← Back
CWE-20

12,724 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,724)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Nov 10, 2009
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The kernel in Apple Mac OS X before 10.6.2 does not properly handle task state segments, which allows local users to gain privileges, cause a denial of service (system crash), or obtain sensitive information via unspecif...Show more
The kernel in Apple Mac OS X before 10.6.2 does not properly handle task state segments, which allows local users to gain privileges, cause a denial of service (system crash), or obtain sensitive information via unspecified vectors.Show less
1Microsoft
1Sharepoint Server
Apr 23, 2026
Oct 30, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The download functionality in Team Services in Microsoft Office SharePoint Server 2007 12.0.0.4518 and 12.0.0.6219 allows remote attackers to read ASP.NET source code via pathnames in the SourceUrl and Source parameters...Show more
The download functionality in Team Services in Microsoft Office SharePoint Server 2007 12.0.0.4518 and 12.0.0.6219 allows remote attackers to read ASP.NET source code via pathnames in the SourceUrl and Source parameters to _layouts/download.aspx.Show less
1Wireshark
1Wireshark
Apr 23, 2026
Oct 30, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
packet-paltalk.c in the Paltalk dissector in Wireshark 1.2.0 through 1.2.2, on SPARC and certain other platforms, allows remote attackers to cause a denial of service (application crash) via a file that records a malform...Show more
packet-paltalk.c in the Paltalk dissector in Wireshark 1.2.0 through 1.2.2, on SPARC and certain other platforms, allows remote attackers to cause a denial of service (application crash) via a file that records a malformed packet trace.Show less
1Linux
1Linux Kernel
Apr 23, 2026
Oct 29, 2009
N/A· v4
N/A· v3
4.9 MEDIUM· v2
The update_cr8_intercept function in arch/x86/kvm/x86.c in the KVM subsystem in the Linux kernel before 2.6.32-rc1 does not properly handle the absence of an Advanced Programmable Interrupt Controller (APIC), which allow...Show more
The update_cr8_intercept function in arch/x86/kvm/x86.c in the KVM subsystem in the Linux kernel before 2.6.32-rc1 does not properly handle the absence of an Advanced Programmable Interrupt Controller (APIC), which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly gain privileges via a call to the kvm_vcpu_ioctl function.Show less
1Derrick Oswald
1Html Parser
Apr 23, 2026
Oct 29, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The decode_entities function in util.c in HTML-Parser before 3.63 allows context-dependent attackers to cause a denial of service (infinite loop) via an incomplete SGML numeric character reference, which triggers generat...Show more
The decode_entities function in util.c in HTML-Parser before 3.63 allows context-dependent attackers to cause a denial of service (infinite loop) via an incomplete SGML numeric character reference, which triggers generation of an invalid UTF-8 character.Show less
1Amirocms
1Amiro.cms
Apr 23, 2026
Oct 27, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Amiro.CMS 5.4.0.0 and earlier allows remote attackers to obtain sensitive information via an invalid loginname ("%%%") to _admin/index.php, which reveals the installation path and other information in an error message.
1Opial
1Opial
Apr 23, 2026
Oct 22, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Unrestricted file upload vulnerability in Opial 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension as a User Image, then accessing it via a request to the file in useri...Show more
Unrestricted file upload vulnerability in Opial 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension as a User Image, then accessing it via a request to the file in userimages, related to register.php.Show less
1Adobe
2Acrobat
Acrobat Reader
Apr 23, 2026
Oct 19, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 do not properly validate input, which might allow attackers to execute arbitrary code via unspecified vectors, a different vulnerability tha...Show more
Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 do not properly validate input, which might allow attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-2998.Show less
1Adobe
2Acrobat
Acrobat Reader
Apr 23, 2026
Oct 19, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 do not properly validate input, which might allow attackers to execute arbitrary code via unspecified vectors, a different vulnerability tha...Show more
Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 do not properly validate input, which might allow attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-3458.Show less
1Adobe
2Acrobat
Acrobat Reader
Apr 23, 2026
Oct 19, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
The JavaScript for Acrobat API in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 does not properly implement the (1) Privileged Context and (2) Safe Path restrictions for unspecified Java...Show more
The JavaScript for Acrobat API in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 does not properly implement the (1) Privileged Context and (2) Safe Path restrictions for unspecified JavaScript methods, which allows remote attackers to create arbitrary files, and possibly execute arbitrary code, via the cPath parameter in a crafted PDF file. NOTE: some of these details are obtained from third party information.Show less
1Adobe
2Acrobat
Acrobat Reader
Apr 23, 2026
Oct 19, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
An unspecified ActiveX control in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 does not properly validate input, which allows attackers to cause a denial of service via unknow...Show more
An unspecified ActiveX control in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 does not properly validate input, which allows attackers to cause a denial of service via unknown vectors.Show less
1Adobe
2Acrobat
Acrobat Reader
Apr 23, 2026
Oct 19, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 do not properly validate input, which allows attackers to cause a denial of service via unspecified vectors.
1Adobe
2Acrobat
Acrobat Reader
Apr 23, 2026
Oct 19, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 do not properly validate input, which might allow attackers to bypass intended Trust Manager restrictions via unspecified vectors.
1Microsoft
5Windows 2000
Windows Server 2003Windows Server 2008+2 more
Apr 23, 2026
Oct 14, 2009
N/A· v4
7.1 HIGH· v3
6.9 MEDIUM· v2
The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does not properly validate data sent from user mode, which allows local users to gain privileges via a c...Show more
The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does not properly validate data sent from user mode, which allows local users to gain privileges via a crafted PE .exe file that triggers a NULL pointer dereference during chain traversal, aka "Windows Kernel NULL Pointer Dereference Vulnerability."Show less
1Ben Webb
1Dopewars
Apr 23, 2026
Oct 8, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Dopewars 1.5.12 allows remote attackers to cause a denial of service (segmentation fault) via a REQUESTJET message with an invalid location.
1Datawizard
1Ftpxq Server
Apr 23, 2026
Oct 5, 2009
N/A· v4
N/A· v3
4.0 MEDIUM· v2
DataWizard Technologies FtpXQ FTP Server 3.0 allows remote authenticated users to cause a denial of service (crash) via a long ABOR command.
1Avas!t
2Avast Antivirus Home
Avast Antivirus Professional
Apr 23, 2026
Oct 1, 2009
N/A· v4
N/A· v3
6.9 MEDIUM· v2
aavmKer4.sys in avast! Home and Professional for Windows before 4.8.1356 does not properly validate input to IOCTLs (1) 0xb2d6000c and (2) 0xb2d60034, which allows local users to gain privileges via IOCTL requests using...Show more
aavmKer4.sys in avast! Home and Professional for Windows before 4.8.1356 does not properly validate input to IOCTLs (1) 0xb2d6000c and (2) 0xb2d60034, which allows local users to gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption, a different vulnerability than CVE-2008-1625.Show less
1Bakbone
1Netvault
Apr 23, 2026
Sep 29, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
npvmgr.exe in BakBone NetVault Backup 8.22 Build 29 allows remote attackers to cause a denial of service (daemon crash) via a packet to (1) TCP or (2) UDP port 20031 with a large value in an unspecified size field, which...Show more
npvmgr.exe in BakBone NetVault Backup 8.22 Build 29 allows remote attackers to cause a denial of service (daemon crash) via a packet to (1) TCP or (2) UDP port 20031 with a large value in an unspecified size field, which is not properly handled in a malloc operation. NOTE: some of these details are obtained from third party information.Show less
1Php
1Php
Apr 23, 2026
Sep 22, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
The php_openssl_apply_verification_policy function in PHP before 5.2.11 does not properly perform certificate validation, which has unknown impact and attack vectors, probably related to an ability to spoof certificates.
1Macournoyer
1Thin
Apr 23, 2026
Sep 22, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
lib/thin/connection.rb in Thin web server before 1.2.4 relies on the X-Forwarded-For header to determine the IP address of the client, which allows remote attackers to spoof the IP address and hide activities via a modif...Show more
lib/thin/connection.rb in Thin web server before 1.2.4 relies on the X-Forwarded-For header to determine the IP address of the client, which allows remote attackers to spoof the IP address and hide activities via a modified X-Forwarded-For header.Show less