← Back
CWE-20

12,724 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,724)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zeeways
1Zeejobsite
Apr 23, 2026
Aug 7, 2009
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Unrestricted file upload vulnerability in editresume_next.php in Zeeways ZEEJOBSITE 2.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a photo in a profile...Show more
Unrestricted file upload vulnerability in editresume_next.php in Zeeways ZEEJOBSITE 2.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a photo in a profile edit action, then accessing the file via a direct request to jobseekers/logos/.Show less
2Debian
Php
2Debian Linux
Php
Apr 23, 2026
Aug 5, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The exif_read_data function in the Exif module in PHP before 5.2.10 allows remote attackers to cause a denial of service (crash) via a malformed JPEG image with invalid offset fields, a different issue than CVE-2005-3353...Show more
The exif_read_data function in the Exif module in PHP before 5.2.10 allows remote attackers to cause a denial of service (crash) via a malformed JPEG image with invalid offset fields, a different issue than CVE-2005-3353.Show less
1Mozilla
1Firefox
Apr 23, 2026
Aug 4, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Mozilla Firefox before 3.0.12, and 3.5.x before 3.5.2, allows remote SOCKS5 proxy servers to cause a denial of service (data stream corruption) via a long domain name in a reply.
1Microsoft
1Internet Explorer
Apr 23, 2026
Aug 3, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
mshtml.dll in Microsoft Internet Explorer 7 and 8 on Windows XP SP3 allows remote attackers to cause a denial of service (application crash) by calling the JavaScript findText method with a crafted Unicode string in the...Show more
mshtml.dll in Microsoft Internet Explorer 7 and 8 on Windows XP SP3 allows remote attackers to cause a denial of service (application crash) by calling the JavaScript findText method with a crafted Unicode string in the first argument, and only one additional argument, as demonstrated by a second argument of -1.Show less
1Mozilla
1Firefox
Apr 23, 2026
Aug 3, 2009
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Mozilla Firefox before 3.0.13, and 3.5.x before 3.5.2, allows remote attackers to spoof the address bar, and possibly conduct phishing attacks, via a crafted web page that calls window.open with an invalid character in t...Show more
Mozilla Firefox before 3.0.13, and 3.5.x before 3.5.2, allows remote attackers to spoof the address bar, and possibly conduct phishing attacks, via a crafted web page that calls window.open with an invalid character in the URL, makes document.write calls to the resulting object, and then calls the stop method during the loading of the error page.Show less
1Joompolitan
1Com Livechat
Apr 23, 2026
Jul 30, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Live Chat (com_livechat) component 1.0 for Joomla! allows remote attackers to use the xmlhttp.php script as an open HTTP proxy to hide network scanning activities or scan internal networks via a GET request with a full U...Show more
Live Chat (com_livechat) component 1.0 for Joomla! allows remote attackers to use the xmlhttp.php script as an open HTTP proxy to hide network scanning activities or scan internal networks via a GET request with a full URL in the query string.Show less
1Firebirdsql
1Firebird
Oct 10, 2025
Jul 29, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
src/remote/server.cpp in fbserver.exe in Firebird SQL 1.5 before 1.5.6, 2.0 before 2.0.6, 2.1 before 2.1.3, and 2.5 before 2.5 Beta 2 allows remote attackers to cause a denial of service (daemon crash) via a malformed op...Show more
src/remote/server.cpp in fbserver.exe in Firebird SQL 1.5 before 1.5.6, 2.0 before 2.0.6, 2.1 before 2.1.3, and 2.5 before 2.5 Beta 2 allows remote attackers to cause a denial of service (daemon crash) via a malformed op_connect_request message that triggers an infinite loop or NULL pointer dereference.Show less
1Squid Cache
1Squid
Apr 23, 2026
Jul 28, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 allows remote attackers to cause a denial of service via malformed requests including (1) "missing or mismatched protocol identifier," (2) missing or negative statu...Show more
Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 allows remote attackers to cause a denial of service via malformed requests including (1) "missing or mismatched protocol identifier," (2) missing or negative status value," (3) "missing version," or (4) "missing or invalid status number," related to (a) HttpMsg.cc and (b) HttpReply.cc.Show less
1Ibm
1Tivoli Identity Manager
Apr 23, 2026
Jul 23, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple session fixation vulnerabilities in IBM Tivoli Identity Manager (ITIM) 5.0.0.6 allow remote attackers to hijack web sessions via unspecified vectors involving the (1) console and (2) self service interfaces.
1Realnetworks
2Helix Server
Helix Server Mobile
Apr 23, 2026
Jul 20, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
RealNetworks Helix Server and Helix Mobile Server before 13.0.0 allow remote attackers to cause a denial of service (daemon crash) via an RTSP SETUP request that (1) specifies the / URI or (2) lacks a / character in the...Show more
RealNetworks Helix Server and Helix Mobile Server before 13.0.0 allow remote attackers to cause a denial of service (daemon crash) via an RTSP SETUP request that (1) specifies the / URI or (2) lacks a / character in the URI.Show less
1Realnetworks
2Helix Server
Helix Server Mobile
Apr 23, 2026
Jul 20, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
rmserver in RealNetworks Helix Server and Helix Mobile Server before 13.0.0 allows remote attackers to cause a denial of service (daemon exit) via multiple RTSP SET_PARAMETER requests with empty DataConvertBuffer headers...Show more
rmserver in RealNetworks Helix Server and Helix Mobile Server before 13.0.0 allows remote attackers to cause a denial of service (daemon exit) via multiple RTSP SET_PARAMETER requests with empty DataConvertBuffer headers.Show less
1Microsoft
4Directx
Windows 2000Windows Server 2003+1 more
Apr 23, 2026
Jul 15, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
The QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 performs updates to pointers without properly v...Show more
The QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 performs updates to pointers without properly validating unspecified data values, which allows remote attackers to execute arbitrary code via a crafted QuickTime media file, aka "DirectX Pointer Validation Vulnerability."Show less
1Wordpress
1Wordpress
Apr 23, 2026
Jul 10, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
WordPress 2.7.1 places the username of a post's author in an HTML comment, which allows remote attackers to obtain sensitive information by reading the HTML source.
1Tor
1Tor
Apr 23, 2026
Jul 10, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Tor before 0.2.0.35 allows remote attackers to cause a denial of service (application crash) via a malformed router descriptor.
1Awingsoft
1Awakening Winds3d Viewer Plugin
Apr 23, 2026
Jul 10, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Insecure method vulnerability in Awingsoft Awakening Winds3D Viewer plugin 3.5.0.0, 3.0.0.5, and possibly other versions allows remote attackers to force the download and execution of arbitrary files via the GetURL metho...Show more
Insecure method vulnerability in Awingsoft Awakening Winds3D Viewer plugin 3.5.0.0, 3.0.0.5, and possibly other versions allows remote attackers to force the download and execution of arbitrary files via the GetURL method.Show less
1Apple
1Safari
Apr 23, 2026
Jul 9, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The CFCharacterSetInitInlineBuffer method in CoreFoundation.dll in Apple Safari 3.2.3 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary co...Show more
The CFCharacterSetInitInlineBuffer method in CoreFoundation.dll in Apple Safari 3.2.3 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via a "high-bit character" in a URL fragment for an unspecified protocol.Show less
1Apple
1Safari
Apr 23, 2026
Jul 9, 2009
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Apple Safari 3.2.3 does not properly implement the file: protocol handler, which allows remote attackers to read arbitrary files or cause a denial of service (launch of multiple Windows Explorer instances) via vectors in...Show more
Apple Safari 3.2.3 does not properly implement the file: protocol handler, which allows remote attackers to read arbitrary files or cause a denial of service (launch of multiple Windows Explorer instances) via vectors involving an unspecified HTML tag, possibly a related issue to CVE-2009-1703.Show less
1Axesstel
1Mv 410r
Apr 23, 2026
Jul 5, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
The web interface on the Axesstel MV 410R relies on client-side JavaScript code to validate input, which allows remote attackers to send crafted data, and possibly have unspecified other impact, via a client that does no...Show more
The web interface on the Axesstel MV 410R relies on client-side JavaScript code to validate input, which allows remote attackers to send crafted data, and possibly have unspecified other impact, via a client that does not process JavaScript.Show less
1Axesstel
1Mv 410r
Apr 23, 2026
Jul 5, 2009
N/A· v4
N/A· v3
7.8 HIGH· v2
The Axesstel MV 410R allows remote attackers to cause a denial of service via a flood of SYN packets, a related issue to CVE-1999-0116.
1Armassa
2Ard 9808
Ard 9808 Software
Apr 23, 2026
Jul 2, 2009
N/A· v4
N/A· v3
7.8 HIGH· v2
The ARD-9808 DVR card security camera allows remote attackers to cause a denial of service via a long URI composed of //.\ (slash slash dot backslash) sequences.