CWE-130 · 102 records
Improper Handling of Length Parameter Inconsistency
CVEs in this class
102 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
89Now | CVE-2025-14847Weaponized | Zlib compressed protocol header length confusion may allow memory readmongodb · mongodb · CWE-130 | High8.7 | KEV | 83.2% | Dec 19, 2025 |
41Plan | CVE-2021-20588No exploit | Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configumitsubishielectric · c controller module setting and monitoring tool · CWE-130 | Critical9.8 | — | 6.9% | Feb 19, 2021 |
40Plan | CVE-2021-38445No exploit | OCI OpenDDS Secure Improper Handling of Length Parameter Inconsistencyobjectcomputing · opendds · CWE-130 | Critical9.8 | — | 2.7% | May 5, 2022 |
39Monitor | CVE-2024-39614Proof of concept | An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14.djangoproject · django · CWE-130 | High7.5 | — | 28.6% | Jul 10, 2024 |
39Monitor | CVE-2022-2714No exploit | Improper Handling of Length Parameter Inconsistency in francoisjacquet/rosariosisrosariosis · rosariosis · CWE-130 | Critical9.8 | — | 0.9% | Sep 6, 2022 |
38Monitor | CVE-2019-3862No exploit | An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message andlibssh2 · libssh2 · CWE-130 | Critical9.1 | — | 7.9% | Mar 21, 2019 |
37Monitor | CVE-2026-67292No exploit | FreeRDP before 3.29.0 WebSocket Ping Buffer Over-disclosurefreerdp · freerdp · CWE-130 | Critical9.3 | — | 0.5% | Aug 1, 2026 |
36Monitor | CVE-2026-9054No exploit | Invalid IP packets cause a kernel panic9front · 9front · CWE-130 | Critical9.2 | — | 0.5% | May 22, 2026 |
36Monitor | CVE-2026-54466No exploit | websocket-driver: Message corruption via abuse of protocol length headersfaye · websocket-driver · CWE-130 | Critical9.2 | — | 0.4% | Jul 17, 2026 |
36Monitor | CVE-2023-5778No exploit | Missing Length Checkabb · freelance controller dcp · CWE-130 | Critical9.2 | — | 0.3% | Sep 18, 2026 |
35Monitor | CVE-2022-1543No exploit | Improper handling of Length parameter in erudika/scoolderudika · scoold · CWE-130 | High8.8 | — | 1.1% | Apr 29, 2022 |
35Monitor | CVE-2022-20690No exploit | Multiple vulnerabilities in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allowcisco · ata 190 firmware · CWE-130 | High8.8 | — | 0.7% | Dec 12, 2022 |
35Monitor | CVE-2022-20689No exploit | Multiple vulnerabilities in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allowcisco · ata 190 firmware · CWE-130 | High8.8 | — | 0.7% | Dec 12, 2022 |
35Monitor | CVE-2026-58096No exploit | ppp(8): missing length validation in LcpDecodeConfig()freebsd · freebsd · CWE-130 | High8.8 | — | 0.6% | Aug 26, 2026 |
35Monitor | CVE-2026-73455No exploit | Security Advisory 0173arista networks · eos · CWE-130 | High8.9 | — | 0.5% | Sep 16, 2026 |
35Monitor | CVE-2020-10065No exploit | Missing Size Checks in Bluetooth HCI over SPIzephyrproject · zephyr · CWE-130 | High8.8 | — | 0.5% | May 25, 2021 |
35Monitor | CVE-2026-5706No exploit | Buffer overflow in Bluetooth Mesh SDK when handling extended advertisementssilicon labs · bt mesh sdk · CWE-130 | High8.9 | — | 0.4% | Aug 27, 2026 |
34Monitor | CVE-2021-36090No exploit | Apache Commons Compress 1.0 to 1.20 denial of service vulnerabilityapache · commons compress · CWE-130 | High7.5 | — | 12.9% | Jul 13, 2021 |
34Monitor | CVE-2021-35516No exploit | Apache Commons Compress 1.6 to 1.20 denial of service vulnerabilityapache · commons compress · CWE-130 | High7.5 | — | 12.4% | Jul 13, 2021 |
34Monitor | CVE-2022-20870No exploit | Cisco IOS XE Software for Catalyst Switches MPLS Denial of Service Vulnerabilitycisco · ios xe · CWE-130 | High8.6 | — | 0.9% | Oct 10, 2022 |
34Monitor | CVE-2026-5367No exploit | Ovn: ovn: information disclosure via crafted dhcpv6 packetsred hat · fast datapath for red hat enterprise linux 10 · CWE-130 | High8.6 | — | 0.9% | Apr 24, 2026 |
34Monitor | CVE-2026-3868No exploit | An improper handling of the length parameter inconsistency vulnerability has been identified in Moxa’s Secure Router.moxa · edr-8010 series · CWE-130 | High8.7 | — | 0.5% | Apr 27, 2026 |
34Monitor | CVE-2026-77619No exploit | Vector: Unauthenticated denial of service in the `logstash` source via unbounded memory allocation.vectordotdev · vector · CWE-130 | High8.7 | — | 0.5% | Sep 22, 2026 |
34Monitor | CVE-2025-30659No exploit | Junos OS: SRX Series: A device configured for vector routing crashes when receiving malformed trafficjuniper · junos · CWE-130 | High8.7 | — | 0.4% | Apr 9, 2025 |
33Monitor | CVE-2021-35517No exploit | Apache Commons Compress 1.1 to 1.20 denial of service vulnerabilityapache · commons compress · CWE-130 | High7.5 | — | 10.6% | Jul 13, 2021 |
- CVE-2025-1484789Now
Zlib compressed protocol header length confusion may allow memory read
HighCVSS 8.7KEVWeaponizedEPSS 83%mongodb · mongodbDec 19, 2025
- CVE-2021-2058841Plan
Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configu
CriticalCVSS 9.8No exploitEPSS 7%mitsubishielectric · c controller module setting and monitoring toolFeb 19, 2021
- CVE-2021-3844540Plan
OCI OpenDDS Secure Improper Handling of Length Parameter Inconsistency
CriticalCVSS 9.8No exploitEPSS 3%objectcomputing · openddsMay 5, 2022
- CVE-2024-3961439Monitor
An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14.
HighCVSS 7.5Proof of conceptEPSS 29%djangoproject · djangoJul 10, 2024
- CVE-2022-271439Monitor
Improper Handling of Length Parameter Inconsistency in francoisjacquet/rosariosis
CriticalCVSS 9.8No exploitEPSS 1%rosariosis · rosariosisSep 6, 2022
- CVE-2019-386238Monitor
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message and
CriticalCVSS 9.1No exploitEPSS 8%libssh2 · libssh2Mar 21, 2019
- CVE-2026-6729237Monitor
FreeRDP before 3.29.0 WebSocket Ping Buffer Over-disclosure
CriticalCVSS 9.3No exploitEPSS 0%freerdp · freerdpAug 1, 2026
- CVE-2026-905436Monitor
Invalid IP packets cause a kernel panic
CriticalCVSS 9.2No exploitEPSS 1%9front · 9frontMay 22, 2026
- CVE-2026-5446636Monitor
websocket-driver: Message corruption via abuse of protocol length headers
CriticalCVSS 9.2No exploitEPSS 0%faye · websocket-driverJul 17, 2026
- CVE-2023-577836Monitor
Missing Length Check
CriticalCVSS 9.2No exploitEPSS 0%abb · freelance controller dcpSep 18, 2026
- CVE-2022-154335Monitor
Improper handling of Length parameter in erudika/scoold
HighCVSS 8.8No exploitEPSS 1%erudika · scooldApr 29, 2022
- CVE-2022-2069035Monitor
Multiple vulnerabilities in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow
HighCVSS 8.8No exploitEPSS 1%cisco · ata 190 firmwareDec 12, 2022
- CVE-2022-2068935Monitor
Multiple vulnerabilities in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow
HighCVSS 8.8No exploitEPSS 1%cisco · ata 190 firmwareDec 12, 2022
- CVE-2026-5809635Monitor
ppp(8): missing length validation in LcpDecodeConfig()
HighCVSS 8.8No exploitEPSS 1%freebsd · freebsdAug 26, 2026
- CVE-2026-7345535Monitor
Security Advisory 0173
HighCVSS 8.9No exploitEPSS 0%arista networks · eosSep 16, 2026
- CVE-2020-1006535Monitor
Missing Size Checks in Bluetooth HCI over SPI
HighCVSS 8.8No exploitEPSS 0%zephyrproject · zephyrMay 25, 2021
- CVE-2026-570635Monitor
Buffer overflow in Bluetooth Mesh SDK when handling extended advertisements
HighCVSS 8.9No exploitEPSS 0%silicon labs · bt mesh sdkAug 27, 2026
- CVE-2021-3609034Monitor
Apache Commons Compress 1.0 to 1.20 denial of service vulnerability
HighCVSS 7.5No exploitEPSS 13%apache · commons compressJul 13, 2021
- CVE-2021-3551634Monitor
Apache Commons Compress 1.6 to 1.20 denial of service vulnerability
HighCVSS 7.5No exploitEPSS 12%apache · commons compressJul 13, 2021
- CVE-2022-2087034Monitor
Cisco IOS XE Software for Catalyst Switches MPLS Denial of Service Vulnerability
HighCVSS 8.6No exploitEPSS 1%cisco · ios xeOct 10, 2022
- CVE-2026-536734Monitor
Ovn: ovn: information disclosure via crafted dhcpv6 packets
HighCVSS 8.6No exploitEPSS 1%red hat · fast datapath for red hat enterprise linux 10Apr 24, 2026
- CVE-2026-386834Monitor
An improper handling of the length parameter inconsistency vulnerability has been identified in Moxa’s Secure Router.
HighCVSS 8.7No exploitEPSS 1%moxa · edr-8010 seriesApr 27, 2026
- CVE-2026-7761934Monitor
Vector: Unauthenticated denial of service in the `logstash` source via unbounded memory allocation.
HighCVSS 8.7No exploitEPSS 1%vectordotdev · vectorSep 22, 2026
- CVE-2025-3065934Monitor
Junos OS: SRX Series: A device configured for vector routing crashes when receiving malformed traffic
HighCVSS 8.7No exploitEPSS 0%juniper · junosApr 9, 2025
- CVE-2021-3551733Monitor
Apache Commons Compress 1.1 to 1.20 denial of service vulnerability
HighCVSS 7.5No exploitEPSS 11%apache · commons compressJul 13, 2021