Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-1284

MITRE ↗

CWE-1284

25
CRITICAL
152
HIGH
152
MEDIUM
24
LOW
381 CVEs · Page 6/8
4.3
CVE-2024-48290

An issue in the Bluetooth Low Energy implementation of Realtek RTL8762E BLE SDK v1.4.0 allows attackers to cause a Denia

2.3
CVE-2023-31304

Improper input validation in SMU may allow an attacker with privileges and a compromised physical function (PF)     to

CVE-2024-6768

A Denial of Service in CLFS.sys in Microsoft Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, and Windo

8.8
CVE-2023-25731

Due to URL previews in the network panel of developer tools improperly storing URLs, query parameters could potentially

8.6
CVE-2022-4904

A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string,

8.6
CVE-2023-42444

phonenumber is a library for parsing, formatting and validating international phone numbers. Prior to versions `0.3.3+8.

8.6
CVE-2023-42447

blurhash-rs is a pure Rust implementation of Blurhash, software for encoding images into ASCII strings that can be turne

8.1
CVE-2023-30269

CLTPHP <=6.0 is vulnerable to Improper Input Validation via application/admin/controller/Template.php.

8.1
CVE-2023-42448

Hydra is the layer-two scalability solution for Cardano. Prior to version 0.13.0, the specification states that the cont

7.8
CVE-2022-20493

In Condition of Condition.java, there is a possible way to grant notification access due to improper input validation. T

7.8
CVE-2022-47029

An issue was found in Action Launcher v50.5 allows an attacker to escalate privilege via modification of the intent stri

7.5
CVE-2022-48297

The geofencing kernel code has a vulnerability of not verifying the length of the input data. Successful exploitation of

7.5
CVE-2022-48298

The geofencing kernel code does not verify the length of the input data. Successful exploitation of this vulnerability m

7.5
CVE-2023-30082

A denial of service attack might be launched against the server if an unusually lengthy password (more than 10000000 cha

7.5
CVE-2023-34188

The HTTP server in Mongoose before 7.10 accepts requests containing negative Content-Length headers. By sending a single

7.5
CVE-2021-46893

Vulnerability of unstrict data verification and parameter check. Successful exploitation of this vulnerability may affec

7.5
CVE-2023-38744

Denial-of-service (DoS) vulnerability due to improper validation of specified type of input issue exists in the built-in

7.5
CVE-2023-41164

In Django 3.2 before 3.2.21, 4.1 before 4.1.11, and 4.2 before 4.2.5, django.utils.encoding.uri_to_iri() is subject to a

7.5
CVE-2023-43665

In Django 3.2 before 3.2.22, 4.1 before 4.1.12, and 4.2 before 4.2.6, the django.utils.text.Truncator chars() and words(

7.1
CVE-2023-35932

jcvi is a Python library to facilitate genome assembly, annotation, and comparative genomics. A configuration injection

6.7
CVE-2023-20707

In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr

6.7
CVE-2023-20708

In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation

6.7
CVE-2023-20722

In m4u, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of

6.5
CVE-2022-3411

A lack of length validation in GitLab CE/EE affecting all versions from 12.4 before 15.6.7, 15.7 before 15.7.6, and 15.8

6.5
CVE-2023-36839

An Improper Validation of Specified Quantity in Input vulnerability in the Layer-2 control protocols daemon (l2cpd) of

6.5
CVE-2023-4518

A vulnerability exists in the input validation of the GOOSE messages where out of range values received and processed

5.9
CVE-2023-23626

go-bitfield is a simple bitfield package for the go language aiming to be more performant that the standard library. Whe

5.5
CVE-2023-22409

An Unchecked Input for Loop Condition vulnerability in a NAT library of Juniper Networks Junos OS allows a local authent

5.5
CVE-2023-27941

A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Ventura 13.3, iOS 15.7.4

5.5
CVE-2023-27961

Multiple validation issues were addressed with improved input sanitization. This issue is fixed in macOS Ventura 13.3, i

5.5
CVE-2023-20704

In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information discl

5.5
CVE-2023-20705

In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information discl

5.5
CVE-2023-21111

In several functions of PhoneAccountRegistrar.java, there is a possible way to prevent an access to emergency services d

5.3
CVE-2021-28510

For certain systems running EOS, a Precision Time Protocol (PTP) packet of a management/signaling message with an invali

4.4
CVE-2023-20709

In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local informatio

4.4
CVE-2023-20710

In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local informatio

4.3
CVE-2023-4439

A vulnerability was found in SourceCodester Card Holder Management System 1.0 and classified as problematic. Affected by

2.7
CVE-2023-23549

Improper Input Validation in Checkmk <2.2.0p15, <2.1.0p37, <=2.0.0p39 allows priviledged attackers to cause partial deni

2.0
CVE-2023-0194

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer driver, where an inval

2.0
CVE-2023-0195

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer driver nvlddmkm.sys, where an ca

10.0
CVE-2021-21960

A stack-based buffer overflow vulnerability exists in both the LLMNR functionality of Sealevel Systems, Inc. SeaConnect

10.0
CVE-2022-20699 KEV

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker t

9.8
CVE-2022-37134

D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Buffer Overflow via /goform/form2Wan.cgi. When wantype is 3, l2tp_usrn

9.8
CVE-2022-20385

a function called 'nla_parse', do not check the len of para, it will check nla_type (which can be controlled by userspac

9.8
CVE-2022-36938

DexLoader function get_stringidx_fromdex() in Redex prior to commit 3b44c64 can load an out of bound address when loadin

9.8
CVE-2022-25727

Memory Corruption in modem due to improper length check while copying into memory in Snapdragon Consumer IOT, Snapdragon

8.8
CVE-2021-21943

A heap-based buffer overflow vulnerability exists in the XWD parser functionality of Accusoft ImageGear 19.10. A special

8.8
CVE-2022-36078

Binary provides encoding/decoding in Borsh and other formats. The vulnerability is a memory allocation vulnerability tha

8.5
CVE-2022-24754

PJSIP is a free and open source multimedia communication library written in C language. In versions prior to and includi

8.4
CVE-2021-30350

Lack of MBN header size verification against input buffer can lead to memory corruption in Snapdragon Auto, Snapdragon C

Frequently Asked Questions

What is CWE-1284?

CWE-1284 (CWE-1284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-1284?

There are 430 CVE records associated with CWE-1284 in our database. Of these, 25 are critical severity, 152 are high severity, and 152 are medium severity.

How can I protect against CWE-1284 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-1284 using AI-powered security agents.

Detect CWE-1284 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-1284 vulnerabilities across your infrastructure.

Get Started