CWE-20
12,737 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,737)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Redhat Wireshark2Enterprise Linux WiresharkApr 29, 2026 Apr 11, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 wiretap/iptrace.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a long packet in an AIX iptrace file. |
2Redhat Wireshark2Enterprise Linux WiresharkApr 29, 2026 Apr 11, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a long packet in a (1) Accellent 5Views (aka .5vw) file, (2) I4B trace file, or (3) NETMON...Show more |
2Redhat Wireshark2Enterprise Linux WiresharkApr 29, 2026 Apr 11, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The dissect_packet function in epan/packet.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a long packet in a capture file, as demons...Show more |
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate function parameters, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser applicatio...Show more |
1Microsoft 5Windows 7 Windows Server 2003Windows Server 2008+2 moreApr 22, 2026 Apr 10, 2012 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Pr...Show more |
1Microsoft 1Forefront Unified Access Gateway Apr 29, 2026 Apr 10, 2012 N/A· v4 N/A· v3 5.8 MEDIUM· v2 Open redirect vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, a...Show more |
HP Onboard Administrator (OA) before 3.50 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. |
1Rockwellautomation 2Factorytalk Rslogix 5000Apr 29, 2026 Apr 2, 2012 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The FactoryTalk (FT) RNADiagReceiver service in Rockwell Automation Allen-Bradley FactoryTalk CPR9 through SR5 and RSLogix 5000 17 through 20 does not properly handle the return value from an unspecified function, which...Show more |
Google Chrome before 18.0.1025.142 does not properly validate the renderer's navigation requests, which has unspecified impact and remote attack vectors. |
The Smart Install feature in Cisco IOS 12.2, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (device reload) by sending a malformed Smart Install message over TCP, aka Bug ID CSCtt16051. |
Opera before 11.62 on Mac OS X allows remote attackers to spoof the address field and security dialogs via crafted styling that causes page content to be displayed outside of the intended content area. |
Opera before 11.62 allows remote attackers to spoof the address field by triggering a page reload followed by a redirect to a different domain. |
Opera before 11.62 allows remote attackers to spoof the address field by triggering the launch of a dialog window associated with a different domain. |
CA ARCserve Backup r12.0 through SP2, r12.5 before SP2, r15 through SP1, and r16 before SP1 on Windows allows remote attackers to cause a denial of service (service shutdown) via a crafted network request. |
IBM DB2 9.1 before FP11, 9.5 before FP9, 9.7 before FP5, and 9.8 before FP4 allows remote attackers to cause a denial of service (daemon crash) via a crafted Distributed Relational Database Architecture (DRDA) request. |
IBM DB2 9.5 before FP9, 9.7 through FP5, and 9.8 through FP4 does not properly check variables, which allows remote authenticated users to bypass intended restrictions on viewing table data by leveraging the CREATEIN pri...Show more |
1Kylegilman 1Video Embed & Thumbnail Generator Apr 29, 2026 Mar 19, 2012 N/A· v4 N/A· v3 7.5 HIGH· v2 kg_callffmpeg.php in the Video Embed & Thumbnail Generator plugin before 2.0 for WordPress allows remote attackers to execute arbitrary commands via unspecified vectors. |
Tiny Server 1.1.9 and earlier allows remote attackers to cause a denial of service (crash) via a long string in a GET request without an HTTP version number. |
1Cisco 135500 Series Adaptive Security Appliance Adaptive Security Appliance SoftwareCatalyst 6500+10 moreApr 29, 2026 Mar 15, 2012 N/A· v4 N/A· v3 7.8 HIGH· v2 Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 7.0 through 7.2 before 7.2(5.7), 8.0 before 8.0(5.27), 8.1 before 8.1...Show more |
1Cisco 115500 Series Adaptive Security Appliance Adaptive Security Appliance SoftwareCatalyst 6500+8 moreApr 29, 2026 Mar 15, 2012 N/A· v4 N/A· v3 7.8 HIGH· v2 Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.4 before 8.4(2.11) and 8.5 before 8.5(1.4) allow remote attackers t...Show more |