CWE-1287
145 CVEs • Abstraction: Base
Improper Validation of Specified Type of Input
The product receives input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.
CVEs (145)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In KDE Connect before 1.33.0 on Android, malicious device IDs (sent via broadcast UDP) could cause an application crash. |
In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privile...Show more |
An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via the Nudm_SubscriberDataManagement API. |
Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins fail to sanitize tag_key inputs. An attacker with network access or the ability to write records into Splunk or Elasticsearch can supply tag_key values co...Show more |
An unauthenticated remote attacker can send a specially crafted Modbus read command to the device which leads to a denial of service. |
The VAPIX API port.cgi did not have sufficient input validation, which may result in process crashes and impact usability. This vulnerability can only be exploited after authenticating with a viewer- operator- or adminis...Show more |
An ACAP configuration file has improper permissions and lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the...Show more |
ACAP applications can gain elevated privileges due to improper input validation, potentially leading to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the install...Show more |
An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsign...Show more |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreJun 17, 2026 Oct 14, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally. |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreJun 17, 2026 Oct 14, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally. |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreJun 17, 2026 Oct 14, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally. |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreJun 17, 2026 Oct 14, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network. |
1Microsoft 4Windows 11 24h2 Windows 11 25h2Windows Server 2022 23h2+1 moreJun 17, 2026 Oct 14, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network. |
1Microsoft 16Windows 10 1507 Windows 10 1607Windows 10 1809+13 moreJun 17, 2026 Oct 14, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network. |
1Microsoft 16Windows 10 1507 Windows 10 1607Windows 10 1809+13 moreJun 17, 2026 Oct 14, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper validation of specified type of input in Microsoft Windows allows an authorized attacker to elevate privileges locally. |
Mattermost Desktop App versions <= 5.13.0 fail to validate URLs external to the configured Mattermost servers, allowing an attacker on a server the user has configured to crash the user's application by sending the user...Show more |
Synapse is an open source Matrix homeserver implementation. Lack of validation for device keys in Synapse before 1.138.3 and in Synapse 1.139.0 allow an attacker registered on the victim homeserver to degrade federation...Show more |
A vulnerability in the web UI of Cisco IOS Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to im...Show more |
Improper Validation of Specified Type of Input vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5. |