…
- CVE-2026-70378HIGHCVSS 7.5EG 7.52026-08-05
imagecli's pipeline operation (Carve::apply in src/image_ops.rs) only asserts , never validating that the ratio is positive. A negative ratio (e.g. -5) causes the computed target width to saturate to 0 via Rust's defined float-to-uint cast…
- CVE-2026-54890HIGHCVSS 7.5EG 7.52026-07-27
Integer Underflow (Wrap or Wraparound) vulnerability in erlang otp erlang/otp (erts modules), erlang otp erts (erts modules) allows Forced Integer Overflow, Excessive Allocation. This vulnerability is associated with program files erts/emu…
- CVE-2026-59532HIGHCVSS 7.5EG 7.52026-07-27
Unauthenticated Other Vulnerability Type in Booking and Rental Manager <= 2.7.2 versions.
- CVE-2026-59531HIGHCVSS 7.5EG 7.52026-07-27
Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2.10.0 versions.
- CVE-2026-11721HIGHCVSS 7.5EG 7.52026-07-22
It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes `named` to produce a wildcard name for a zone that is shorter than the…
- CVE-2026-32665HIGHCVSS 7.5EG 7.52026-07-22
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstream DNS-over-QUIC (DoQ) is enabled, the first two bidirectional streams on a new QUIC connection (stream_id 0 and 4) bypass the per-stream 'quic-size' gate entirely, and …
- CVE-2026-47667HIGHCVSS 7.5EG 7.52026-07-21
CImg Library is a C++ library for image processing. Prior to version 4.0.0 in `_load_analyze()`, the header_size field is read as an `unsigned int` from the first 4 bytes of an Analyze/NIfTI file and passed directly to `new unsigned char[h…
- CVE-2026-50285HIGHCVSS 7.5EG 7.52026-07-15
Pomerium is an identity and context-aware access proxy. Prior to 0.32.8, decodeQueryStringV2 in pkg/hpke/url.go performs zstd decompression of attacker-controlled data without an output-memory limit when DecryptURLValues processes HPKE V2 …
- CVE-2026-57023HIGHCVSS 7.5EG 7.52026-07-09
An Improper Validation of Specified Quantity in Input vulnerability in the TCP proxy plugin of Juniper Networks Junos OS on MX Series with SPC3, and SRX Series allows an unauthenticated, network-based attacker to cause a complete Denial of…
- CVE-2026-59879HIGHCVSS 7.5EG 7.52026-07-08
Immutable.js provides many Persistent Immutable data structures. Prior to 4.3.9 and 5.1.8, List#set, List#setSize, List#setIn, List#updateIn, and the functional set, setIn, and updateIn mishandle an index or size in the range 2 ** 30 to 2 …
- CVE-2026-54234HIGHCVSS 7.5EG 7.52026-07-06
vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, a frontend-legal multi-request speculative decoding workload can cause the rejection sampler to produce a recovered token equal to the m…
- CVE-2026-55952HIGHCVSS 7.5EG 7.52026-07-02
The Erlang/OTP ssl application does not validate that the PSK identity list and binder list carried in a TLS 1.3 ClientHello pre-shared key extension have equal length before passing them to the session ticket handler. In tls_handshake_1_3…
- CVE-2026-49078HIGHCVSS 7.5EG 7.52026-06-15
Unauthenticated Other Vulnerability Type in WP Travel Engine <= 6.7.10 versions.
- CVE-2026-49110HIGHCVSS 7.5EG 7.52026-06-15
Unauthenticated Broken Authentication in Upsell Order Bump Offer for WooCommerce <= 3.1.4 versions.
- CVE-2026-45441HIGHCVSS 7.5EG 7.52026-06-15
Unauthenticated Other Vulnerability Type in WpEvently <= 5.3.3 versions.
- CVE-2026-49218HIGHCVSS 7.5EG 7.52026-06-10
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, a missing check in the DCM decoder could result in an image with invalid dimensions and that could cau…
- CVE-2026-44635HIGHCVSS 7.5EG 7.52026-05-27
Kysely is a type-safe TypeScript SQL query builder. From 0.26.0 to 0.28.16, DefaultQueryCompiler.visitJSONPathLeg does not escape JSON-path metacharacters (., [, ], *, **, ?). When attacker-controlled input flows into eb.ref(col, '->$').ke…
- CVE-2026-8047HIGHCVSS 7.5EG 7.52026-05-26
The affected products perform improper length checking when parsing incoming HTTP requests, resulting in a size-limited out-of-bounds write. An unauthenticated remote attacker can exploit this flaw to cause a denial of service via a system…
- CVE-2026-39829HIGHCVSS 7.5EG 7.52026-05-22
The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This co…
- CVE-2026-8813HIGHCVSS 7.5EG 7.52026-05-19
This affects versions of the package exifreader before 4.39.0. A crafted image containing an ICC mluc tag can set an attacker-controlled record count together with a zero record size. During parsing, ExifReader repeatedly processes the sam…
- CVE-2026-44826HIGHCVSS 7.5EG 7.52026-05-15
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.2, Vvveb CMS does not validate the sign of the quantity parameter on the cart-add endpoint. Submitting a negative intege…
- CVE-2025-14869HIGHCVSS 7.5EG 7.52026-05-14
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause denial of service by sending specially c…
- CVE-2026-25863HIGHCVSS 7.5EG 7.52026-05-04
Conditional Fields for Contact Form 7 WordPress plugin through version 2.7.2 contains an uncontrolled resource consumption vulnerability in the Wpcf7cfMailParser class where the hide_hidden_mail_fields_regex_callback() method reads an iter…
- CVE-2025-70069HIGHCVSS 7.5EG 7.52026-05-04
An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXConverter.cpp and ConvertMeshMultiMaterial() method
Map vulnerabilities like CWE-1284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →