In the Linux kernel, the following vulnerability has been resolved: dlm: validate length in dlm_search_rsb_tree The le
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by
A flaw was found in OVN (Open Virtual Network). A remote attacker, by sending crafted DHCPv6 (Dynamic Host Configuration
mouse07410/asn1c is an ASN.1 compiler. In 1.4 and earlier, a memory safety vulnerability was identified in the OER decod
When processing the header of an incoming message, libnv failed to properly validate the message size. The lack of vali
mp_SetEnddisc() copied a user-supplied PSN endpoint value without length validation, allowing a buffer overflow via the
In the Linux kernel, the following vulnerability has been resolved: rxrpc: fix oversized RESPONSE authenticator length
A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises
websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, the frame format in draft versions
Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask
If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 accepts requests with opcode 0x5e, which con
A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside th
In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiv
A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ
Net::CIDR::Lite versions before 0.23 for Perl mishandles IPv4 mapped IPv6 addresses, which may allow IP ACL bypass. _pa
When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original
FastNetMon Community Edition through 1.2.9 has out-of-bounds memory access because it incorrectly parses BGP path attrib
FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket transport (libfreerdp/cor
Improper Handling of Length Parameter Inconsistency (CWE-130) vulnerability exists in TTSSH2 plugin of Tera Term provide
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi
An out-of-bounds read was found in the DHCPv4 packet capture code of wicked. ni_capture_inspect_udp_header() in src/capt
The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (El
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.24 to before 0.10.78, the FFI trampo
An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. ASGI requests with a missing or understated `Content-
Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.16, _read_character_string a
A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The SICAM SIAPP SDK client component doe
A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The SICAM SIAPP SDK server component doe
Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Files#fail sets the Cont
Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9
HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise
An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches
An improper handling of the length parameter inconsistency vulnerability has been identified in Moxa’s Secure Router. Be
An attacker sending tcp, il, rudp, rudp, or gre packets with a length less than the header size would trigger a kernel p
Improper bounds validation in EmberZNet SDK versions 9.0.2 and earlier may result in crashes or dynamic memory leakage.
In Bluetooth Mesh SDK 6.1.4 and earlier, malformed extended advertisements can trigger out-of-bounds writes leading to s
Frequently Asked Questions
What is CWE-130?
CWE-130 (CWE-130) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-130?
There are 44 CVE records associated with CWE-130 in our database. Of these, 2 are critical severity, 16 are high severity, and 20 are medium severity.
How can I protect against CWE-130 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-130 using AI-powered security agents.
Detect CWE-130 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-130 vulnerabilities across your infrastructure.
Get Started