Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-1284'

View all threats tagged with 'cwe-1284'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-1284

Threats Tagged 'cwe-1284'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-57053: CWE-1284 Improper Validation of Specified Quantity in Input in GNU libidnCVE-2026-57053
0

GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The affected code is not present in libidn2.

Join the discussion
CVE-2026-53540: CWE-1284: Improper Validation of Specified Quantity in Input in Kludex python-multipartCVE-2026-53540
0

Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.31, parse_form() did not validate the Content-Length header before using it to bound its chunked read of the request body. A negative Content-Length turned the bounded read into a read-until-EOF, so the entire body was loaded into memory in a single read instead of in fixed-size chunks. This vulnerability is fixed in 0.0.31.

Join the discussion
CVE-2026-49110: CWE-1284 Improper Validation of Specified Quantity in Input in WP Swings Upsell Order Bump Offer for WooCommerceCVE-2026-49110
0

CVE-2026-49110 is a high severity vulnerability in WP Swings Upsell Order Bump Offer for WooCommerce versions up to and including 3.1.4. It involves improper validation of specified quantity in input, leading to unauthenticated broken authentication. This flaw allows an attacker to impact the integrity of the system without requiring user interaction or privileges.

Join the discussion
CVE-2026-45441: CWE-1284 Improper Validation of Specified Quantity in Input in Magepeople inc. WpEventlyCVE-2026-45441
0

CVE-2026-45441 is a high-severity vulnerability in Magepeople inc.'s WpEvently plugin affecting versions up to and including 5.3.3. It involves improper validation of specified quantity in input, classified under CWE-1284. The vulnerability can be exploited without authentication and does not impact confidentiality or availability but can cause a high integrity impact. No official patch or remediation guidance is currently available from the vendor.

Join the discussion
CVE-2026-42657: CWE-1284 Improper Validation of Specified Quantity in Input in Wasiliy Strecker Contest GalleryCVE-2026-42657
0

Unauthenticated Other Vulnerability Type in Contest Gallery <= 28.1.7 versions.

Join the discussion
CVE-2026-12059: CWE-1284 Improper validation of specified quantity in input in Cellopoint CelloOSCVE-2026-12059
0

The SSH service of CelloOS developed by Cellopoint has an Improper Access Control vulnerability, allowing authenticated remote attackers to bypass the enforced command restrictions and execute operating system commands outside the originally authorized scope.

Join the discussion
CVE-2026-11596: CWE-1284 Improper validation of specified quantity in input in ConnectWise ScreenConnectCVE-2026-11596
0

In ScreenConnect™ versions prior to 26.2, input validation within the Host Pass creation functionality could allow an authenticated user with Host Pass creation privileges the ability to specify a token expiration duration beyond the intended maximum when generating delegated access tokens.

Join the discussion
CVE-2026-53689: CWE-1284 Improper Validation of Specified Quantity in Input in sahlberg libnfsCVE-2026-53689
0

A vulnerability in libnfs versions up to and including 6.0.2 allows improper validation of string size, causing an integer overflow during connection to a crafted NFS server. This occurs in the libnfs_zdr_string function. The issue can lead to high impact on confidentiality and integrity, with low impact on availability.

Join the discussion
CVE-2026-49777: CWE-1284 Improper Validation of Specified Quantity in Input in ShapedPlugin, LLC Product Slider Pro for WooCommerceCVE-2026-49777
0

Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce allows Malicious Software Implanted. This issue affects Product Slider Pro for WooCommerce: from n/a before 3.5.4.

Join the discussion
CVE-2026-47329: CWE-1284 Improper validation of specified quantity in input in Canonical Ubuntu LinuxCVE-2026-47329
0

Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor notification responses. The bug can be triggered by an unprivileged local user and could result in handling of crafted responses.

Join the discussion

Showing 1 to 10 of 14 results

Filters:Tag: cwe-1284
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses