Vulnerabilities > Improper Validation of Specified Quantity in Input

DATE CVE VULNERABILITY TITLE RISK
2024-12-29 CVE-2024-56716 Improper Validation of Specified Quantity in Input vulnerability in Linux Kernel
In the Linux kernel, the following vulnerability has been resolved: netdevsim: prevent bad user input in nsim_dev_health_break_write() If either a zero count or a large one is provided, kernel can crash.
local
low complexity
linux CWE-1284
5.5
2024-12-12 CVE-2024-52901 Improper Validation of Specified Quantity in Input vulnerability in IBM Infosphere Information Server 11.7
IBM InfoSphere Information Server 11.7 could allow an authenticated user to GUI to not load or stop working due to improper input validation.
network
low complexity
ibm CWE-1284
6.5
2024-11-27 CVE-2024-9369 Improper Validation of Specified Quantity in Input vulnerability in Google Chrome
Insufficient data validation in Mojo in Google Chrome prior to 129.0.6668.89 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page.
network
low complexity
google CWE-1284
critical
9.6
2024-10-03 CVE-2024-8508 Improper Validation of Specified Quantity in Input vulnerability in multiple products
NLnet Labs Unbound up to and including version 1.21.0 contains a vulnerability when handling replies with very large RRsets that it needs to perform name compression for.
network
low complexity
nlnetlabs debian CWE-1284
5.3
2024-09-18 CVE-2024-8887 Improper Validation of Specified Quantity in Input vulnerability in Circutor Q-Smt Firmware 1.0.4
CIRCUTOR Q-SMT in its firmware version 1.0.4, could be affected by a denial of service (DoS) attack if an attacker with access to the web service bypasses the authentication mechanisms on the login page, allowing the attacker to use all the functionalities implemented at web level that allow interacting with the device.
network
low complexity
circutor CWE-1284
8.6
2024-09-13 CVE-2024-31416 Improper Validation of Specified Quantity in Input vulnerability in Eaton Foreseer Electrical Power Monitoring System
The Eaton Foreseer software provides multiple customizable input fields for the users to configure parameters in the tool like alarms, reports, etc.
network
low complexity
eaton CWE-1284
6.5
2024-09-07 CVE-2024-8558 Improper Validation of Specified Quantity in Input vulnerability in Oretnom23 Food Ordering Management System 1.0
A vulnerability classified as problematic was found in SourceCodester Food Ordering Management System 1.0.
network
low complexity
oretnom23 CWE-1284
4.3
2024-09-05 CVE-2024-42416 Improper Validation of Specified Quantity in Input vulnerability in Freebsd
The ctl_report_supported_opcodes function did not sufficiently validate a field provided by userspace, allowing an arbitrary write to a limited amount of kernel help memory. Malicious software running in a guest VM that exposes virtio_scsi can exploit the vulnerabilities to achieve code execution on the host in the bhyve userspace process, which typically runs as root.
local
low complexity
freebsd CWE-1284
8.8
2024-08-31 CVE-2024-0111 Improper Validation of Specified Quantity in Input vulnerability in Nvidia Cuda Toolkit
NVIDIA CUDA Toolkit contains a vulnerability in command 'cuobjdump' where a user may cause a crash or produce incorrect output by passing a malformed ELF file.
local
low complexity
nvidia CWE-1284
4.4
2024-08-07 CVE-2024-41991 Improper Validation of Specified Quantity in Input vulnerability in Djangoproject Django
An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15.
network
low complexity
djangoproject CWE-1284
7.5