Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce
Improper Validation of Specified Quantity in Input vulnerability in GalleryCreator SimpLy Gallery simply-gallery-block a
Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib. Compress::Raw::Zlib incl
nimiq-block contains block primitives to be used in Nimiq's Rust implementation. `SkipBlockProof::verify` computes its q
Sysax Multi Server 6.95 contains a denial of service vulnerability in the administrative password field that allows atta
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.0 to before 0.10.78, the *_from_pem_
Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings. Thi
DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the
Improper Validation of Specified Quantity in Input vulnerability in BoldGrid W3 Total Cache w3-total-cache allows Access
Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions.
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below
GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote
The SSH service of CelloOS developed by Cellopoint has an Improper Access Control vulnerability, allowing authenticated
Unauthenticated Multiple Vulnerabilities in BitFire Security <= 5.0.3 versions.
HTSlib is a library for reading and writing bioinformatics file formats. GZI files are used to index block-compressed GZ
HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA se
nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In 1.3.0 and earlier, block timestam
Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) rece
Software installed and run as a non-privileged user may conduct improper GPU system calls to pass invalid log2 page size
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering t
Improper Validation of Specified Quantity in Input vulnerability in SaasProject Booking Package allows Accessing Functio
DupTerminator 1.4.5639.37199 contains a denial of service vulnerability that allows attackers to crash the application b
RarmaRadio 2.72.8 contains a denial of service vulnerability that allows attackers to crash the application by overflowi
iDailyDiary 4.30 contains a denial of service vulnerability that allows attackers to crash the application by overflowin
WebSSH for iOS 14.16.10 contains a denial of service vulnerability in the mashREPL tool that allows attackers to crash t
Sandboxie 5.49.7 contains a denial of service vulnerability that allows attackers to crash the application by overflowin
Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-ser
Crypt::URandom versions from 0.41 before 0.55 for Perl is vulnerable to a heap buffer overflow in the XS function crypt_
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.2 before 18.7.5, 18.8 before 18.8.5, and 1
Crypt::SysRandom::XS versions before 0.010 for Perl is vulnerable to a heap buffer overflow in the XS function random_by
jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Pr
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and
ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's Byt
ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the server_m
A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-stock.php file
A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0. The vulnerability is loc
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 18.8.9, 18.9 before 18.9.5, and 1
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.8.9, 18.9 before 18.9.5, and
An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXConverter.cpp and ConvertMes
Conditional Fields for Contact Form 7 WordPress plugin through version 2.7.2 contains an uncontrolled resource consumpti
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.9.7, 18.10 before 18.10.6, and
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.2
This affects versions of the package exifreader before 4.39.0. A crafted image containing an ICC mluc tag can set an att
The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessive
The affected products perform improper length checking when parsing incoming HTTP requests, resulting in a size-limited
Kysely is a type-safe TypeScript SQL query builder. From 0.26.0 to 0.28.16, DefaultQueryCompiler.visitJSONPathLeg does n
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
Unauthenticated Other Vulnerability Type in WpEvently <= 5.3.3 versions.
Unauthenticated Other Vulnerability Type in WP Travel Engine <= 6.7.10 versions.
Unauthenticated Broken Authentication in Upsell Order Bump Offer for WooCommerce <= 3.1.4 versions.
Frequently Asked Questions
What is CWE-1284?
CWE-1284 (CWE-1284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-1284?
There are 152 CVE records associated with CWE-1284 in our database. Of these, 10 are critical severity, 61 are high severity, and 52 are medium severity.
How can I protect against CWE-1284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-1284 using AI-powered security agents.
Detect CWE-1284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-1284 vulnerabilities across your infrastructure.
Get Started