An authorization flaw in the user management command could allow an authenticated user to make limited changes to authen
Sandboxie 5.30 contains a denial of service vulnerability that allows local attackers to crash the application by supply
fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From version 4.0.
An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXParser.cpp, ParseVectorDataA
sppp_pap_input in sys/net/if_spppsubr.c in OpenBSD before 076e2b1 allows authentication bypass via certain zero values f
In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: disallow non-power of two min_region
NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_valid() function fails to validate s_log_block_size
IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an aut
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could
IBM OPENBMC FW1110.00 through FW1110.11 is vulnerable to denial of service attacks by unauthenticated network users.
Unauthenticated Other Vulnerability Type in Contest Gallery <= 28.1.7 versions.
rsync before 3.5.0 contains a logic error in --max-alloc handling that allows a sender or configuration setting --max-al
A flaw was found in Keycloak. A remote attacker with high privileges, such as a realm administrator configuring a malici
In ScreenConnect™ versions prior to 26.2, input validation within the Host Pass creation functionality could allow an au
Ledger Nano X, Flex, and Stax devices contain a denial of service vulnerability in the MCU firmware update process due t
A security vulnerability has been detected in OWASP DefectDojo up to 2.55.4. This vulnerability affects the function inp
CWE-1284 Improper Validation of Specified Quantity in Input vulnerability exists that could cause Event and Data Log tru
In OpenBSD through 7.8, the slaacd and rad daemons have an infinite loop when they receive a crafted ICMPv6 Neighbor Dis
Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the toc plugin and TableOfContents direc
An improper access control vulnerability exists where an authenticated non-administrative application user could potenti
internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important
GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandl
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, improper validat
Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.31, parse_form() did not validate the Content-
tor before 0.4.9.9 was prone to an infinite loop when decompressing a truncated zlib/gzip stream with done=1. A truncat
Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor n
zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts
CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM becaus
Tanium addressed an improper input validation vulnerability in Discover.
Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows
An integer underflow vulnerability in the Silicon Labs Z-Wave Protocol Controller can lead to out of bounds memory reads
A denial-of-service security issue in the affected product. The security issue occurs when a malformed CIP forward open
Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric MELSEC iQ-R Series R08PCPU, R16P
Improper input validation in IOMMU could allow a malicious hypervisor to reconfigure IOMMU registers resulting in loss o
Improper bound check within AMD CPU microcode can allow a malicious guest to write to host memory, potentially resulting
Insufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_
Insufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_
** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows
** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the PayPalEmail payment
Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the f
Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the
Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the f
H5Z__filter_nbit in H5Znbit.c in HDF5 through 2.3.0 dereferences cd_values[0] through cd_values[4] without validating th
H5Z__filter_fletcher32 in H5Zfletcher32.c in HDF5 through 2.3.0 computes the data length to checksum by subtracting the
GNU Emacs for Android improperly validates the table header input in sfnt_read_table_directory() in src/sfnt.c. Due to a
ServiceNow has remediated a sandbox escape security issue that was identified in the Now Platform. This security issue c
A heap-based buffer overflow vulnerability in Fireware OS's iked process allows an authenticated administrator to crash
A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process iallows a remote unauthenticated
Frequently Asked Questions
What is CWE-1284?
CWE-1284 (CWE-1284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-1284?
There are 430 CVE records associated with CWE-1284 in our database. Of these, 25 are critical severity, 152 are high severity, and 152 are medium severity.
How can I protect against CWE-1284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-1284 using AI-powered security agents.
Detect CWE-1284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-1284 vulnerabilities across your infrastructure.
Get Started