CWE-20
12,724 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,724)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Multiple open redirect vulnerabilities in Pligg 1.0.2 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the (1) return parameter to pligg/login.php and the (2) H...Show more |
The PayPal Website Payments Standard functionality in the Ubercart module 5.x before 5.x-1.9 and 6.x before 6.x-2.1 for Drupal does not properly validate orders, which allows remote attackers to trigger unspecified "dupl...Show more |
The command matching functionality in sudo 1.6.8 through 1.7.2p5 does not properly handle when a file in the current working directory has the same name as a pseudo-command in the sudoers file and the PATH contains an en...Show more |
Irssi before 0.8.15, when SSL is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) field or a Subject Alternative Name field of the X.509 certificate, which allows man...Show more |
The Web Install ActiveX control (CSDWebInstaller) in Cisco Secure Desktop (CSD) before 3.5.841 does not properly verify the signatures of downloaded programs, which allows remote attackers to force the download and execu...Show more |
1Microsoft 7Windows 2000 Windows 2003 ServerWindows 7+4 moreApr 29, 2026 Apr 14, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 The Authenticode Signature verification functionality in cabview.dll in Cabinet File Viewer Shell Extension 5.1, 6.0, and 6.1 in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista...Show more |
1Microsoft 7Windows 2000 Windows 2003 ServerWindows 7+4 moreApr 29, 2026 Apr 14, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 The WinVerifyTrust function in Authenticode Signature Verification 5.1, 6.0, and 6.1 in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 G...Show more |
1Microsoft 2Windows 7 Windows Server 2008Apr 29, 2026 Apr 14, 2010 N/A· v4 N/A· v3 4.7 MEDIUM· v2 The kernel in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate relocation sections of image files, which allows local users to cause a denial of service (reboot) via a crafted file, aka "Windows...Show more |
1Microsoft 2Windows 7 Windows Server 2008Apr 29, 2026 Apr 14, 2010 N/A· v4 N/A· v3 10.0 HIGH· v2 The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate fields in SMB transaction responses, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code o...Show more |
1Microsoft 5Windows 2000 Windows 2003 ServerWindows Server 2003+2 moreApr 29, 2026 Apr 14, 2010 N/A· v4 N/A· v3 4.9 MEDIUM· v2 Unspecified vulnerability in registry-key validation in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold allows local users to cause a denial of service (reboot) via a crafted app...Show more |
1Microsoft 5Windows 2000 Windows 2003 ServerWindows Server 2003+2 moreApr 29, 2026 Apr 14, 2010 N/A· v4 N/A· v3 4.7 MEDIUM· v2 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold does not perform the expected validation before creating a symbolic link, which allows local users to cause a denial of service (r...Show more |
1Microsoft 6Windows 2000 Windows 2003 ServerWindows Server 2003+3 moreApr 29, 2026 Apr 14, 2010 N/A· v4 N/A· v3 4.7 MEDIUM· v2 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not properly validate a registry-key argument to an unspecified system call, which al...Show more |
1Microsoft 6Exchange Server Windows 2000Windows 2003 Server+3 moreApr 29, 2026 Apr 14, 2010 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2003 SP2, does not properly parse MX records, which allows remote DNS servers to c...Show more |
memcached.c in memcached before 1.4.3 allows remote attackers to cause a denial of service (daemon hang or crash) via a long line that triggers excessive memory allocation. NOTE: some of these details are obtained from...Show more |
The virtio_net_bad_features function in hw/virtio-net.c in the virtio-net driver in the Linux kernel before 2.6.26, when used on a guest OS in conjunction with qemu-kvm 0.11.0 or KVM 83, allows remote attackers to cause...Show more |
The qtm_decompress function in libclamav/mspack.c in ClamAV before 0.96 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted CAB archive that uses the Quantum (aka...Show more |
Emweb Wt before 3.1.1 does not validate the UTF-8 encoding of (1) form values and (2) JSignal arguments, which has unspecified impact and remote attack vectors. |
1Mozilla 3Firefox SeamonkeyThunderbirdApr 29, 2026 Apr 5, 2010 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The XMLDocument::load function in Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 does not perform the expected nsIContentPolicy checks during loading of content...Show more |
Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, executes a mail application in situations where an IMG element has a SRC attribute that is a redirect to a mailto: URL, which allows remote...Show more |
NWFTPD.nlm before 5.03b in the FTP server in Novell NetWare allows remote authenticated users to cause a denial of service (abend) via a crafted ABOR command. |