Weaknesses of type CWE-1284

324 results

Validação inadequada da quantidade de dados em entrada

A aplicação não valida corretamente a quantidade, tamanho ou volume de dados que recebe do usuário, permitindo que entradas maiores ou menores que o esperado passem pelo controle. Isso abre espaço para ataques de negação de serviço, estouro de buffer, consumo excessivo de recursos ou processamento de dados malformados.

Example

Um serviço web aceita um parâmetro 'quantidade' para retornar registros, mas não limita o valor máximo. Um atacante envia quantidade=999999999, forçando a aplicação a alocar gigabytes de memória ou executar query que consome toda a CPU, derrubando o serviço para usuários legítimos.

How to mitigate

Implemente validação explícita para toda entrada numérica ou de tamanho: defina limites mínimos e máximos aceitáveis, rejeite silenciosamente o que sair desses intervalos e registre tentativas suspeitas. Use whitelist de valores válidos quando possível.

CVE-2026-1352MEDIUMIBM® Db2® is vulnerable to a trap or return SQLCODE -901 when compiling a specially crafted query with a defined indexEPSS 0.3%CVE-2026-78010HIGHFireware OS Stack-Based Buffer Overflow in iked Allows Unauthenticated Denial of ServiceEPSS 0.3%CVE-2026-16025HIGHImproper Payment Validation in PayTR's PayTR Virtual Pos iFrame API (v9x) WHMCS ModuleEPSS 0.3%CVE-2025-8320HIGHTesla Wall Connector Content-Length Header Improper Input Validation Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-9704MEDIUMKeycloak: keycloak: privilege escalation due to oversized subject_token jwtEPSS 0.3%CVE-2025-36428MEDIUMIBM Db2 Denial of ServiceEPSS 0.3%CVE-2024-31957MEDIUMA vulnerability was discovered in Samsung Mobile Processors Exynos 2200 and Exynos 2400 where they lack a check for the validation of nativeEPSS 0.3%CVE-2026-83115HIGHVulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Command Line - RapidClone). Supported versiEPSS 0.3%CVE-2026-59531HIGHWordPress Falcon – WordPress Optimizations & Tweaks plugin <= 2.10.0 - Unknown vulnerabilityEPSS 0.3%CVE-2025-12385HIGHImproper validation of <img> tag size in Text component parserEPSS 0.3%CVE-2026-40093HIGHnimiq-blockchain is missing a wall-clock upper bound on block timestampsEPSS 0.3%CVE-2025-52534MEDIUMImproper bound check within AMD CPU microcode can allow a malicious guest to write to host memory, potentially resulting in loss of integritEPSS 0.3%CVE-2026-2474HIGHCrypt::URandom versions from 0.41 before 0.55 for Perl is vulnerable to a heap buffer overflow in the XS function crypt_urandom_getrandom()EPSS 0.3%CVE-2025-49292MEDIUMWordPress Profile Builder plugin <= 3.13.8 - Content Spoofing VulnerabilityEPSS 0.3%CVE-2023-0195LOWNVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer driver nvlddmkm.sys, where an can cause CWE-1284, whEPSS 0.3%CVE-2026-27384CRITICALWordPress W3 Total Cache plugin <= 2.9.1 - Arbitrary Code Execution vulnerabilityEPSS 0.3%CVE-2026-76899MEDIUMCordysCRM: Authenticated SQL injection via `sort.name` on `POST /account-pool/page`EPSS 0.3%CVE-2023-52343MEDIUMIn SecurityCommand message after as security has been actived., there is a possible improper input validation. This could lead to remote infEPSS 0.3%CVE-2026-48977HIGHOpenSlide: Arbitrary memory write with crafted Ventana BIF fileEPSS 0.3%CVE-2024-7488MEDIUMBusiness Logic Error in RestApp Inc.'s Online Ordering SystemEPSS 0.3%