CWE-20
12,724 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,724)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Winny 2.0b7.1 and earlier does not properly process BBS information, which has unspecified impact and remote attack vectors that might lead to use of the product's host for DDoS attacks. |
1Redhat 2Enterprise Virtualization KvmApr 29, 2026 Aug 24, 2010 N/A· v4 N/A· v3 6.6 MEDIUM· v2 QEMU-KVM, as used in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and KVM 83, does not properly validate guest QXL driver pointers, which allows guest OS users to cause a denial of...Show more |
1Redhat 2Enterprise Virtualization QspiceApr 29, 2026 Aug 24, 2010 N/A· v4 N/A· v3 6.6 MEDIUM· v2 libspice, as used in QEMU-KVM in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and qspice 0.3.0, does not properly validate guest QXL driver pointers, which allows guest OS users to...Show more |
The ienipp.ocx ActiveX control in the browser plugin in Novell iPrint Client before 5.42 does not properly validate the debug parameter, which allows remote attackers to execute arbitrary code or cause a denial of servic...Show more |
Cacti before 0.8.7f, as used in Red Hat High Performance Computing (HPC) Solution and other products, allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in (1) the FQDN fiel...Show more |
The ReadMetaFromId3v2 function in taglib.cpp in the TagLib plugin in VideoLAN VLC media player 0.9.0 through 1.1.2 does not properly process ID3v2 tags, which allows remote attackers to cause a denial of service (applica...Show more |
The standardise function in Anibal Monsalve Salazar sSMTP 2.61 and 2.62 allows local users to cause a denial of service (application exit) via an e-mail message containing a long line that begins with a . (dot) character...Show more |
bdf/bdflib.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service (application crash) via a crafted BDF font file, related to an attempted modification of a value in a static string. |
3Apple CanonicalFreetype5Freetype Iphone OsMac Os X+2 moreApr 29, 2026 Aug 19, 2010 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The FT_Stream_EnterFrame function in base/ftstream.c in FreeType before 2.4.2 does not properly validate certain position values, which allows remote attackers to cause a denial of service (application crash) or possibly...Show more |
Client.cpp in ZNC 0.092 allows remote attackers to cause a denial of service (exception and daemon crash) via a PING command that lacks an argument. |
Cisco IOS 15.1(2)T allows remote attackers to cause a denial of service (resource consumption and TCP outage) via spoofed TCP packets, related to embryonic TCP connections that remain in the SYN_RCVD or SYN_SENT state, a...Show more |
The IPMI dissector in Wireshark 1.2.0 through 1.2.9 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors. |
1Microsoft 3Windows 2003 Server Windows Server 2003Windows XpApr 29, 2026 Aug 11, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 The Secure Channel (aka SChannel) security package in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, does not properly validate certificate request messages from TLS and SSL servers, which allows remote s...Show more |
1Microsoft 3Windows 7 Windows Server 2008Windows VistaApr 29, 2026 Aug 11, 2010 N/A· v4 N/A· v3 7.8 HIGH· v2 The SMB Server in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate an internal variable in an SMB packet, which allows remote attackers to cause a denia...Show more |
1Microsoft 6Windows 2003 Server Windows 7Windows Server 2003+3 moreApr 29, 2026 Aug 11, 2010 N/A· v4 N/A· v3 10.0 HIGH· v2 The SMB Server in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate fields in an SMB request, which allo...Show more |
1Microsoft 6Windows 2003 Server Windows 7Windows Server 2003+3 moreApr 29, 2026 Aug 11, 2010 N/A· v4 N/A· v3 7.2 HIGH· v2 The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly validate pseudo-...Show more |
1Microsoft 5Windows 2003 Server Windows Server 2003Windows Server 2008+2 moreApr 29, 2026 Aug 11, 2010 N/A· v4 8.4 HIGH· v3 7.2 HIGH· v2 The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2 do not properly validate user-mode input passed...Show more |
1Microsoft 3Windows 7 Windows Server 2008Windows VistaApr 29, 2026 Aug 11, 2010 N/A· v4 N/A· v3 4.6 MEDIUM· v2 The kernel in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate ACLs on kernel objects, which allows local users to cause a denial of service (reboot) vi...Show more |
1Microsoft 6Windows 2003 Server Windows 7Windows Server 2003+3 moreApr 29, 2026 Aug 11, 2010 N/A· v4 N/A· v3 4.4 MEDIUM· v2 The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly validate an unsp...Show more |
1Redhat 2Jboss Enterprise Service Bus Jboss Enterprise Soa PlatformApr 29, 2026 Aug 10, 2010 N/A· v4 N/A· v3 3.5 LOW· v2 JBoss Enterprise Service Bus (ESB) before 4.7 CP02 in JBoss Enterprise SOA Platform before 5.0.2 does not properly consider the security domain with which a service is secured, which might allow remote attackers to gain...Show more |