CWE-1284 · 307 записей
Improper Validation of Specified Quantity in Input
CVE этого класса
307 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
66На этой неделе | CVE-2010-3904Готовый эксплойт | The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before linux · linux kernel · CWE-1284 | Высокая7,8 | KEV | 15,7 % | 6 дек. 2010 г. |
56В плане | CVE-2021-43267Proof of concept | An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16.linux · linux kernel · CWE-1284 | Критическая9,8 | — | 57,9 % | 2 нояб. 2021 г. |
46В плане | CVE-2022-37134Эксплойта нет | D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Buffer Overflow via /goform/form2Wan.cgi.dlink · dir-816 firmware · CWE-1284 | Критическая9,8 | — | 21,7 % | 22 авг. 2022 г. |
41В плане | CVE-2026-49777Proof of concept | WordPress Product Slider Pro for WooCommerce plugin < 3.5.4 - Backdoor vulnerabilityshapedplugin, llc · product slider pro for woocommerce · CWE-1284 | Критическая10,0 | — | 2,0 % | 5 июн. 2026 г. |
40В плане | CVE-2008-2374Эксплойта нет | src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.34 and bluez-utils before 3.34 versions, does not validate string lengtbluez · bluez-libs · CWE-1284 | Критическая9,8 | — | 4,3 % | 7 июл. 2008 г. |
40В плане | CVE-2026-81779Эксплойта нет | WordPress Newspapers X theme 1.0.46-1.0.48 - Backdoor vulnerabilitysilk themes · newspapers x · CWE-1284 | Критическая10,0 | — | 0,5 % | 31 авг. 2026 г. |
39Наблюдать | CVE-2021-31556Эксплойта нет | An issue was discovered in the Oauth extension for MediaWiki through 1.35.2.mediawiki · mediawiki · CWE-1284 | Критическая9,8 | — | 1,6 % | 12 авг. 2021 г. |
39Наблюдать | CVE-2026-3381Эксплойта нет | Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlibpmqs · compress\ · CWE-1284 | Критическая9,8 | — | 0,8 % | 4 мар. 2026 г. |
39Наблюдать | CVE-2026-25345Эксплойта нет | WordPress SimpLy Gallery plugin <= 3.3.2 - Arbitrary Code Execution vulnerabilitygallerycreator · simply gallery · CWE-1284 | Критическая9,9 | — | 0,4 % | 25 мар. 2026 г. |
39Наблюдать | CVE-2022-25727Эксплойта нет | Memory Corruption in modem due to improper length check while copying into memory in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snaqualcomm · ar8031 firmware · CWE-1284 | Критическая9,8 | — | 0,4 % | 15 нояб. 2022 г. |
39Наблюдать | CVE-2022-20385Эксплойта нет | a function called 'nla_parse', do not check the len of para, it will check nla_type (which can be controlled by userspace) with 'maxtype' (igoogle · android · CWE-1284 | Критическая9,8 | — | 0,4 % | 13 сент. 2022 г. |
39Наблюдать | CVE-2025-43964Эксплойта нет | In LibRaw before 0.21.4, tag 0x412 processing in phase_one_correct in decoders/load_mfbacks.cpp does not enforce minimum w0 and w1 values.libraw · libraw · CWE-1284 | Критическая9,8 | — | 0,4 % | 20 апр. 2025 г. |
39Наблюдать | CVE-2025-55398Эксплойта нет | An issue was discovered in mouse07410 asn1c thru 0.9.29 (2025-03-20) - a fork of vlm asn1c.CWE-1284 | Критическая9,8 | — | 0,4 % | 22 авг. 2025 г. |
38Наблюдать | CVE-2025-9316Готовый эксплойт | N-central unauthenticated sessionID generationn-able · n-central · CWE-1284 | Средняя6,9 | — | 36,3 % | 12 нояб. 2025 г. |
38Наблюдать | CVE-2024-9369Эксплойта нет | Insufficient data validation in Mojo in Google Chrome prior to 129.0.6668.89 allowed a remote attacker who had compromised the renderer procgoogle · chrome · CWE-1284 | Критическая9,6 | — | 0,7 % | 27 нояб. 2024 г. |
38Наблюдать | CVE-2026-87470Эксплойта нет | Improper quantity validation in Tint in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbigoogle · chrome · CWE-1284 | Критическая9,6 | — | 0,5 % | 8 сент. 2026 г. |
37Наблюдать | CVE-2022-36620Эксплойта нет | D-link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img is vulnerable to Buffer Overflow via /goform/addRouting.dlink · dir-816 firmware · CWE-1284 | Высокая7,5 | — | 23,7 % | 31 авг. 2022 г. |
37Наблюдать | CVE-2021-31346Эксплойта нет | A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions siemens · capital vstar · CWE-1284 | Критическая9,1 | — | 2,0 % | 9 нояб. 2021 г. |
36Наблюдать | CVE-2025-5349Proof of concept | NetScaler ADC and NetScaler Gateway - Improper access control on the NetScaler Management Interfacecitrix · netscaler application delivery controller · CWE-1284 | Высокая8,7 | — | 6,2 % | 17 июн. 2025 г. |
36Наблюдать | CVE-2021-31345Эксплойта нет | A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions siemens · capital vstar · CWE-1284 | Критическая9,1 | — | 1,6 % | 9 нояб. 2021 г. |
36Наблюдать | CVE-2026-57623Эксплойта нет | WordPress W3 Total Cache plugin <= 2.9.4 - Arbitrary Code Execution vulnerabilityboldgrid · w3 total cache · CWE-1284 | Критическая9,0 | — | 0,5 % | 2 июл. 2026 г. |
36Наблюдать | CVE-2022-25769Эксплойта нет | Improper regex in htaccess fileacquia · mautic · CWE-1284 | Критическая9,1 | — | 0,5 % | 18 сент. 2024 г. |
36Наблюдать | CVE-2026-27384Proof of concept | WordPress W3 Total Cache plugin <= 2.9.1 - Arbitrary Code Execution vulnerabilityboldgrid · w3 total cache · CWE-1284 | Критическая9,0 | — | 0,4 % | 5 мар. 2026 г. |
36Наблюдать | CVE-2025-65548Эксплойта нет | NUT-14 allows cashu tokens to be created with a preimage hash.cashu · nutshell · CWE-1284 | Критическая9,1 | — | 0,4 % | 8 дек. 2025 г. |
35Наблюдать | CVE-2008-1440Эксплойта нет | Microsoft Windows XP SP2 and SP3, and Server 2003 SP1 and SP2, does not properly validate the option length field in Pragmatic General Multimicrosoft · windows server 2003 · CWE-1284 | Высокая7,1 | — | 22,6 % | 11 июн. 2008 г. |
- CVE-2010-390466На этой неделе
The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 16 %linux · linux kernel6 дек. 2010 г.
- CVE-2021-4326756В плане
An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16.
КритическаяCVSS 9,8Proof of conceptEPSS 58 %linux · linux kernel2 нояб. 2021 г.
- CVE-2022-3713446В плане
D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Buffer Overflow via /goform/form2Wan.cgi.
КритическаяCVSS 9,8Эксплойта нетEPSS 22 %dlink · dir-816 firmware22 авг. 2022 г.
- CVE-2026-4977741В плане
WordPress Product Slider Pro for WooCommerce plugin < 3.5.4 - Backdoor vulnerability
КритическаяCVSS 10,0Proof of conceptEPSS 2 %shapedplugin, llc · product slider pro for woocommerce5 июн. 2026 г.
- CVE-2008-237440В плане
src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.34 and bluez-utils before 3.34 versions, does not validate string lengt
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %bluez · bluez-libs7 июл. 2008 г.
- CVE-2026-8177940В плане
WordPress Newspapers X theme 1.0.46-1.0.48 - Backdoor vulnerability
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %silk themes · newspapers x31 авг. 2026 г.
- CVE-2021-3155639Наблюдать
An issue was discovered in the Oauth extension for MediaWiki through 1.35.2.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %mediawiki · mediawiki12 авг. 2021 г.
- CVE-2026-338139Наблюдать
Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %pmqs · compress\4 мар. 2026 г.
- CVE-2026-2534539Наблюдать
WordPress SimpLy Gallery plugin <= 3.3.2 - Arbitrary Code Execution vulnerability
КритическаяCVSS 9,9Эксплойта нетEPSS 0 %gallerycreator · simply gallery25 мар. 2026 г.
- CVE-2022-2572739Наблюдать
Memory Corruption in modem due to improper length check while copying into memory in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Sna
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %qualcomm · ar8031 firmware15 нояб. 2022 г.
- CVE-2022-2038539Наблюдать
a function called 'nla_parse', do not check the len of para, it will check nla_type (which can be controlled by userspace) with 'maxtype' (i
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %google · android13 сент. 2022 г.
- CVE-2025-4396439Наблюдать
In LibRaw before 0.21.4, tag 0x412 processing in phase_one_correct in decoders/load_mfbacks.cpp does not enforce minimum w0 and w1 values.
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %libraw · libraw20 апр. 2025 г.
- CVE-2025-5539839Наблюдать
An issue was discovered in mouse07410 asn1c thru 0.9.29 (2025-03-20) - a fork of vlm asn1c.
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %22 авг. 2025 г.
- CVE-2025-931638Наблюдать
N-central unauthenticated sessionID generation
СредняяCVSS 6,9Готовый эксплойтEPSS 36 %n-able · n-central12 нояб. 2025 г.
- CVE-2024-936938Наблюдать
Insufficient data validation in Mojo in Google Chrome prior to 129.0.6668.89 allowed a remote attacker who had compromised the renderer proc
КритическаяCVSS 9,6Эксплойта нетEPSS 1 %google · chrome27 нояб. 2024 г.
- CVE-2026-8747038Наблюдать
Improper quantity validation in Tint in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbi
КритическаяCVSS 9,6Эксплойта нетEPSS 0 %google · chrome8 сент. 2026 г.
- CVE-2022-3662037Наблюдать
D-link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img is vulnerable to Buffer Overflow via /goform/addRouting.
ВысокаяCVSS 7,5Эксплойта нетEPSS 24 %dlink · dir-816 firmware31 авг. 2022 г.
- CVE-2021-3134637Наблюдать
A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %siemens · capital vstar9 нояб. 2021 г.
- CVE-2025-534936Наблюдать
NetScaler ADC and NetScaler Gateway - Improper access control on the NetScaler Management Interface
ВысокаяCVSS 8,7Proof of conceptEPSS 6 %citrix · netscaler application delivery controller17 июн. 2025 г.
- CVE-2021-3134536Наблюдать
A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %siemens · capital vstar9 нояб. 2021 г.
- CVE-2026-5762336Наблюдать
WordPress W3 Total Cache plugin <= 2.9.4 - Arbitrary Code Execution vulnerability
КритическаяCVSS 9,0Эксплойта нетEPSS 1 %boldgrid · w3 total cache2 июл. 2026 г.
- CVE-2022-2576936Наблюдать
Improper regex in htaccess file
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %acquia · mautic18 сент. 2024 г.
- CVE-2026-2738436Наблюдать
WordPress W3 Total Cache plugin <= 2.9.1 - Arbitrary Code Execution vulnerability
КритическаяCVSS 9,0Proof of conceptEPSS 0 %boldgrid · w3 total cache5 мар. 2026 г.
- CVE-2025-6554836Наблюдать
NUT-14 allows cashu tokens to be created with a preimage hash.
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %cashu · nutshell8 дек. 2025 г.
- CVE-2008-144035Наблюдать
Microsoft Windows XP SP2 and SP3, and Server 2003 SP1 and SP2, does not properly validate the option length field in Pragmatic General Multi
ВысокаяCVSS 7,1Эксплойта нетEPSS 23 %microsoft · windows server 200311 июн. 2008 г.