CWE-20
12,815 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,815)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The dissect_sip_common function in epan/dissectors/packet-sip.c in the SIP dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 does not properly initialize a data structure, which allows remote attackers...Show more |
The ieee802154_map_rec function in epan/dissectors/packet-ieee802154.c in the IEEE 802.15.4 dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 uses an incorrect pointer chain, which allows remote attacke...Show more |
1Cisco 1Adaptive Security Appliance Cx Context Aware Security Software Apr 29, 2026 Nov 4, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The Safe Search enforcement feature in Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security Software does not properly perform filtering, which allows remote attackers to bypass intended policy restrictions...Show more |
Xen before 4.1.x, 4.2.x, and 4.3.x does not take the page_alloc_lock and grant_table.lock in the same order, which allows local guest administrators with access to multiple vcpus to cause a denial of service (host deadlo...Show more |
1Ibm 2Tivoli Federated Identity Manager Tivoli Federated Identity Manager Business GatewayApr 29, 2026 Nov 1, 2013 N/A· v4 N/A· v3 5.8 MEDIUM· v2 Open redirect vulnerability in IBM Tivoli Federated Identity Manager (TFIM) 6.1.1 before IF 15, 6.2.0 before IF 14, 6.2.1, and 6.2.2 before IF 8 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.1.1 befor...Show more |
1Cisco 7Asr 1001 Asr 1002Asr 1002 X+4 moreApr 29, 2026 Oct 31, 2013 N/A· v4 N/A· v3 7.8 HIGH· v2 Cisco IOS XE 3.9 before 3.9.2S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) by sending malformed EoGRE packets over (1) IPv4 or (2) IPv6, aka Bug ID CSCuf08269. |
1Cisco 7Asr 1001 Asr 1002Asr 1002 X+4 moreApr 29, 2026 Oct 31, 2013 N/A· v4 N/A· v3 7.8 HIGH· v2 The TCP reassembly feature in Cisco IOS XE 3.7 before 3.7.3S and 3.8 before 3.8.1S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) via large TCP packets that are processed by the...Show more |
1Cisco 7Asr 1001 Asr 1002Asr 1002 X+4 moreApr 29, 2026 Oct 31, 2013 N/A· v4 N/A· v3 7.8 HIGH· v2 The PPTP ALG implementation in Cisco IOS XE 3.9 before 3.9.2S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) by sending many PPTP packets over NAT, aka Bug ID CSCuh19936. |
1Cisco 7Asr 1001 Asr 1002Asr 1002 X+4 moreApr 29, 2026 Oct 31, 2013 N/A· v4 N/A· v3 7.8 HIGH· v2 Cisco IOS XE 3.4 before 3.4.2S and 3.5 before 3.5.1S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) via malformed ICMP error packets associated with a (1) TCP or (2) UDP session...Show more |
1Mozilla 4Firefox SeamonkeyThunderbird+1 moreApr 29, 2026 Oct 30, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The SELECT element implementation in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22 does not properly restrict the nature or placement of HTML within a dropd...Show more |
1Triplc 2Nano 10 Plc Nano 10 Plc FirmwareApr 29, 2026 Oct 29, 2013 N/A· v4 N/A· v3 7.8 HIGH· v2 Triangle Research International (aka Tri) Nano-10 PLC devices with firmware r81 and earlier do not properly handle large length values in MODBUS data, which allows remote attackers to cause a denial of service (transitio...Show more |
The compressed packet parser in GnuPG 1.4.x before 1.4.15 and 2.0.x before 2.0.22 allows remote attackers to cause a denial of service (infinite recursion) via a crafted OpenPGP message. |
2Redhat Ubuntu5Jboss Enterprise Brms Platform Jboss Enterprise Portal PlatformJboss Enterprise Web Server+2 moreApr 29, 2026 Oct 28, 2013 N/A· v4 N/A· v3 7.5 HIGH· v2 The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red Hat JBoss Web Server 1.0.2 allows remote attackers to write to arbitrary files vi...Show more |
1F5 9Big Ip Access Policy Manager Big Ip Application Security ManagerBig Ip Edge Gateway+6 moreApr 29, 2026 Oct 26, 2013 N/A· v4 N/A· v3 7.8 HIGH· v2 The Traffic Management Microkernel (TMM) in F5 BIG-IP LTM, APM, ASM, Edge Gateway, GTM, Link Controller, and WOM 10.0.0 through 10.2.2 and 11.0.0; Analytics 11.0.0; PSM 9.4.0 through 9.4.8, 10.0.0 through 10.2.4, and 11....Show more |
TimThumb (timthumb.php) before 2.0 does not validate the entire source with the domain white list, which allows remote attackers to upload and execute arbitrary code via a URL containing a white-listed domain in the src...Show more |
VideoLAN VLC Media Player 2.0.8 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in a URL in a m3u file. |
1Cisco 3Content Security Management Appliance Email Security Appliance FirmwareWeb Security ApplianceApr 29, 2026 Oct 24, 2013 N/A· v4 N/A· v3 7.8 HIGH· v2 The web framework on Cisco Web Security Appliance (WSA), Email Security Appliance (ESA), and Content Security Management Appliance (SMA) devices does not properly manage the state of HTTP and HTTPS sessions, which allows...Show more |
1Cisco 1Secure Access Control System Apr 29, 2026 Oct 24, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Cisco Secure Access Control System (ACS) does not properly implement an incoming-packet firewall rule, which allows remote attackers to cause a denial of service (process crash) via a flood of crafted packets, aka Bug ID...Show more |
The USB hub controller in Apple Mac OS X before 10.9 allows local users to cause a denial of service (system crash) via a request with a crafted (1) port or (2) port number. |
The kernel in Apple Mac OS X before 10.9 allows local users to obtain sensitive information or cause a denial of service (out-of-bounds read and system crash) via a crafted Mach-O file. |