← Back
CWE-20

12,724 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,724)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Nov 16, 2010
N/A· v4
N/A· v3
7.8 HIGH· v2
Networking in Apple Mac OS X 10.6.2 through 10.6.4 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted PIM packet.
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Nov 15, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Disk Images in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted UDIF image.
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Nov 15, 2010
N/A· v4
N/A· v3
5.8 MEDIUM· v2
CFNetwork in Apple Mac OS X 10.6.x before 10.6.5 does not properly validate the domains of cookies, which makes it easier for remote web servers to track users by setting a cookie that is associated with a partial IP add...Show more
CFNetwork in Apple Mac OS X 10.6.x before 10.6.5 does not properly validate the domains of cookies, which makes it easier for remote web servers to track users by setting a cookie that is associated with a partial IP address.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Nov 15, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
AFP Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon restart) via crafted reconnect authentication packets.
1Landesk
1Management Gateway
Apr 29, 2026
Nov 15, 2010
N/A· v4
N/A· v3
8.5 HIGH· v2
gsb/drivers.php in LANDesk Management Gateway 4.0 through 4.0-1.48 and 4.2 through 4.2-1.8 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the DRIVES parameter, as dem...Show more
gsb/drivers.php in LANDesk Management Gateway 4.0 through 4.0-1.48 and 4.2 through 4.2-1.8 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the DRIVES parameter, as demonstrated by a cross-site request forgery (CSRF) attack.Show less
2Canonical
Php
2Php
Ubuntu Linux
Apr 29, 2026
Nov 12, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The utf8_decode function in PHP before 5.3.4 does not properly handle non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data, which makes it easier for remote attackers to bypass cross-site scripting...Show more
The utf8_decode function in PHP before 5.3.4 does not properly handle non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data, which makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string.Show less
1Scottmac
1Libmbfl
Apr 29, 2026
Nov 10, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The mb_strcut function in Libmbfl 1.1.0, as used in PHP 5.3.x through 5.3.3, allows context-dependent attackers to obtain potentially sensitive information via a large value of the third parameter (aka the length paramet...Show more
The mb_strcut function in Libmbfl 1.1.0, as used in PHP 5.3.x through 5.3.3, allows context-dependent attackers to obtain potentially sensitive information via a large value of the third parameter (aka the length parameter).Show less
1Microsoft
1Forefront Unified Access Gateway
Apr 29, 2026
Nov 10, 2010
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Open redirect vulnerability in the web interface in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to redirect users to arbitrary web sites and conduc...Show more
Open redirect vulnerability in the web interface in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka "UAG Redirection Spoofing Vulnerability."Show less
1Ibm
1Websphere Application Server
Apr 29, 2026
Nov 9, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Web Services Security component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.13 does not properly implement the Java API for XML Web Services (aka JAX-WS), which allows remote attackers to cause a denia...Show more
The Web Services Security component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.13 does not properly implement the Java API for XML Web Services (aka JAX-WS), which allows remote attackers to cause a denial of service (data corruption) via a crafted JAX-WS request that leads to incorrectly encoded data.Show less
2Canonical
Php
2Php
Ubuntu Linux
Apr 29, 2026
Nov 9, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The ZipArchive::getArchiveComment function in PHP 5.2.x through 5.2.14 and 5.3.x through 5.3.3 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafte...Show more
The ZipArchive::getArchiveComment function in PHP 5.2.x through 5.2.14 and 5.3.x through 5.3.3 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ZIP archive.Show less
2Debian
Google
2Chrome
Debian Linux
Apr 29, 2026
Nov 6, 2010
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Google Chrome before 7.0.517.44 does not properly perform a cast of an unspecified variable during processing of an SVG use element, which allows remote attackers to cause a denial of service or possibly have unspecified...Show more
Google Chrome before 7.0.517.44 does not properly perform a cast of an unspecified variable during processing of an SVG use element, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted SVG document.Show less
3Fedoraproject
GoogleWebkitgtk
3Chrome
FedoraWebkitgtk
Apr 29, 2026
Nov 6, 2010
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, does not properly handle large text areas, which allows remote attackers to cause a denial of service (memory corruption) or...Show more
WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, does not properly handle large text areas, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted HTML document.Show less
4Foolabs
GlyphandcogKde+1 more
4Kdegraphics
PopplerXpdf+1 more
Apr 29, 2026
Nov 5, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, kdegraphics, and possibly other products allows context-dependent attac...Show more
The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a PDF file with a crafted PostScript Type1 font that contains a negative array index, which bypasses input validation and triggers memory corruption.Show less
1Poppler
1Poppler
Apr 29, 2026
Nov 5, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The PostScriptFunction::PostScriptFunction function in poppler/Function.cc in the PDF parser in poppler 0.8.7 and possibly other versions up to 0.15.1, and possibly other products, allows context-dependent attackers to c...Show more
The PostScriptFunction::PostScriptFunction function in poppler/Function.cc in the PDF parser in poppler 0.8.7 and possibly other versions up to 0.15.1, and possibly other products, allows context-dependent attackers to cause a denial of service (crash) via a PDF file that triggers an uninitialized pointer dereference.Show less
1Rubyonrails
1Rails
Apr 29, 2026
Oct 28, 2010
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Ruby on Rails 2.3.9 and 3.0.0 does not properly handle nested attributes, which allows remote attackers to modify arbitrary records by changing the names of parameters for form inputs.
1Pidgin
1Pidgin
Apr 29, 2026
Oct 28, 2010
N/A· v4
N/A· v3
4.0 MEDIUM· v2
libpurple in Pidgin before 2.7.4 does not properly validate the return value of the purple_base64_decode function, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and applic...Show more
libpurple in Pidgin before 2.7.4 does not properly validate the return value of the purple_base64_decode function, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a crafted message, related to the plugins for MSN, MySpaceIM, XMPP, and Yahoo! and the NTLM authentication support.Show less
1Nitrosecurity
1Nitroview Esm Software
Apr 29, 2026
Oct 27, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
ess.pm in NitroSecurity NitroView ESM 8.4.0a, when ESSPMDebug is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in the Request parameter to ess.
1Tibco
4Activematrix Businessworks Service Engine
Activematrix Service BusActivematrix Service Grid+1 more
Apr 29, 2026
Oct 26, 2010
N/A· v4
N/A· v3
10.0 HIGH· v2
The (1) ActiveMatrix Runtime and (2) ActiveMatrix Administrator components in TIBCO ActiveMatrix Service Grid before 2.3.1, ActiveMatrix Service Bus before 2.3.1, ActiveMatrix BusinessWorks Service Engine before 5.8.1, a...Show more
The (1) ActiveMatrix Runtime and (2) ActiveMatrix Administrator components in TIBCO ActiveMatrix Service Grid before 2.3.1, ActiveMatrix Service Bus before 2.3.1, ActiveMatrix BusinessWorks Service Engine before 5.8.1, and ActiveMatrix Service Performance Manager before 1.3.2 do not properly handle JMX connections, which allows remote attackers to execute arbitrary code, obtain sensitive information, or cause a denial of service via unspecified vectors.Show less
1Typo3
1Typo3
Apr 29, 2026
Oct 25, 2010
N/A· v4
N/A· v3
4.9 MEDIUM· v2
Unspecified vulnerability in the Extension Manager in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 allows remote authenticated administrators to read and possibly modify arbitrary files via a cra...Show more
Unspecified vulnerability in the Extension Manager in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 allows remote authenticated administrators to read and possibly modify arbitrary files via a crafted parameter, a different vulnerability than CVE-2010-3714.Show less
1Typo3
1Typo3
Apr 29, 2026
Oct 25, 2010
N/A· v4
N/A· v3
6.0 MEDIUM· v2
The be_user_creation task in TYPO3 4.2.x before 4.2.15 and 4.3.x before 4.3.7 allows remote authenticated users to gain privileges via a crafted POST request that creates a user account with arbitrary group memberships.