Vulnerabilities > Improper Validation of Specified Quantity in Input

DATE CVE VULNERABILITY TITLE RISK
2023-11-03 CVE-2023-41164 Improper Validation of Specified Quantity in Input vulnerability in multiple products
In Django 3.2 before 3.2.21, 4.1 before 4.1.11, and 4.2 before 4.2.5, django.utils.encoding.uri_to_iri() is subject to a potential DoS (denial of service) attack via certain inputs with a very large number of Unicode characters.
network
low complexity
djangoproject fedoraproject CWE-1284
7.5
2023-11-03 CVE-2023-43665 Improper Validation of Specified Quantity in Input vulnerability in multiple products
In Django 3.2 before 3.2.22, 4.1 before 4.1.12, and 4.2 before 4.2.6, the django.utils.text.Truncator chars() and words() methods (when used with html=True) are subject to a potential DoS (denial of service) attack via certain inputs with very long, potentially malformed HTML text.
network
low complexity
djangoproject fedoraproject CWE-1284
7.5
2023-10-12 CVE-2023-36839 Improper Validation of Specified Quantity in Input vulnerability in Juniper Junos
An Improper Validation of Specified Quantity in Input vulnerability in the Layer-2 control protocols daemon (l2cpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker who sends specific LLDP packets to cause a Denial of Service(DoS). This issue occurs when specific LLDP packets are received and telemetry polling is being done on the device.
low complexity
juniper CWE-1284
6.5
2023-10-04 CVE-2023-42448 Improper Validation of Specified Quantity in Input vulnerability in Iohk Hydra
Hydra is the layer-two scalability solution for Cardano.
network
low complexity
iohk CWE-1284
8.1
2023-09-19 CVE-2023-42444 Improper Validation of Specified Quantity in Input vulnerability in Whisperfish Phonenumber
phonenumber is a library for parsing, formatting and validating international phone numbers.
network
low complexity
whisperfish CWE-1284
7.5
2023-09-19 CVE-2023-42447 Improper Validation of Specified Quantity in Input vulnerability in Whisperfish Blurhash-Rs 0.1.1
blurhash-rs is a pure Rust implementation of Blurhash, software for encoding images into ASCII strings that can be turned into a gradient of colors representing the original image.
network
low complexity
whisperfish CWE-1284
7.5
2023-06-23 CVE-2023-35932 Improper Validation of Specified Quantity in Input vulnerability in Jcvi Project Jcvi
jcvi is a Python library to facilitate genome assembly, annotation, and comparative genomics.
network
low complexity
jcvi-project CWE-1284
8.8
2023-06-14 CVE-2023-30082 Improper Validation of Specified Quantity in Input vulnerability in Enhancesoft Osticket 1.17.2
A denial of service attack might be launched against the server if an unusually lengthy password (more than 10000000 characters) is supplied using the osTicket application.
network
low complexity
enhancesoft CWE-1284
7.5
2023-04-01 CVE-2023-0195 Improper Validation of Specified Quantity in Input vulnerability in Nvidia Virtual GPU
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer driver nvlddmkm.sys, where an can cause CWE-1284, which may lead to hypothetical Information leak of unimportant data such as local variable data of the driver
low complexity
nvidia CWE-1284
2.4
2023-03-06 CVE-2022-4904 Improper Validation of Specified Quantity in Input vulnerability in multiple products
A flaw was found in the c-ares package.
network
low complexity
c-ares-project redhat fedoraproject CWE-1284
8.6