Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-1286'

View all threats tagged with 'cwe-1286'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-1286

Threats Tagged 'cwe-1286'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2025-8873: CWE-1286: Improper Validation of Syntactic Correctness of Input in Arista Networks EOSCVE-2025-8873
0

On affected platforms running Arista EOS with IPsec configured, a specially crafted packet can cause the dataplane to stop processing all IPsec traffic. The control plane may detect this condition, and attempt to reset the IPsec processing pipeline. After reset traffic may not resume being processed. There is no impact to non-IPsec traffic or to IPsec traffic not originating or terminating on the system. This issue was reported by an Arista customer.

Join the discussion
CVE-2026-24092: CWE-1286: Improper Validation of Syntactic Correctness of Input in Qualcomm, Inc. SnapdragonCVE-2026-24092
0

CVE-2026-24092 is a high-severity vulnerability in Qualcomm Snapdragon devices involving memory corruption triggered by processing fastboot commands to set display mode. The flaw is due to improper validation of the syntactic correctness of input. This vulnerability can lead to complete confidentiality, integrity, and availability compromise. No patch or official remediation has been confirmed yet. The affected versions are not explicitly stated.

Join the discussion
CVE-2026-24091: CWE-1286: Improper Validation of Syntactic Correctness of Input in Qualcomm, Inc. SnapdragonCVE-2026-24091
0

CVE-2026-24091 is a high severity vulnerability in Qualcomm Snapdragon devices involving memory corruption triggered by improperly formatted fastboot commands. The flaw stems from improper validation of the syntactic correctness of input, classified under CWE-1286. This vulnerability can lead to complete compromise of confidentiality, integrity, and availability. No patch or official remediation guidance has been provided yet, and no known exploits are reported in the wild. The affected versions are not explicitly stated.

Join the discussion
CVE-2026-24089: CWE-1286: Improper Validation of Syntactic Correctness of Input in Qualcomm, Inc. SnapdragonCVE-2026-24089
0

CVE-2026-24089 is a high-severity vulnerability in Qualcomm Snapdragon devices involving memory corruption triggered by processing fastboot commands with invalid input. The flaw relates to improper validation of the syntactic correctness of input data, classified under CWE-1286. This vulnerability can lead to significant confidentiality, integrity, and availability impacts. No official patch or remediation guidance has been provided yet.

Join the discussion
CVE-2026-24087: CWE-1286: Improper Validation of Syntactic Correctness of Input in Qualcomm, Inc. SnapdragonCVE-2026-24087
0

CVE-2026-24087 is a high-severity vulnerability in Qualcomm Snapdragon devices involving memory corruption triggered by processing fastboot OEM commands. The flaw relates to improper validation of the syntactic correctness of input, classified under CWE-1286. This vulnerability can lead to complete confidentiality, integrity, and availability compromise. No patch or official remediation guidance is currently available, and no known exploits are reported in the wild.

Join the discussion
CVE-2026-0983: CWE-1286 Improper validation of syntactic correctness of input in M-Files Corporation M-Files ServerCVE-2026-0983
0

Denial-of-service condition in M-Files Server versions before 26.5.16015.0, before 26.2 LTS, and before 25.8 LTS SR3 allows an authenticated user to cause the MFserver process to crash

Join the discussion
CVE-2026-40198: CWE-1286 Improper Validation of Syntactic Correctness of Input in STIGTSP Net::CIDR::LiteCVE-2026-40198
0

Net::CIDR::Lite versions before 0.23 for Perl does not validate IPv6 group count, which may allow IP ACL bypass. _pack_ipv6() does not check that uncompressed IPv6 addresses (without ::) have exactly 8 hex groups. Inputs like "abcd", "1:2:3", or "1:2:3:4:5:6:7" are accepted and produce packed values of wrong length (3, 7, or 15 bytes instead of 17). The packed values are used internally for mask and comparison operations. find() and bin_find() use Perl string comparison (lt/gt) on these values, and comparing strings of different lengths gives wrong results. This can cause find() to incorrectly report an address as inside or outside a range. Example: my $cidr = Net::CIDR::Lite->new("::/8"); $cidr->find("1:2:3"); # invalid input, incorrectly returns true This is the same class of input validation issue as CVE-2021-47154 (IPv4 leading zeros) previously fixed in this module. See also CVE-2026-40199, a related issue in the same function affecting IPv4 mapped IPv6 addresses.

Join the discussion
CVE-2026-33778: CWE-1286 Improper Validation of Syntactic Correctness of Input in Juniper Networks Junos OSCVE-2026-33778
0

An Improper Validation of Syntactic Correctness of Input vulnerability in the IPsec library used by kmd and iked of Juniper Networks Junos OS on SRX Series and MX Series allows an unauthenticated, network-based attacker to cause a complete Denial-of-Service (DoS). If an affected device receives a specifically malformed first ISAKMP packet from the initiator, the kmd/iked process will crash and restart, which momentarily prevents new security associations (SAs) for from being established. Repeated exploitation of this vulnerability causes a complete inability to establish new VPN connections. This issue affects Junos OS on SRX Series and MX Series: * all versions before 22.4R3-S9, * 23.2 version before 23.2R2-S6, * 23.4 version before 23.4R2-S7, * 24.2 versions before 24.2R2-S4, * 24.4 versions before 24.4R2-S3, * 25.2 versions before 25.2R1-S2, 25.2R2.

Join the discussion
CVE-2024-51983: CWE-1286 Improper Validation of Syntactic Correctness of Input in Brother Industries, Ltd HL-L8260CDNCVE-2024-51983
0

An unauthenticated attacker who can connect to the Web Services feature (HTTP TCP port 80) can issue a WS-Scan SOAP request containing an unexpected JobToken value which will crash the target device. The device will reboot, after which the attacker can reissue the command to repeatedly crash the device.

Join the discussion
CVE-2024-51982: CWE-1286 Improper Validation of Syntactic Correctness of Input in Brother Industries, Ltd HL-L8260CDNCVE-2024-51982
0

CVE-2024-51982 is a high-severity vulnerability affecting the Brother HL-L8260CDN printer. An unauthenticated attacker able to connect to TCP port 9100 can send a malformed Printer Job Language (PJL) command with a non-numeric FORMLINES variable, causing the device to crash and reboot. This can be repeatedly exploited to cause denial of service. There is no information about an available patch or official remediation at this time.

Join the discussion

Showing 1 to 10 of 26 results

Filters:Tag: cwe-1286
Page 1 of 3
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses