CWE-1284

CWE-1284 · 9 records · 6 with a public proof-of-concept

Records the NVD classes under CWE-1284, highest CVSS first.

  1. HIGH 7.5CVE-2026-97057public PoC

    redis-parser through 3.0.0 fails to validate the multi-bulk length value in RESP protocol parsing, allowing attackers to trigger an uncaught RangeError by supplying an excessively large declared length. A malicious or compromised Redis endpoint can deliver a c…

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 7.5CVE-2026-94450public PoC

    Improper validation of the Destination Connection ID length in s2n-quic 1.88.0 and earlier may allow an unauthenticated remote user to cause a denial of service by shutting down a server endpoint via a single crafted UDP datagram. Only server endpoints specifi…

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 7.5CVE-2026-93345

    MikroTik RouterOS before 7.25beta4 contains an improper input validation vulnerability in the labelled-VPN NLRI iterators of the routing service that allows an unauthenticated on-path attacker to crash the BGP service by sending a malformed MP_REACH_NLRI UPDAT…

    AI risk analysis on Exploit-DB.ai →

  4. HIGH 7.5CVE-2026-70378public PoC

    imagecli's pipeline operation (Carve::apply in src/image_ops.rs) only asserts , never validating that the ratio is positive. A negative ratio (e.g. -5) causes the computed target width to saturate to 0 via Rust's defined float-to-uint cast, which is then passe…

    AI risk analysis on Exploit-DB.ai →

  5. MEDIUM 6.5CVE-2026-73436

    On affected platforms running Arista EOS with OSPFv2 and OSPFv2 segment routing configured, a specially crafted OSPFv2 packet from an adjacent OSPF neighbor may cause OSPF to restart unexpectedly.

    AI risk analysis on Exploit-DB.ai →

  6. MEDIUM 6.3CVE-2026-93015public PoC

    BlueKitchen BTstack through 1.8.2 fails to validate the peer-reported endpoint count against table bounds in A2DP stream endpoint discovery. A bonded peer can send an AVDTP DISCOVER response with more endpoints than the fixed table holds, causing out-of-bounds…

    AI risk analysis on Exploit-DB.ai →

  7. MEDIUM 5.3CVE-2026-97058public PoC

    sprintf-js through 1.1.3 passes unbounded precision specifiers to toFixed, toExponential, and toPrecision methods without validation, causing uncaught RangeError exceptions. Attackers who control format strings can inject precision values exceeding ECMAScript …

    AI risk analysis on Exploit-DB.ai →

  8. UNSCOREDCVE-2026-12974

    A Security Policy Bypass vulnerability exists in Forcepoint Security Engine (NGFW). This issue affects Forcepoint Security Engine (NGFW): from 7.1.0 through 7.1.13, from 7.3.0 through 7.3.1, 7.3.3, from 7.4.0 through 7.4.1, and 7.5.0.

    AI risk analysis on Exploit-DB.ai →

  9. UNSCOREDCVE-2026-89420public PoC

    Improper Validation of Specified Quantity in Input in ZenHive mpp allows a client holding an open payment channel to obtain paid resources without being charged. MPP.Session.Actions.accept_voucher/3 in lib/mpp/session/actions.ex treats a voucher whose cumulat…

    AI risk analysis on Exploit-DB.ai →