CWE-231 - Improper Handling of Extra Values
- Abstraction:Variant
- Structure:Simple
- Status:Draft
- Release Date:2006-07-19
- Latest Modification Date:2023-06-29
Weakness Name
Improper Handling of Extra Values
Description
The product does not handle or incorrectly handles when more values are provided than expected.
Common Consequences
Scope: Integrity
Impact: Unexpected State
Related Weaknesses
CWE-120Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')High
Microsoft tests new Windows 11 tool to remotely fix boot crashes
New Crocodilus malware steals Android users’ crypto wallet keys
Microsoft's killing script used to avoid Microsoft Account in Windows 11
RESURGE Malware Exploits Ivanti Flaw with Rootkit and Web Shell Features
U.S. seized $8.2 million in crypto linked to 'Romance Baiting' scams
New Android Trojan Crocodilus Abuses Accessibility to Steal Banking and Crypto Credentials
BlackLock Ransomware Exposed After Researchers Exploit Leak Site Vulnerability
Retail giant Sam’s Club investigates Clop ransomware breach claims
Phishing-as-a-service operation uses DNS-over-HTTPS for evasion
CVE-2020-29574 CyberoamOS (CROS) SQL Injection Vulnerability
CVE-2025-22224 VMware ESXi and Workstation TOCTOU Race Condition Vulnerability
CVE-2022-43939 Hitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability
CVE-2024-49035 Microsoft Partner Center Improper Access Control Vulnerability
CVE-2022-43769 Hitachi Vantara Pentaho BA Server Special Element Injection Vulnerability
CVE-2024-20953 Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability
CVE-2018-8639 Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability
CVE-2024-41710 Mitel SIP Phones Argument Injection Vulnerability
CVE-2025-0111 Palo Alto Networks PAN-OS File Read Vulnerability
CVE-2025-2783 Google Chromium Mojo Sandbox Escape Vulnerability
InformationalInformation Disclosure - Suspicious Comments
InformationalRe-examine Cache-control Directives