CWE-20
12,737 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,737)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 115500 Series Adaptive Security Appliance Adaptive Security Appliance SoftwareCatalyst 6500+8 moreApr 29, 2026 Mar 15, 2012 N/A· v4 N/A· v3 7.1 HIGH· v2 The Threat Detection feature on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.0 through 8.2 before 8.2(5.20), 8.3...Show more |
1Cisco 115500 Series Adaptive Security Appliance Adaptive Security Appliance SoftwareCatalyst 6500+8 moreApr 29, 2026 Mar 15, 2012 N/A· v4 N/A· v3 7.1 HIGH· v2 The UDP inspection engine on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.0 before 8.0(5.25), 8.1 before 8.1(2.5...Show more |
1Mozilla 4Firefox SeamonkeyThunderbird+1 moreApr 29, 2026 Mar 14, 2012 N/A· v4 N/A· v3 7.5 HIGH· v2 The nsWindow implementation in the browser engine in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3,...Show more |
1Microsoft 5Windows 7 Windows Server 2003Windows Server 2008+2 moreApr 29, 2026 Mar 13, 2012 N/A· v4 8.4 HIGH· v3 7.2 HIGH· v2 win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle window m...Show more |
1Microsoft 3Windows 7 Windows Server 2008Windows VistaApr 29, 2026 Mar 13, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 DirectWrite in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly render Unicode characters, which allows remote attackers to cause a denial of service (app...Show more |
1Microsoft 2Windows 7 Windows Server 2008Apr 29, 2026 Mar 13, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The Remote Desktop Protocol (RDP) service in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (application hang) via a series of crafted packets,...Show more |
VMware vCenter Chargeback Manager (aka CBM) before 2.0.1 does not properly handle XML API requests, which allows remote attackers to read arbitrary files or cause a denial of service via unspecified vectors. |
1Ibm 2Maximo Asset Management Maximo Asset Management EssentialsApr 29, 2026 Mar 13, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Open redirect vulnerability in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via the...Show more |
The Internationalized Domain Name (IDN) feature in Apple Safari before 5.1.4 on Windows does not properly restrict the characters in URLs, which allows remote attackers to spoof a domain name via unspecified homoglyphs. |
CFNetwork in Apple iOS before 5.1 does not properly construct request headers during parsing of URLs, which allows remote attackers to obtain sensitive information via a malformed URL, a different vulnerability than CVE-...Show more |
1Symantec 5Altiris Client Management Suite Pcanywhere Solution Altiris Climentent Manage Suite Pcanywhere SolutionAltiris Deployment Solution Remote Pcanywhere Solution+2 moreApr 29, 2026 Mar 8, 2012 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The awhost32 service in Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), Altiris Client Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and...Show more |
Apple Safari 5.0.5 does not properly implement the setInterval function, which allows remote attackers to spoof the address bar via a crafted web page. |
Apache Struts 2 before 2.2.3.1 evaluates a string as an OGNL expression during the handling of a conversion error, which allows remote attackers to modify run-time data values, and consequently execute arbitrary code, vi...Show more |
VP8 Codec SDK (libvpx) before 1.0.0 "Duclair" allows remote attackers to cause a denial of service (application crash) via (1) unspecified "corrupt input" or (2) by "starting decoding from a P-frame," which triggers an o...Show more |
1Symantec 4Altiris Client Management Suite Pcanywhere Solution Altiris Deployment Solution Remote Pcanywhere SolutionAltiris It Management Suite Pcanywhere Solution+1 moreApr 29, 2026 Feb 22, 2012 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), Altiris Client Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), and Al...Show more |
The server in IBM solidDB 6.5 before FP9 and 7.0 before FP1 allows remote authenticated users to cause a denial of service (daemon crash) via a SELECT statement with a ROWNUM condition involving a subquery. |
Multiple open redirect vulnerabilities in CubeCart 3.0.20 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) r parameter to switch.php or (2) got...Show more |
1Secureideas 1Basic Analysis And Security Engine Apr 29, 2026 Feb 18, 2012 N/A· v4 N/A· v3 7.5 HIGH· v2 base_ag_main.php in Basic Analysis and Security Engine (BASE) 1.4.5 allows remote attackers to execute arbitrary code by uploading contents of the file with an executable extension via a create action, then accessing it...Show more |
The resolver in dnscache in Daniel J. Bernstein djbdns 1.05 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger c...Show more |
afd.sys in the Ancillary Function Driver in Microsoft Windows Server 2003 SP2 does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "...Show more |