CWE-20
12,734 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,734)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Opera before 11.11 does not properly implement FRAMESET elements, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to page unload. |
1Hp 2Openview Performance Agent Operations AgentApr 29, 2026 Jul 1, 2011 N/A· v4 N/A· v3 6.4 MEDIUM· v2 ovbbccb.exe 6.20.50.0 and other versions in HP OpenView Performance Agent 4.70 and 5.0; and Operations Agent 11.0, 8.60.005, 8.60.006, 8.60.007, 8.60.008, 8.60.501, and 8.53; allows remote attackers to delete arbitrary f...Show more |
Mozilla Gecko before 5.0, as used in Firefox before 5.0 and Thunderbird before 5.0, does not block use of a cross-domain image as a WebGL texture, which allows remote attackers to obtain approximate copies of arbitrary i...Show more |
2D Bus Project Freedesktop2D Bus DbusApr 29, 2026 Jun 22, 2011 N/A· v4 N/A· v3 4.6 MEDIUM· v2 The _dbus_header_byteswap function in dbus-marshal-header.c in D-Bus (aka DBus) 1.2.x before 1.2.28, 1.4.x before 1.4.12, and 1.5.x before 1.5.4 does not properly handle a non-native byte order, which allows local users...Show more |
Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly validate the start parameter, which might allow remote attackers to conduct SQL injection attacks, obtain sensitive information, or cau...Show more |
The FLV ASSET Xtra component in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code via unspecified vectors, related to an "input validation vulnerability." |
1Adobe 3Blazeds LivecycleLivecycle Data ServicesApr 29, 2026 Jun 16, 2011 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Adobe LiveCycle Data Services 3.1 and earlier, LiveCycle 9.0.0.2 and earlier, and BlazeDS 4.0.1 and earlier do not properly handle object graphs, which allows attackers to cause a denial of service via unspecified vector...Show more |
1Adobe 3Blazeds LivecycleLivecycle Data ServicesApr 29, 2026 Jun 16, 2011 N/A· v4 N/A· v3 10.0 HIGH· v2 Adobe LiveCycle Data Services 3.1 and earlier, LiveCycle 9.0.0.2 and earlier, and BlazeDS 4.0.1 and earlier do not properly restrict creation of classes during deserialization of (1) AMF and (2) AMFX data, which allows a...Show more |
1Microsoft 5Windows 7 Windows Server 2003Windows Server 2008+2 moreApr 29, 2026 Jun 16, 2011 N/A· v4 N/A· v3 9.3 HIGH· v2 win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 on 64-bit platforms does no...Show more |
1Microsoft 5Excel Excel ViewerOffice+2 moreApr 29, 2026 Jun 16, 2011 N/A· v4 N/A· v3 9.3 HIGH· v2 Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP...Show more |
1Microsoft 6Windows 2003 Server Windows 7Windows Server 2003+3 moreApr 29, 2026 Jun 16, 2011 N/A· v4 N/A· v3 10.0 HIGH· v2 The SMB client in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote SMB servers to execute arbit...Show more |
Microsoft .NET Framework 2.0 SP1 and SP2, 3.5 Gold and SP1, 3.5.1, and 4.0, and Silverlight 4 before 4.0.60531.0, does not properly validate arguments to unspecified networking API functions, which allows remote attacker...Show more |
Google V8, as used in Google Chrome before 12.0.742.91, allows remote attackers to bypass the Same Origin Policy via unspecified vectors. |
Google Chrome before 12.0.742.91 does not properly implement the framework for extensions, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lea...Show more |
Google Chrome before 12.0.742.91 does not properly handle a large number of form submissions, which allows remote attackers to cause a denial of service (application crash) via unspecified vectors. |
The X.509 certificate validation functionality in Mozilla Firefox 4.0.x through 4.0.1 does not properly implement single-session security exceptions, which might make it easier for user-assisted remote attackers to spoof...Show more |
Microsoft Internet Explorer 9 and earlier does not properly restrict cross-zone drag-and-drop actions, which allows user-assisted remote attackers to read cookie files via vectors involving an IFRAME element with a SRC a...Show more |
Microsoft Internet Explorer 8 and earlier, and Internet Explorer 9 beta, does not properly restrict cross-zone drag-and-drop actions, which allows user-assisted remote attackers to read cookie files via vectors involving...Show more |
1Cisco 1Anyconnect Secure Mobility Client Apr 29, 2026 Jun 2, 2011 N/A· v4 N/A· v3 9.3 HIGH· v2 The helper application in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.5.3041, and 3.0.x before 3.0.629, on Linux and Mac OS X downloads a client executable file (vpndownloader.exe) w...Show more |
1Cisco 1Anyconnect Secure Mobility Client Apr 29, 2026 Jun 2, 2011 N/A· v4 N/A· v3 7.6 HIGH· v2 The helper application in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.3.185 on Windows, and on Windows Mobile, downloads a client executable file (vpndownloader.exe) without verifyin...Show more |