← Back
CWE-20

12,734 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,734)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Chrome
Apr 29, 2026
Aug 3, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Google Chrome before 13.0.782.107 does not ensure that extension installations are confirmed by a browser dialog, which makes it easier for remote attackers to modify the product's functionality via a Trojan horse extens...Show more
Google Chrome before 13.0.782.107 does not ensure that extension installations are confirmed by a browser dialog, which makes it easier for remote attackers to modify the product's functionality via a Trojan horse extension.Show less
1Phpmyadmin
1Phpmyadmin
Apr 29, 2026
Aug 1, 2011
N/A· v4
N/A· v3
6.4 MEDIUM· v2
libraries/auth/swekey/swekey.auth.lib.php in phpMyAdmin 3.x before 3.3.10.3 and 3.4.x before 3.4.3.2 does not properly manage sessions associated with Swekey authentication, which allows remote attackers to modify the SE...Show more
libraries/auth/swekey/swekey.auth.lib.php in phpMyAdmin 3.x before 3.3.10.3 and 3.4.x before 3.4.3.2 does not properly manage sessions associated with Swekey authentication, which allows remote attackers to modify the SESSION superglobal array, other superglobal arrays, and certain swekey.auth.lib.php local variables via a crafted query string, a related issue to CVE-2011-2505.Show less
1Hp
1Linux Imaging And Printing Project
Apr 29, 2026
Jul 29, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
foomatic-rip-hplip in HP Linux Imaging and Printing (HPLIP) 3.11.5 allows remote attackers to execute arbitrary code via a crafted *FoomaticRIPCommandLine field in a .ppd file.
1Joomla
1Joomla
Apr 29, 2026
Jul 27, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Joomla! 1.6.x before 1.6.2 does not prevent page rendering inside a frame in a third-party HTML document, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.
1Nrl
1Opie
Apr 29, 2026
Jul 27, 2011
N/A· v4
N/A· v3
7.2 HIGH· v2
opielogin.c in opielogin in OPIE 2.4.1-test1 and earlier does not check the return value of the setuid system call, which allows local users to gain privileges by arranging for an account to already be running its maximu...Show more
opielogin.c in opielogin in OPIE 2.4.1-test1 and earlier does not check the return value of the setuid system call, which allows local users to gain privileges by arranging for an account to already be running its maximum number of processes.Show less
2Canonical
Debian
2Advanced Package Tool
Ubuntu Linux
Apr 29, 2026
Jul 27, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
APT before 0.8.15.2 does not properly validate inline GPG signatures, which allows man-in-the-middle attackers to install modified packages via vectors involving lack of an initial clearsigned message.
1Citrix
1Access Gateway
Apr 29, 2026
Jul 21, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
The NSEPA.NsepaCtrl.1 ActiveX control in nsepa.ocx in Citrix Access Gateway Enterprise Edition 8.1 before 8.1-67.7, 9.0 before 9.0-70.5, and 9.1 before 9.1-96.4 attempts to validate signed DLLs by checking the certificat...Show more
The NSEPA.NsepaCtrl.1 ActiveX control in nsepa.ocx in Citrix Access Gateway Enterprise Edition 8.1 before 8.1-67.7, 9.0 before 9.0-70.5, and 9.1 before 9.1-96.4 attempts to validate signed DLLs by checking the certificate subject, not the signature, which allows man-in-the-middle attackers to execute arbitrary code via HTTP header data referencing a DLL that was signed with a crafted certificate.Show less
1Apple
2Safari
Webkit
Apr 29, 2026
Jul 21, 2011
N/A· v4
N/A· v3
8.8 HIGH· v2
WebKit in Apple Safari before 5.0.6 has improper libxslt security settings, which allows remote attackers to create arbitrary files, and consequently execute arbitrary code, via a crafted web site. NOTE: this may overla...Show more
WebKit in Apple Safari before 5.0.6 has improper libxslt security settings, which allows remote attackers to create arbitrary files, and consequently execute arbitrary code, via a crafted web site. NOTE: this may overlap CVE-2011-1425.Show less
1Apple
2Imageio
Safari
Apr 29, 2026
Jul 21, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
ImageIO in Apple Safari before 5.0.6 on Windows does not properly address re-entrancy issues, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF fi...Show more
ImageIO in Apple Safari before 5.0.6 on Windows does not properly address re-entrancy issues, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF file.Show less
1Ibm
1Websphere Application Server
Apr 29, 2026
Jul 19, 2011
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Open redirect vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.39 and 7.0 before 7.0.0.19 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the logo...Show more
Open redirect vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.39 and 7.0 before 7.0.0.19 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the logoutExitPage parameter.Show less
1Linux
1Linux Kernel
Apr 29, 2026
Jul 18, 2011
N/A· v4
N/A· v3
2.1 LOW· v2
The do_task_stat function in fs/proc/array.c in the Linux kernel before 2.6.39-rc1 does not perform an expected uid check, which makes it easier for local users to defeat the ASLR protection mechanism by reading the star...Show more
The do_task_stat function in fs/proc/array.c in the Linux kernel before 2.6.39-rc1 does not perform an expected uid check, which makes it easier for local users to defeat the ASLR protection mechanism by reading the start_code and end_code fields in the /proc/#####/stat file for a process executing a PIE binary.Show less
1Apache
1Tomcat
Apr 29, 2026
Jul 14, 2011
N/A· v4
N/A· v3
4.4 MEDIUM· v2
Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.19, when sendfile is enabled for the HTTP APR or HTTP NIO connector, does not validate certain request attributes, which allows local users to bypa...Show more
Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.19, when sendfile is enabled for the HTTP APR or HTTP NIO connector, does not validate certain request attributes, which allows local users to bypass intended file access restrictions or cause a denial of service (infinite loop or JVM crash) by leveraging an untrusted web application.Show less
1Squirrelmail
1Squirrelmail
Apr 29, 2026
Jul 14, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
functions/page_header.php in SquirrelMail 1.4.21 and earlier does not prevent page rendering inside a frame in a third-party HTML document, which makes it easier for remote attackers to conduct clickjacking attacks via a...Show more
functions/page_header.php in SquirrelMail 1.4.21 and earlier does not prevent page rendering inside a frame in a third-party HTML document, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.Show less
1Google
1Android Sdk
Apr 29, 2026
Jul 8, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
dexdump in Android SDK before 2.3 does not properly perform structural verification, which allows user-assisted remote attackers to cause a denial of service (dexdump crash) and possibly execute arbitrary code via a malf...Show more
dexdump in Android SDK before 2.3 does not properly perform structural verification, which allows user-assisted remote attackers to cause a denial of service (dexdump crash) and possibly execute arbitrary code via a malformed APK or dex file that calls a method using more arguments than the number of register that have been declared for that method.Show less
1Ibm
1Rational Doors Web Access
Apr 29, 2026
Jul 7, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
IBM Rational DOORS Web Access 1.4.x before 1.4.0.4 does not properly handle exceptions, which has unspecified impact and remote attack vectors.
1Digium
1Asterisk
Apr 29, 2026
Jul 6, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
chan_iax2.c in the IAX2 channel driver in Asterisk Open Source 1.4.x before 1.4.41.1, 1.6.2.x before 1.6.2.18.1, and 1.8.x before 1.8.4.3, and Asterisk Business Edition C.3 before C.3.7.3, accesses a memory address conta...Show more
chan_iax2.c in the IAX2 channel driver in Asterisk Open Source 1.4.x before 1.4.41.1, 1.6.2.x before 1.6.2.18.1, and 1.8.x before 1.8.4.3, and Asterisk Business Edition C.3 before C.3.7.3, accesses a memory address contained in an option control frame, which allows remote attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a crafted frame.Show less
1Opera
1Opera Browser
Apr 29, 2026
Jul 1, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Opera before 11.10 allows remote attackers to hijack (1) searches and (2) customizations via unspecified third party applications.
1Opera
1Opera Browser
Apr 29, 2026
Jul 1, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Opera before 11.11 does not properly handle destruction of a Silverlight instance, which allows remote attackers to cause a denial of service (application crash) via a web page, as demonstrated by vod.onet.pl.
1Opera
1Opera Browser
Apr 29, 2026
Jul 1, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Cascading Style Sheets (CSS) implementation in Opera before 11.11 does not properly handle the column-count property, which allows remote attackers to cause a denial of service (infinite repaint loop and application...Show more
The Cascading Style Sheets (CSS) implementation in Opera before 11.11 does not properly handle the column-count property, which allows remote attackers to cause a denial of service (infinite repaint loop and application hang) via a web page, as demonstrated by an unspecified Wikipedia page.Show less
1Opera
1Opera Browser
Apr 29, 2026
Jul 1, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Opera before 11.11 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted web page that is not properly handled during a reload occurring after the opening of a popup of the...Show more
Opera before 11.11 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted web page that is not properly handled during a reload occurring after the opening of a popup of the Easy Sticky Note extension.Show less