CWE-1284 354 件の CVE MITRE の定義 ↗

CWE-1284: Improper Validation of Specified Quantity in Input

概要

CWE-1284(Improper Validation of Specified Quantity in Input)は各種脆弱性データベースや評価で用いられる弱点タイプを説明します。定義・背景・対応する CVE は以下の各セクションを参照してください。

セキュリティへの影響
セキュリティ影響:製品や文脈に依存します。CVE 記録、深刻度、MITRE の説明を参照して優先度を判断してください。

説明

The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

適用プラットフォーム

種別 名称 クラス 普遍性 OS / CPE
language Not Language-Specific Often

このデータベースの関連 CVE

これらの CVE は本データベースでこの弱点に対応付けられており、追跡と検索のために保持されています。

CVE 公開 概要
CVE-2026-59695 2026-07-17 Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet in a single request by naming an arbitrarily high gas price. Wh…
CVE-2026-59694 2026-07-17 Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per payment by a large multiplier, degrading the sponsor's…
CVE-2026-59252 2026-07-17 Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet, resulting in denial of service for legitimate clients. When th…
CVE-2026-57364 2026-07-13 Improper Validation of Specified Quantity in Input vulnerability in WPDeveloper Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More better-payment allows Accessing …
CVE-2026-57023 2026-07-09 An Improper Validation of Specified Quantity in Input vulnerability in the TCP proxy plugin of Juniper Networks Junos OS on MX Series with SPC3, and SRX Series allows an unauthenticated, network-based…
CVE-2026-57019 2026-07-09 An Improper Validation of Specified Quantity in Input vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, adjacent attacker to caus…
CVE-2026-59930 2026-07-08 Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the toc plugin and TableOfContents directive generate heading IDs as predictable toc_N values without slugifying the hea…
CVE-2026-59879 2026-07-08 Immutable.js provides many Persistent Immutable data structures. Prior to 4.3.9 and 5.1.8, List#set, List#setSize, List#setIn, List#updateIn, and the functional set, setIn, and updateIn mishandle an i…
CVE-2026-59997 2026-07-07 internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended securi…
CVE-2026-43928 2026-07-06 FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the PayPalEmail payment adapter accepts PayPal IPN callbacks and credits the IPN-supplied amount (`mc_g…
CVE-2026-54234 2026-07-06 vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, a frontend-legal multi-request speculative decoding workload can cause the rejection sampler to p…
CVE-2022-4990 2026-07-02 ** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to bypass security validation and access restricted memory blocks v…
CVE-2022-4989 2026-07-02 ** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to access unintended memory regions via crafted IOCTL requests, lea…
CVE-2026-55952 2026-07-02 The Erlang/OTP ssl application does not validate that the PSK identity list and binder list carried in a TLS 1.3 ClientHello pre-shared key extension have equal length before passing them to the sessi…
CVE-2026-57623 2026-07-02 Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions.
CVE-2026-11906 2026-06-30 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutra…
CVE-2026-56035 2026-06-26 Unauthenticated Multiple Vulnerabilities in BitFire Security <= 5.0.3 versions.
CVE-2026-54092 2026-06-25 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, unchecked passwords maximums allow for an arbi…
CVE-2026-12755 2026-06-25 Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows an authenticated user with the UserGroupsView permission to coerce server-side …
CVE-2026-57062 2026-06-23 CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is r…

コンテンツ投稿

名称
CWE Content Team
組織
MITRE
日付
2020-06-24
バージョン
4.1

コンテンツの変更履歴

日付 名称 バージョン 重要度 コメント
2022-10-13 CWE Content Team 4.9 updated Observed_Examples, Relationships
2023-04-27 CWE Content Team 4.11 updated Relationships
2023-06-29 CWE Content Team 4.12 updated Mapping_Notes, Relationships
2025-09-09 CWE Content Team 4.18 updated Observed_Examples
2025-12-11 CWE Content Team 4.19 updated Common_Consequences, Demonstrative_Examples, Description, Detection_Factors, Modes_of_Introduction, Observed_Examples, Weakness_Ordinalities
2026-04-30 CWE Content Team 4.20 updated Demonstrative_Examples, Observed_Examples

貢献

タイプ 名称 日付 コメント
Content Affan Ahmed 2025-02-28 Provided a demonstrative example in PHP
cvelogic Threat Intelligence