← Back
CWE-20

12,744 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,744)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Lullabot
1Fivestar Module For Drupal
Apr 29, 2026
Aug 14, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Fivestar module 6.x-1.x before 6.x-1.20 for Drupal does not properly validate voting data, which allows remote attackers to manipulate voting averages via a negative value in the vote parameter.
1Nodejs
1Node.js
Apr 29, 2026
Aug 13, 2012
N/A· v4
N/A· v3
6.4 MEDIUM· v2
The Update method in src/node_http_parser.cc in Node.js before 0.6.17 and 0.7 before 0.7.8 does not properly check the length of a string, which allows remote attackers to obtain sensitive information (request header con...Show more
The Update method in src/node_http_parser.cc in Node.js before 0.6.17 and 0.7 before 0.7.8 does not properly check the length of a string, which allows remote attackers to obtain sensitive information (request header contents) and possibly spoof HTTP headers via a zero length string.Show less
1Bytemark
1Symbiosis
Apr 29, 2026
Aug 13, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Bytemark Symbiosis before Revision 1322 does not properly validate passwords, which allows remote attackers to gain access to email accounts via an arbitrary password.
1Caucho
1Resin
Apr 29, 2026
Aug 12, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Caucho Quercus, as distributed in Resin before 4.0.29, does not properly handle unspecified characters in the names of variables, which has unknown impact and remote attack vectors, related to an "HTTP Parameter Contamin...Show more
Caucho Quercus, as distributed in Resin before 4.0.29, does not properly handle unspecified characters in the names of variables, which has unknown impact and remote attack vectors, related to an "HTTP Parameter Contamination" issue.Show less
1Breakingpointsystems
2Breakingpoint Storm Appliance
Breakingpoint Storm Appliance Ctm
Apr 29, 2026
Aug 12, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The BreakingPoint Storm appliance before 3.0 requires cleartext credentials for establishing a session from a GUI administrative client, which allows remote attackers to obtain sensitive information by sniffing the netwo...Show more
The BreakingPoint Storm appliance before 3.0 requires cleartext credentials for establishing a session from a GUI administrative client, which allows remote attackers to obtain sensitive information by sniffing the network for XML documents.Show less
1Linux
1Linux Kernel
Apr 29, 2026
Aug 9, 2012
N/A· v4
N/A· v3
7.2 HIGH· v2
The sock_alloc_send_pskb function in net/core/sock.c in the Linux kernel before 3.4.5 does not properly validate a certain length value, which allows local users to cause a denial of service (heap-based buffer overflow a...Show more
The sock_alloc_send_pskb function in net/core/sock.c in the Linux kernel before 3.4.5 does not properly validate a certain length value, which allows local users to cause a denial of service (heap-based buffer overflow and system crash) or possibly gain privileges by leveraging access to a TUN/TAP device.Show less
1Ibm
3Global Security Kit
Rational Directory ServerTivoli Directory Server
Apr 29, 2026
Aug 8, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IBM Global Security Kit (aka GSKit) before 8.0.14.22, as used in IBM Rational Directory Server, IBM Tivoli Directory Server, and other products, does not properly validate data during execution of a protection mechanism...Show more
IBM Global Security Kit (aka GSKit) before 8.0.14.22, as used in IBM Rational Directory Server, IBM Tivoli Directory Server, and other products, does not properly validate data during execution of a protection mechanism against the Vaudenay SSL CBC timing attack, which allows remote attackers to cause a denial of service (application crash) via crafted values in the TLS Record Layer, a different vulnerability than CVE-2012-2333.Show less
1Martin Nagy
1Bind Dyndb Ldap
Apr 29, 2026
Aug 7, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The dns_to_ldap_dn_escape function in src/ldap_convert.c in bind-dyndb-ldap 1.1.0rc1 and earlier does not properly escape distinguished names (DN) for LDAP queries, which allows remote DNS servers to cause a denial of se...Show more
The dns_to_ldap_dn_escape function in src/ldap_convert.c in bind-dyndb-ldap 1.1.0rc1 and earlier does not properly escape distinguished names (DN) for LDAP queries, which allows remote DNS servers to cause a denial of service (named service hang) via a "$" character in a DN in a DNS query.Show less
1Cisco
1Ip Communicator
Apr 29, 2026
Aug 6, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Cisco IP Communicator 8.6 allows man-in-the-middle attackers to modify the Certificate Trust List via unspecified vectors, aka Bug ID CSCtz01471.
1Mit
1Kerberos 5
Apr 29, 2026
Aug 6, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
The kdc_handle_protected_negotiation function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8.x, 1.9.x before 1.9.5, and 1.10.x before 1.10.3 attempts to calculate a checksum before verifying that t...Show more
The kdc_handle_protected_negotiation function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8.x, 1.9.x before 1.9.5, and 1.10.x before 1.10.3 attempts to calculate a checksum before verifying that the key type is appropriate for a checksum, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized pointer free, heap memory corruption, and daemon crash) via a crafted AS-REQ request.Show less
1Cisco
1Ios
Apr 29, 2026
Aug 6, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The MallocLite implementation in Cisco IOS 12.0, 12.2, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (Route Processor crash) via a BGP UPDATE message with a modified local-preference (aka LOCA...Show more
The MallocLite implementation in Cisco IOS 12.0, 12.2, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (Route Processor crash) via a BGP UPDATE message with a modified local-preference (aka LOCAL_PREF) attribute length, aka Bug ID CSCtq06538.Show less
1Djangoproject
1Django
Apr 29, 2026
Jul 31, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The django.forms.ImageField class in the form system in Django before 1.3.2 and 1.4.x before 1.4.1 completely decompresses image data during image validation, which allows remote attackers to cause a denial of service (m...Show more
The django.forms.ImageField class in the form system in Django before 1.3.2 and 1.4.x before 1.4.1 completely decompresses image data during image validation, which allows remote attackers to cause a denial of service (memory consumption) by uploading an image file.Show less
1Ibm
2Aix
Vios
Apr 29, 2026
Jul 30, 2012
N/A· v4
N/A· v3
4.9 MEDIUM· v2
The kernel in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly implement the dupmsg system call, which allows local users to cause a denial of service (system crash) via a crafted application.
1Systemtap
1Systemtap
Apr 29, 2026
Jul 26, 2012
N/A· v4
N/A· v3
3.7 LOW· v2
The insert_module function in runtime/staprun/staprun_funcs.c in the systemtap runtime tool (staprun) in SystemTap before 1.6 does not properly validate a module when loading it, which allows local users to gain privileg...Show more
The insert_module function in runtime/staprun/staprun_funcs.c in the systemtap runtime tool (staprun) in SystemTap before 1.6 does not properly validate a module when loading it, which allows local users to gain privileges via a race condition between the signature validation and the module initialization.Show less
1Systemtap
1Systemtap
Apr 29, 2026
Jul 26, 2012
N/A· v4
N/A· v3
4.4 MEDIUM· v2
runtime/staprun/staprun_funcs.c in the systemtap runtime tool (staprun) in SystemTap before 1.6 does not properly validate modules when a module path is specified by a user for user-space probing, which allows local user...Show more
runtime/staprun/staprun_funcs.c in the systemtap runtime tool (staprun) in SystemTap before 1.6 does not properly validate modules when a module path is specified by a user for user-space probing, which allows local users in the stapusr group to gain privileges via a crafted module in the search path in the -u argument.Show less
1Apple
1Safari
Apr 29, 2026
Jul 25, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
CRLF injection vulnerability in WebKit in Apple Safari before 6.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP request splitting attacks via a crafted web site that leverages improper WebSock...Show more
CRLF injection vulnerability in WebKit in Apple Safari before 6.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP request splitting attacks via a crafted web site that leverages improper WebSockets URI handling.Show less
1Apple
1Safari
Apr 29, 2026
Jul 25, 2012
N/A· v4
N/A· v3
5.8 MEDIUM· v2
WebKit in Apple Safari before 6.0 does not properly handle Cascading Style Sheets (CSS) property values, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.
1Apple
1Safari
Apr 29, 2026
Jul 25, 2012
N/A· v4
N/A· v3
5.8 MEDIUM· v2
WebKit in Apple Safari before 6.0 does not properly handle drag-and-drop events, which allows user-assisted remote attackers to bypass the Same Origin Policy via a crafted web site.
1Isc
1Bind
Apr 29, 2026
Jul 25, 2012
N/A· v4
N/A· v3
7.8 HIGH· v2
ISC BIND 9.4.x, 9.5.x, 9.6.x, and 9.7.x before 9.7.6-P2; 9.8.x before 9.8.3-P2; 9.9.x before 9.9.1-P2; and 9.6-ESV before 9.6-ESV-R7-P2, when DNSSEC validation is enabled, does not properly initialize the failing-query c...Show more
ISC BIND 9.4.x, 9.5.x, 9.6.x, and 9.7.x before 9.7.6-P2; 9.8.x before 9.8.3-P2; 9.9.x before 9.9.1-P2; and 9.6-ESV before 9.6-ESV-R7-P2, when DNSSEC validation is enabled, does not properly initialize the failing-query cache, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) by sending many queries.Show less
1Moodle
1Moodle
Apr 29, 2026
Jul 20, 2012
N/A· v4
N/A· v3
4.9 MEDIUM· v2
Open redirect vulnerability in the Calendar set page in Moodle 2.1.x before 2.1.3 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via a redirection URL.