CWE-1284— Improper Validation of Specified Quantity in Input
The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.— MITRE CWE catalog
439 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1284page 4 of 9
- CVE-2026-1092HIGHCVSS 7.5EG 7.52026-04-08
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an unauthenticated user to cause denial of service due to improper input v…
- CVE-2025-12664HIGHCVSS 7.5EG 7.52026-04-08
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an unauthenticated user to cause denial of service by sending repeated Grap…
- CVE-2026-30573HIGHCVSS 7.5EG 7.52026-04-01
A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0. The vulnerability is located in the add-sales.php file. The application fails to validate the "txtprice" and "txttotalcost" parameters, allowin…
- CVE-2026-30575HIGHCVSS 7.5EG 7.52026-03-27
A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-stock.php file. The application fails to validate the "txtqty" parameter during stock entry, allowing negative values to be processed…
- CVE-2026-2229HIGHCVSS 7.5EG 7.52026-03-12
ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the server_max_window_bits parameter in the permessage-deflate extension. When a WebSocket client connects to a server, it automa…
- CVE-2026-1528HIGHCVSS 7.5EG 7.52026-03-12
ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state, and throws a fatal TypeError that terminates the process.…
- CVE-2025-14513HIGHCVSS 7.5EG 7.52026-03-11
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service condition due to improp…
- CVE-2026-29062HIGHCVSS 7.5EG 7.52026-03-06
jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. From version 3.0.0 to before version 3.1.0, the UTF8DataInputJsonParser, which is used when parsing from a jav…
- CVE-2026-2597HIGHCVSS 7.5EG 7.52026-02-27
Crypt::SysRandom::XS versions before 0.010 for Perl is vulnerable to a heap buffer overflow in the XS function random_bytes(). The function does not validate that the length parameter is non-negative. If a negative value (e.g. -1) is supp…
- CVE-2025-14511HIGHCVSS 7.5EG 7.52026-02-25
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthenticated user to cause denial of service by sending specially craft…
- CVE-2026-2474HIGHCVSS 7.5EG 7.52026-02-16
Crypt::URandom versions from 0.41 before 0.55 for Perl is vulnerable to a heap buffer overflow in the XS function crypt_urandom_getrandom(). The function does not validate that the length parameter is non-negative. If a negative value (e.…
- CVE-2026-23864HIGHCVSS 7.5EG 7.52026-01-26
Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack. The vulnerabilities are triggered by sending spe…
- CVE-2021-47831HIGHCVSS 7.5EG 7.52026-01-16
Sandboxie 5.49.7 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the container folder input field. Attackers can paste a large buffer of repeated characters into the Sandbox containe…
- CVE-2021-47827HIGHCVSS 7.5EG 7.52026-01-16
WebSSH for iOS 14.16.10 contains a denial of service vulnerability in the mashREPL tool that allows attackers to crash the application by pasting malformed input. Attackers can trigger the vulnerability by copying a 300-character buffer of…
- CVE-2021-47824HIGHCVSS 7.5EG 7.52026-01-16
iDailyDiary 4.30 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the preferences tab name field. Attackers can paste a 2,000,000 character buffer into the default diary tab name to t…
- CVE-2021-47821HIGHCVSS 7.5EG 7.52026-01-16
RarmaRadio 2.72.8 contains a denial of service vulnerability that allows attackers to crash the application by overflowing network configuration fields with large character buffers. Attackers can generate a 100,000 character buffer and pas…
- CVE-2021-47818HIGHCVSS 7.5EG 7.52026-01-16
DupTerminator 1.4.5639.37199 contains a denial of service vulnerability that allows attackers to crash the application by inputting a long character string in the Excluded text box. Attackers can generate a payload of 8000 repeated charact…
- CVE-2024-30516HIGHCVSS 7.5EG 7.52026-01-05
Improper Validation of Specified Quantity in Input vulnerability in SaasProject Booking Package allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Booking Package: from n/a through 1.6.27.
- CVE-2025-33211HIGHCVSS 7.5EG 7.52025-12-03
NVIDIA Triton Server for Linux contains a vulnerability where an attacker may cause an improper validation of specified quantity in input. A successful exploit of this vulnerability may lead to denial of service.
- CVE-2025-61938HIGHCVSS 7.5EG 7.52025-10-15
When a BIG-IP Advanced WAF or ASM security policy is configured with a URL greater than 1024 characters in length for the Data Guard Protection Enforcement setting, either manually or through the automatic Policy Builder, the bd process ca…
- CVE-2025-43793HIGHCVSS 7.5EG 7.52025-09-15
Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions may incorrectly identify the…
- CVE-2025-2256HIGHCVSS 7.5EG 7.52025-09-12
An issue has been discovered in GitLab CE/EE affecting all versions from 7.12 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed unauthorized users to render the GitLab instance unresponsive to legitimate use…
- CVE-2025-32689HIGHCVSS 7.5EG 7.52025-09-09
Improper Validation of Specified Quantity in Input vulnerability in Convers Lab WP SmartPay smartpay.This issue affects WP SmartPay: from n/a through <= 2.8.2.
- CVE-2025-4365HIGHCVSS 7.5EG 7.52025-06-17
Arbitrary file read in NetScaler Console and NetScaler SDX (SVM)
- CVE-2024-9448HIGHCVSS 7.5EG 7.52025-05-08
On affected platforms running Arista EOS with Traffic Policies configured the vulnerability will cause received untagged packets not to hit Traffic Policy rules that they are expected to hit. If the rule was to drop the packet, the packet …
- CVE-2025-3511HIGHCVSS 7.5EG 7.52025-04-25
Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric Corporation CC-Link IE TSN Remote I/O module, CC-Link IE TSN Analog-Digital Converter module, CC-Link IE TSN Digital-Analog Converter module, CC-Link I…
- CVE-2025-29784HIGHCVSS 7.5EG 7.52025-04-18
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, the s parameter in GET requests for forum search functionality lacks length validation, allowing attackers to submit excessive…
- CVE-2024-20149HIGHCVSS 7.5EG 7.52025-01-06
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY0123134…
- CVE-2024-47257HIGHCVSS 7.5EG 7.52024-11-26
Florent Thiéry has found that selected Axis devices were vulnerable to handling certain ethernet frames which could lead to the Axis device becoming unavailable in the network. Axis has released patched AXIS OS versions for the highlight…
- CVE-2024-41991HIGHCVSS 7.5EG 7.52024-08-07
An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize and urlizetrunc template filters, and the AdminURLFieldWidget widget, are subject to a potential denial-of-service attack via certain inputs with a very l…
- CVE-2024-30527HIGHCVSS 7.5EG 7.52024-05-17
Improper Validation of Specified Quantity in Input vulnerability in Tips and Tricks HQ WP Express Checkout (Accept PayPal Payments) allows Manipulating Hidden Fields.This issue affects WP Express Checkout (Accept PayPal Payments): from n/a…
- CVE-2023-4518HIGHCVSS 7.5EG 7.52023-12-01
A vulnerability exists in the input validation of the GOOSE messages where out of range values received and processed by the IED caused a reboot of the device. In order for an attacker to exploit the vulnerability, goose receiving block…
- CVE-2023-43665HIGHCVSS 7.5EG 7.52023-11-03
In Django 3.2 before 3.2.22, 4.1 before 4.1.12, and 4.2 before 4.2.6, the django.utils.text.Truncator chars() and words() methods (when used with html=True) are subject to a potential DoS (denial of service) attack via certain inputs with …
- CVE-2023-41164HIGHCVSS 7.5EG 7.52023-11-03
In Django 3.2 before 3.2.21, 4.1 before 4.1.11, and 4.2 before 4.2.5, django.utils.encoding.uri_to_iri() is subject to a potential DoS (denial of service) attack via certain inputs with a very large number of Unicode characters.
- CVE-2023-42447HIGHCVSS 7.5EG 7.52023-09-19
blurhash-rs is a pure Rust implementation of Blurhash, software for encoding images into ASCII strings that can be turned into a gradient of colors representing the original image. In version 0.1.1, the blurhash parsing code may panic due …
- CVE-2023-42444HIGHCVSS 7.5EG 7.52023-09-19
phonenumber is a library for parsing, formatting and validating international phone numbers. Prior to versions `0.3.3+8.13.9` and `0.2.5+8.11.3`, the phonenumber parsing code may panic due to a panic-guarded out-of-bounds access on the pho…
- CVE-2023-38744HIGHCVSS 7.5EG 7.52023-08-03
Denial-of-service (DoS) vulnerability due to improper validation of specified type of input issue exists in the built-in EtherNet/IP port of the CJ Series CJ2 CPU unit and the communication function of the CS/CJ Series EtherNet/IP unit. If…
- CVE-2021-46893HIGHCVSS 7.5EG 7.52023-07-05
Vulnerability of unstrict data verification and parameter check. Successful exploitation of this vulnerability may affect integrity.
- CVE-2023-34188HIGHCVSS 7.5EG 7.52023-06-23
The HTTP server in Mongoose before 7.10 accepts requests containing negative Content-Length headers. By sending a single attack payload over TCP, an attacker can cause an infinite loop in which the server continuously reparses that payload…
- CVE-2023-30082HIGHCVSS 7.5EG 7.52023-06-14
A denial of service attack might be launched against the server if an unusually lengthy password (more than 10000000 characters) is supplied using the osTicket application. This can cause the website to go down or stop responding. When a l…
- CVE-2022-48298HIGHCVSS 7.5EG 7.52023-02-09
The geofencing kernel code does not verify the length of the input data. Successful exploitation of this vulnerability may cause out-of-bounds memory access.
- CVE-2022-48297HIGHCVSS 7.5EG 7.52023-02-09
The geofencing kernel code has a vulnerability of not verifying the length of the input data. Successful exploitation of this vulnerability may cause out-of-bounds memory access.
- CVE-2022-20445HIGHCVSS 7.5EG 7.52022-11-08
In process_service_search_rsp of sdp_discovery.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction i…
- CVE-2022-39294HIGHCVSS 7.5EG 7.52022-10-31
conduit-hyper integrates a conduit application with the hyper server. Prior to version 0.4.2, `conduit-hyper` did not check any limit on a request's length before calling [`hyper::body::to_bytes`](https://docs.rs/hyper/latest/hyper/body/fn…
- CVE-2022-39313HIGHCVSS 7.5EG 7.52022-10-24
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Versions prior to 4.10.17, and prior to 5.2.8 on the 5.x branch, crash when a file download request is received with an invalid byte ra…
- CVE-2022-40761HIGHCVSS 7.5EG 7.52022-09-16
The function tee_obj_free in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking the function TEE_AllocateOperation with a disturbed heap layout, related to utee_cryp_obj_alloc.
- CVE-2022-2277HIGHCVSS 7.5EG 7.52022-09-14
Improper Input Validation vulnerability exists in the Hitachi Energy MicroSCADA X SYS600's ICCP stack during the ICCP communication establishment causes a denial-of-service when ICCP of SYS600 is request to forward any data item updates wi…
- CVE-2022-36620HIGHCVSS 7.5EG 7.52022-08-31
D-link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img is vulnerable to Buffer Overflow via /goform/addRouting.
- CVE-2022-21208HIGHCVSS 7.5EG 7.52022-08-23
The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single session or in total for all concurrent sessions. An attacker can exploit this vulnerab…
- CVE-2021-45918HIGHCVSS 7.5EG 7.52022-06-20
NHI’s health insurance web service component has insufficient validation for input string length, which can result in heap-based buffer overflow attack. A remote attacker can exploit this vulnerability to flood the memory space reserved …
Map vulnerabilities like CWE-1284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →