← Back
CWE-20

12,734 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,734)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
1Host Integration Server
Apr 29, 2026
Oct 12, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service outage) via crafted TCP or UDP traffic, aka "Access of Unallocated Memor...Show more
Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service outage) via crafted TCP or UDP traffic, aka "Access of Unallocated Memory DoS Vulnerability."Show less
1Microsoft
1Host Integration Server
Apr 29, 2026
Oct 12, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service outage) via crafted TCP or UDP traffic, aka "Endless Loop DoS in snabase...Show more
Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service outage) via crafted TCP or UDP traffic, aka "Endless Loop DoS in snabase.exe Vulnerability."Show less
1Microsoft
3Windows 7
Windows Server 2008Windows Vista
Apr 29, 2026
Oct 12, 2011
N/A· v4
N/A· v3
4.7 MEDIUM· v2
win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle TrueType fonts, which allows local users to cause a denia...Show more
win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle TrueType fonts, which allows local users to cause a denial of service (system hang) via a crafted font file, aka "Win32k TrueType Font Type Translation Vulnerability."Show less
1Microsoft
1Internet Explorer
Apr 29, 2026
Oct 12, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
Microsoft Internet Explorer 6 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "OnLoad Event Remote Code Execution Vulnerability."
1Webmanager Pro
1Cms Webmanager Pro
Apr 29, 2026
Oct 8, 2011
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Open redirect vulnerability in c.php in CMS WebManager-Pro 8.1 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.
1Apache
1Http Server
Apr 29, 2026
Oct 5, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for config...Show more
The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an initial @ (at sign) character.Show less
1Tedfelix
1Acpid
Apr 29, 2026
Oct 5, 2011
N/A· v4
N/A· v3
2.1 LOW· v2
acpid.c in acpid before 2.0.9 does not properly handle a situation in which a process has connected to acpid.socket but is not reading any data, which allows local users to cause a denial of service (daemon hang) via a c...Show more
acpid.c in acpid before 2.0.9 does not properly handle a situation in which a process has connected to acpid.socket but is not reading any data, which allows local users to cause a denial of service (daemon hang) via a crafted application that performs a connect system call but no read system calls.Show less
1Mozilla
2Firefox
Seamonkey
Apr 29, 2026
Sep 29, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The JSSubScriptLoader in Mozilla Firefox 4.x through 6 and SeaMonkey before 2.4 does not properly handle XPCNativeWrappers during calls to the loadSubScript method in an add-on, which makes it easier for remote attackers...Show more
The JSSubScriptLoader in Mozilla Firefox 4.x through 6 and SeaMonkey before 2.4 does not properly handle XPCNativeWrappers during calls to the loadSubScript method in an add-on, which makes it easier for remote attackers to gain privileges via a crafted web site that leverages certain unwrapping behavior.Show less
1Adobe
1Flash Player
Apr 29, 2026
Sep 22, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
Adobe Flash Player before 10.3.183.10 on Windows, Mac OS X, Linux, and Solaris, and before 10.3.186.7 on Android, allows remote attackers to execute arbitrary code via crafted streaming media, related to a "logic error v...Show more
Adobe Flash Player before 10.3.183.10 on Windows, Mac OS X, Linux, and Solaris, and before 10.3.186.7 on Android, allows remote attackers to execute arbitrary code via crafted streaming media, related to a "logic error vulnerability."Show less
1Adobe
1Flash Player
Apr 29, 2026
Sep 22, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
Adobe Flash Player before 10.3.183.10 on Windows, Mac OS X, Linux, and Solaris, and before 10.3.186.7 on Android, allows attackers to execute arbitrary code or cause a denial of service (browser crash) via unspecified ve...Show more
Adobe Flash Player before 10.3.183.10 on Windows, Mac OS X, Linux, and Solaris, and before 10.3.186.7 on Android, allows attackers to execute arbitrary code or cause a denial of service (browser crash) via unspecified vectors, related to a "logic error issue."Show less
1Wireshark
1Wireshark
Apr 29, 2026
Sep 20, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The unxorFrame function in epan/dissectors/packet-opensafety.c in the OpenSafety dissector in Wireshark 1.6.x before 1.6.2 does not properly validate a certain frame size, which allows remote attackers to cause a denial...Show more
The unxorFrame function in epan/dissectors/packet-opensafety.c in the OpenSafety dissector in Wireshark 1.6.x before 1.6.2 does not properly validate a certain frame size, which allows remote attackers to cause a denial of service (loop and application crash) via a malformed packet.Show less
1Google
1Chrome
Apr 29, 2026
Sep 19, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Google Chrome before 14.0.835.163 does not properly handle strings in PDF documents, which allows remote attackers to have an unspecified impact via a crafted document that triggers an incorrect read operation.
1Google
1Chrome
Apr 29, 2026
Sep 19, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Google Chrome before 14.0.835.163 allows user-assisted remote attackers to spoof the URL bar via vectors related to the forward button.
1Google
1Chrome
Apr 29, 2026
Sep 19, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
The installer in Google Chrome before 14.0.835.163 on Mac OS X does not properly handle lock files, which has unspecified impact and attack vectors.
1Google
1Chrome
Apr 29, 2026
Sep 19, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Google Chrome before 14.0.835.163 does not properly perform garbage collection during the processing of PDF documents, which allows remote attackers to cause a denial of service or possibly have unspecified other impact...Show more
Google Chrome before 14.0.835.163 does not properly perform garbage collection during the processing of PDF documents, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.Show less
1Google
1Chrome
Apr 29, 2026
Sep 19, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Google Chrome before 14.0.835.163 allows user-assisted remote attackers to spoof the URL bar via vectors related to "unusual user interaction."
1Google
1Chrome
Apr 29, 2026
Sep 19, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Google Chrome before 14.0.835.163 does not properly consider the MIME type during the loading of a plug-in, which has unspecified impact and remote attack vectors.
1Measuresoft
1Scadapro
Apr 29, 2026
Sep 16, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) BF, (2) OF, or (3) EF command.
1Bcfg2
1Bcfg2
Apr 29, 2026
Sep 16, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
The server in Bcfg2 1.1.2 and earlier, and 1.2 prerelease, allows remote attackers to execute arbitrary commands via shell metacharacters in data received from a client.
1Adobe
2Acrobat
Acrobat Reader
Apr 29, 2026
Sep 15, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
Adobe Reader and Acrobat 8.x before 8.3.1, 9.x before 9.4.6, and 10.x before 10.1.1 allow attackers to execute arbitrary code via unspecified vectors, related to a "logic error vulnerability."