Skip to content
Noroxi

CWE-130 · 102 records

Improper Handling of Length Parameter Inconsistency

CVEs in this class

102 records

  • Zlib compressed protocol header length confusion may allow memory read

    HighCVSS 8.7KEVWeaponizedEPSS 83%

    mongodb · mongodbDec 19, 2025

  • Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configu

    CriticalCVSS 9.8No exploitEPSS 7%

    mitsubishielectric · c controller module setting and monitoring toolFeb 19, 2021

  • OCI OpenDDS Secure Improper Handling of Length Parameter Inconsistency

    CriticalCVSS 9.8No exploitEPSS 3%

    objectcomputing · openddsMay 5, 2022

  • An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14.

    HighCVSS 7.5Proof of conceptEPSS 29%

    djangoproject · djangoJul 10, 2024

  • CVE-2022-2714
    39Monitor

    Improper Handling of Length Parameter Inconsistency in francoisjacquet/rosariosis

    CriticalCVSS 9.8No exploitEPSS 1%

    rosariosis · rosariosisSep 6, 2022

  • CVE-2019-3862
    38Monitor

    An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message and

    CriticalCVSS 9.1No exploitEPSS 8%

    libssh2 · libssh2Mar 21, 2019

  • FreeRDP before 3.29.0 WebSocket Ping Buffer Over-disclosure

    CriticalCVSS 9.3No exploitEPSS 0%

    freerdp · freerdpAug 1, 2026

  • CVE-2026-9054
    36Monitor

    Invalid IP packets cause a kernel panic

    CriticalCVSS 9.2No exploitEPSS 1%

    9front · 9frontMay 22, 2026

  • websocket-driver: Message corruption via abuse of protocol length headers

    CriticalCVSS 9.2No exploitEPSS 0%

    faye · websocket-driverJul 17, 2026

  • CVE-2023-5778
    36Monitor

    Missing Length Check

    CriticalCVSS 9.2No exploitEPSS 0%

    abb · freelance controller dcpSep 18, 2026

  • CVE-2022-1543
    35Monitor

    Improper handling of Length parameter in erudika/scoold

    HighCVSS 8.8No exploitEPSS 1%

    erudika · scooldApr 29, 2022

  • Multiple vulnerabilities in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow

    HighCVSS 8.8No exploitEPSS 1%

    cisco · ata 190 firmwareDec 12, 2022

  • Multiple vulnerabilities in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow

    HighCVSS 8.8No exploitEPSS 1%

    cisco · ata 190 firmwareDec 12, 2022

  • ppp(8): missing length validation in LcpDecodeConfig()

    HighCVSS 8.8No exploitEPSS 1%

    freebsd · freebsdAug 26, 2026

  • Security Advisory 0173

    HighCVSS 8.9No exploitEPSS 0%

    arista networks · eosSep 16, 2026

  • Missing Size Checks in Bluetooth HCI over SPI

    HighCVSS 8.8No exploitEPSS 0%

    zephyrproject · zephyrMay 25, 2021

  • CVE-2026-5706
    35Monitor

    Buffer overflow in Bluetooth Mesh SDK when handling extended advertisements

    HighCVSS 8.9No exploitEPSS 0%

    silicon labs · bt mesh sdkAug 27, 2026

  • Apache Commons Compress 1.0 to 1.20 denial of service vulnerability

    HighCVSS 7.5No exploitEPSS 13%

    apache · commons compressJul 13, 2021

  • Apache Commons Compress 1.6 to 1.20 denial of service vulnerability

    HighCVSS 7.5No exploitEPSS 12%

    apache · commons compressJul 13, 2021

  • Cisco IOS XE Software for Catalyst Switches MPLS Denial of Service Vulnerability

    HighCVSS 8.6No exploitEPSS 1%

    cisco · ios xeOct 10, 2022

  • CVE-2026-5367
    34Monitor

    Ovn: ovn: information disclosure via crafted dhcpv6 packets

    HighCVSS 8.6No exploitEPSS 1%

    red hat · fast datapath for red hat enterprise linux 10Apr 24, 2026

  • CVE-2026-3868
    34Monitor

    An improper handling of the length parameter inconsistency vulnerability has been identified in Moxa’s Secure Router.

    HighCVSS 8.7No exploitEPSS 1%

    moxa · edr-8010 seriesApr 27, 2026

  • Vector: Unauthenticated denial of service in the `logstash` source via unbounded memory allocation.

    HighCVSS 8.7No exploitEPSS 1%

    vectordotdev · vectorSep 22, 2026

  • Junos OS: SRX Series: A device configured for vector routing crashes when receiving malformed traffic

    HighCVSS 8.7No exploitEPSS 0%

    juniper · junosApr 9, 2025

  • Apache Commons Compress 1.1 to 1.20 denial of service vulnerability

    HighCVSS 7.5No exploitEPSS 11%

    apache · commons compressJul 13, 2021

All vulnerability classes