Vulnerabilities > Improper Validation of Specified Quantity in Input

DATE CVE VULNERABILITY TITLE RISK
2023-04-01 CVE-2023-0195 Improper Validation of Specified Quantity in Input vulnerability in Nvidia Virtual GPU
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer driver nvlddmkm.sys, where an can cause CWE-1284, which may lead to hypothetical Information leak of unimportant data such as local variable data of the driver
low complexity
nvidia CWE-1284
2.4
2023-03-06 CVE-2022-4904 Improper Validation of Specified Quantity in Input vulnerability in multiple products
A flaw was found in the c-ares package.
network
low complexity
c-ares-project redhat fedoraproject CWE-1284
8.6
2023-02-13 CVE-2022-3411 Improper Validation of Specified Quantity in Input vulnerability in Gitlab
A lack of length validation in GitLab CE/EE affecting all versions from 12.4 before 15.6.7, 15.7 before 15.7.6, and 15.8 before 15.8.1 allows an authenticated attacker to create a large Issue description via GraphQL which, when repeatedly requested, saturates CPU usage.
network
low complexity
gitlab CWE-1284
6.5
2023-02-09 CVE-2023-23626 Improper Validation of Specified Quantity in Input vulnerability in Protocol Go-Bitfield 1.0.0
go-bitfield is a simple bitfield package for the go language aiming to be more performant that the standard library.
network
low complexity
protocol CWE-1284
7.5
2023-02-09 CVE-2022-48297 Improper Validation of Specified Quantity in Input vulnerability in Huawei Emui and Harmonyos
The geofencing kernel code has a vulnerability of not verifying the length of the input data.
network
low complexity
huawei CWE-1284
7.5
2023-02-09 CVE-2022-48298 Improper Validation of Specified Quantity in Input vulnerability in Huawei Emui and Harmonyos
The geofencing kernel code does not verify the length of the input data.
network
low complexity
huawei CWE-1284
7.5
2023-01-26 CVE-2021-28510 Improper Validation of Specified Quantity in Input vulnerability in Arista EOS
For certain systems running EOS, a Precision Time Protocol (PTP) packet of a management/signaling message with an invalid Type-Length-Value (TLV) causes the PTP agent to restart.
network
low complexity
arista CWE-1284
7.5
2023-01-26 CVE-2022-20493 Improper Validation of Specified Quantity in Input vulnerability in Google Android
In Condition of Condition.java, there is a possible way to grant notification access due to improper input validation.
local
low complexity
google CWE-1284
7.8
2023-01-13 CVE-2023-22409 Improper Validation of Specified Quantity in Input vulnerability in Juniper Junos
An Unchecked Input for Loop Condition vulnerability in a NAT library of Juniper Networks Junos OS allows a local authenticated attacker with low privileges to cause a Denial of Service (DoS).
local
low complexity
juniper CWE-1284
5.5
2022-12-26 CVE-2022-37311 Improper Validation of Specified Quantity in Input vulnerability in Open-Xchange Appsuite
OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large location request parameter to the redirect servlet.
network
low complexity
open-xchange CWE-1284
5.3