Vulnerabilities > Improper Validation of Specified Quantity in Input

DATE CVE VULNERABILITY TITLE RISK
2022-09-14 CVE-2022-2277 Improper Validation of Specified Quantity in Input vulnerability in Hitachienergy Microscada X Sys600
Improper Input Validation vulnerability exists in the Hitachi Energy MicroSCADA X SYS600's ICCP stack during the ICCP communication establishment causes a denial-of-service when ICCP of SYS600 is request to forward any data item updates with timestamps too distant in the future to any remote ICCP system.
network
low complexity
hitachienergy CWE-1284
7.5
2022-09-13 CVE-2022-20385 Improper Validation of Specified Quantity in Input vulnerability in Google Android
a function called 'nla_parse', do not check the len of para, it will check nla_type (which can be controlled by userspace) with 'maxtype' (in this case, it is GSCAN_MAX), then it access polciy array 'policy[type]', which OOB access happens.Product: AndroidVersions: Android SoCAndroid ID: A-238379819
network
low complexity
google CWE-1284
critical
9.8
2022-09-07 CVE-2022-36086 Improper Validation of Specified Quantity in Input vulnerability in Rust-Osdev Linked-List-Allocator
linked_list_allocator is an allocator usable for no_std systems.
network
low complexity
rust-osdev CWE-1284
critical
9.8
2022-09-02 CVE-2022-36078 Improper Validation of Specified Quantity in Input vulnerability in Binary Project Binary
Binary provides encoding/decoding in Borsh and other formats.
network
low complexity
binary-project CWE-1284
7.5
2022-09-02 CVE-2021-35132 Improper Validation of Specified Quantity in Input vulnerability in Qualcomm products
Out of bound write in DSP service due to improper bound check for response buffer size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
local
low complexity
qualcomm CWE-1284
7.8
2022-08-31 CVE-2022-36620 Improper Validation of Specified Quantity in Input vulnerability in Dlink Dir-816 Firmware 1.10Cnb04
D-link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img is vulnerable to Buffer Overflow via /goform/addRouting.
network
low complexity
dlink CWE-1284
7.5
2022-08-23 CVE-2022-21208 Improper Validation of Specified Quantity in Input vulnerability in Node-Opcua Project Node-Opcua
The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single session or in total for all concurrent sessions.
network
low complexity
node-opcua-project CWE-1284
7.5
2022-08-22 CVE-2022-37134 Improper Validation of Specified Quantity in Input vulnerability in Dlink Dir-816 Firmware 1.10Cnb04
D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Buffer Overflow via /goform/form2Wan.cgi.
network
low complexity
dlink CWE-1284
critical
9.8
2022-08-17 CVE-2022-2868 Improper Validation of Specified Quantity in Input vulnerability in multiple products
libtiff's tiffcrop utility has a improper input validation flaw that can lead to out of bounds read and ultimately cause a crash if an attacker is able to supply a crafted file to tiffcrop.
local
low complexity
libtiff fedoraproject debian CWE-1284
5.5
2022-08-10 CVE-2022-25793 Improper Validation of Specified Quantity in Input vulnerability in Autodesk 3DS MAX 2021/2021.3.8/2022
A Stack-based Buffer Overflow Vulnerability in Autodesk 3ds Max 2022, 2021, and 2020 may lead to code execution through the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer when parsing ActionScript Byte Code files.
local
low complexity
autodesk CWE-1284
7.8