← Back
CWE-20

12,737 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,737)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Redhat
Wireshark
2Enterprise Linux
Wireshark
Apr 29, 2026
Apr 11, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
wiretap/iptrace.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a long packet in an AIX iptrace file.
2Redhat
Wireshark
2Enterprise Linux
Wireshark
Apr 29, 2026
Apr 11, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a long packet in a (1) Accellent 5Views (aka .5vw) file, (2) I4B trace file, or (3) NETMON...Show more
Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a long packet in a (1) Accellent 5Views (aka .5vw) file, (2) I4B trace file, or (3) NETMON 2 capture file.Show less
2Redhat
Wireshark
2Enterprise Linux
Wireshark
Apr 29, 2026
Apr 11, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The dissect_packet function in epan/packet.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a long packet in a capture file, as demons...Show more
The dissect_packet function in epan/packet.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a long packet in a capture file, as demonstrated by an airopeek file.Show less
1Microsoft
1.net Framework
Apr 29, 2026
Apr 10, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate function parameters, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser applicatio...Show more
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate function parameters, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka ".NET Framework Parameter Validation Vulnerability."Show less
1Microsoft
5Windows 7
Windows Server 2003Windows Server 2008+2 more
Apr 22, 2026
Apr 10, 2012
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Pr...Show more
The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly validate the digest of a signed portable executable (PE) file, which allows user-assisted remote attackers to execute arbitrary code via a modified file with additional content, aka "WinVerifyTrust Signature Validation Vulnerability."Show less
1Microsoft
1Forefront Unified Access Gateway
Apr 29, 2026
Apr 10, 2012
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Open redirect vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, a...Show more
Open redirect vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka "UAG Blind HTTP Redirect Vulnerability."Show less
1Hp
1Onboard Administrator
Apr 29, 2026
Apr 5, 2012
N/A· v4
N/A· v3
5.8 MEDIUM· v2
HP Onboard Administrator (OA) before 3.50 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
1Rockwellautomation
2Factorytalk
Rslogix 5000
Apr 29, 2026
Apr 2, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The FactoryTalk (FT) RNADiagReceiver service in Rockwell Automation Allen-Bradley FactoryTalk CPR9 through SR5 and RSLogix 5000 17 through 20 does not properly handle the return value from an unspecified function, which...Show more
The FactoryTalk (FT) RNADiagReceiver service in Rockwell Automation Allen-Bradley FactoryTalk CPR9 through SR5 and RSLogix 5000 17 through 20 does not properly handle the return value from an unspecified function, which allows remote attackers to cause a denial of service (service outage) via a crafted packet.Show less
1Google
1Chrome
Apr 29, 2026
Mar 30, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Google Chrome before 18.0.1025.142 does not properly validate the renderer's navigation requests, which has unspecified impact and remote attack vectors.
1Cisco
1Ios
Apr 29, 2026
Mar 29, 2012
N/A· v4
N/A· v3
7.8 HIGH· v2
The Smart Install feature in Cisco IOS 12.2, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (device reload) by sending a malformed Smart Install message over TCP, aka Bug ID CSCtt16051.
1Opera
1Opera Browser
Apr 29, 2026
Mar 28, 2012
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Opera before 11.62 on Mac OS X allows remote attackers to spoof the address field and security dialogs via crafted styling that causes page content to be displayed outside of the intended content area.
1Opera
1Opera Browser
Apr 29, 2026
Mar 28, 2012
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Opera before 11.62 allows remote attackers to spoof the address field by triggering a page reload followed by a redirect to a different domain.
1Opera
1Opera Browser
Apr 29, 2026
Mar 28, 2012
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Opera before 11.62 allows remote attackers to spoof the address field by triggering the launch of a dialog window associated with a different domain.
1Broadcom
1Arcserve Backup
Apr 29, 2026
Mar 22, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
CA ARCserve Backup r12.0 through SP2, r12.5 before SP2, r15 through SP1, and r16 before SP1 on Windows allows remote attackers to cause a denial of service (service shutdown) via a crafted network request.
1Ibm
1Db2
Apr 29, 2026
Mar 20, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IBM DB2 9.1 before FP11, 9.5 before FP9, 9.7 before FP5, and 9.8 before FP4 allows remote attackers to cause a denial of service (daemon crash) via a crafted Distributed Relational Database Architecture (DRDA) request.
1Ibm
1Db2
Apr 29, 2026
Mar 20, 2012
N/A· v4
N/A· v3
4.0 MEDIUM· v2
IBM DB2 9.5 before FP9, 9.7 through FP5, and 9.8 through FP4 does not properly check variables, which allows remote authenticated users to bypass intended restrictions on viewing table data by leveraging the CREATEIN pri...Show more
IBM DB2 9.5 before FP9, 9.7 through FP5, and 9.8 through FP4 does not properly check variables, which allows remote authenticated users to bypass intended restrictions on viewing table data by leveraging the CREATEIN privilege to execute crafted SQL CREATE VARIABLE statements.Show less
1Kylegilman
1Video Embed & Thumbnail Generator
Apr 29, 2026
Mar 19, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
kg_callffmpeg.php in the Video Embed & Thumbnail Generator plugin before 2.0 for WordPress allows remote attackers to execute arbitrary commands via unspecified vectors.
1Saurabh Gupta
1Tiny Server
Apr 29, 2026
Mar 19, 2012
N/A· v4
N/A· v3
7.8 HIGH· v2
Tiny Server 1.1.9 and earlier allows remote attackers to cause a denial of service (crash) via a long string in a GET request without an HTTP version number.
1Cisco
135500 Series Adaptive Security Appliance
Adaptive Security Appliance SoftwareCatalyst 6500+10 more
Apr 29, 2026
Mar 15, 2012
N/A· v4
N/A· v3
7.8 HIGH· v2
Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 7.0 through 7.2 before 7.2(5.7), 8.0 before 8.0(5.27), 8.1 before 8.1...Show more
Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 7.0 through 7.2 before 7.2(5.7), 8.0 before 8.0(5.27), 8.1 before 8.1(2.53), 8.2 before 8.2(5.8), 8.3 before 8.3(2.25), 8.4 before 8.4(2.5), and 8.5 before 8.5(1.2) and the Firewall Services Module (FWSM) 3.1 and 3.2 before 3.2(23) and 4.0 and 4.1 before 4.1(8) in Cisco Catalyst 6500 series devices, when multicast routing is enabled, allow remote attackers to cause a denial of service (device reload) via a crafted IPv4 PIM message, aka Bug IDs CSCtr47517 and CSCtu97367.Show less
1Cisco
115500 Series Adaptive Security Appliance
Adaptive Security Appliance SoftwareCatalyst 6500+8 more
Apr 29, 2026
Mar 15, 2012
N/A· v4
N/A· v3
7.8 HIGH· v2
Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.4 before 8.4(2.11) and 8.5 before 8.5(1.4) allow remote attackers t...Show more
Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.4 before 8.4(2.11) and 8.5 before 8.5(1.4) allow remote attackers to cause a denial of service (device reload) via (1) IPv4 or (2) IPv6 packets that trigger syslog message 305006, aka Bug ID CSCts39634.Show less