Parameters are not validated or sanitized, and are later used in various internal operations.
The product parses a formatted message or structure, but it does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data.