← Back
CWE-20

12,711 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,711)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
1Quicktime Mpeg 2 Playback Component
Apr 23, 2026
Jan 22, 2009
N/A· v4
N/A· v3
7.6 HIGH· v2
Unspecified vulnerability in Apple QuickTime MPEG-2 Playback Component before 7.60.92.0 on Windows allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted MPEG-2 m...Show more
Unspecified vulnerability in Apple QuickTime MPEG-2 Playback Component before 7.60.92.0 on Windows allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted MPEG-2 movie.Show less
1Zkesoft
1Ayeview
Apr 23, 2026
Jan 22, 2009
N/A· v4
N/A· v3
7.8 HIGH· v2
AyeView 2.20 allows user-assisted attackers to cause a denial of service (memory consumption or application crash) via a bitmap (aka .bmp) file with large height and width values.
1Trend Micro
3Internet Security 2007
Internet Security 2008Officescan
Apr 23, 2026
Jan 21, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The ApiThread function in the firewall service (aka TmPfw.exe) in Trend Micro Network Security Component (NSC) modules, as used in Trend Micro OfficeScan 8.0 SP1 Patch 1 and Internet Security 2007 and 2008 17.0.1224, all...Show more
The ApiThread function in the firewall service (aka TmPfw.exe) in Trend Micro Network Security Component (NSC) modules, as used in Trend Micro OfficeScan 8.0 SP1 Patch 1 and Internet Security 2007 and 2008 17.0.1224, allows remote attackers to cause a denial of service (service crash) via a packet with a large value in an unspecified size field.Show less
1Symantec
1Appstream Client
Apr 23, 2026
Jan 20, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
The LaunchObj ActiveX control before 5.2.2.865 in launcher.dll in Symantec AppStream Client 5.2.x before 5.2.2 SP3 MP1 does not properly validate downloaded files, which allows remote attackers to execute arbitrary code...Show more
The LaunchObj ActiveX control before 5.2.2.865 in launcher.dll in Symantec AppStream Client 5.2.x before 5.2.2 SP3 MP1 does not properly validate downloaded files, which allows remote attackers to execute arbitrary code via the installAppMgr method and unspecified other methods.Show less
1Ibm
1Db2 Universal Database
Apr 23, 2026
Jan 16, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in the server in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote authenticated users to cause a denial of service (trap) via a crafted data stream.
1Ibm
1Db2 Universal Database
Apr 23, 2026
Jan 16, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote attackers to cause a denial of service (infinite loop) via a crafted CONNECT data stream.
1Realvnc
1Realvnc
Apr 23, 2026
Jan 16, 2009
N/A· v4
N/A· v3
10.0 HIGH· v2
The CMsgReader::readRect function in the VNC Viewer component in RealVNC VNC Free Edition 4.0 through 4.1.2, Enterprise Edition E4.0 through E4.4.2, and Personal Edition P4.0 through P4.4.2 allows remote VNC servers to e...Show more
The CMsgReader::readRect function in the VNC Viewer component in RealVNC VNC Free Edition 4.0 through 4.1.2, Enterprise Edition E4.0 through E4.4.2, and Personal Edition P4.0 through P4.4.2 allows remote VNC servers to execute arbitrary code via crafted RFB protocol data, related to "encoding type."Show less
1Cisco
2Unified Ip Phone 7940g
Unified Ip Phone 7960g
Apr 23, 2026
Jan 16, 2009
N/A· v4
N/A· v3
7.1 HIGH· v2
Cisco Unified IP Phone (aka SIP phone) 7960G and 7940G with firmware P0S3-08-9-00 and possibly other versions before 8.10 allows remote attackers to cause a denial of service (device reboot) or possibly execute arbitrary...Show more
Cisco Unified IP Phone (aka SIP phone) 7960G and 7940G with firmware P0S3-08-9-00 and possibly other versions before 8.10 allows remote attackers to cause a denial of service (device reboot) or possibly execute arbitrary code via a Realtime Transport Protocol (RTP) packet with malformed headers.Show less
1Cisco
2Ons
Ons 15600
Apr 23, 2026
Jan 16, 2009
N/A· v4
N/A· v3
7.8 HIGH· v2
Cisco ONS 15310-CL, 15310-MA, 15327, 15454, 15454 SDH, and 15600 with software 7.0.2 through 7.0.6, 7.2.2, 8.0.x, 8.5.1, and 8.5.2 allows remote attackers to cause a denial of service (control-card reset) via a crafted T...Show more
Cisco ONS 15310-CL, 15310-MA, 15327, 15454, 15454 SDH, and 15600 with software 7.0.2 through 7.0.6, 7.2.2, 8.0.x, 8.5.1, and 8.5.2 allows remote attackers to cause a denial of service (control-card reset) via a crafted TCP session.Show less
2Debian
Linux
2Debian Linux
Linux Kernel
Apr 23, 2026
Jan 15, 2009
N/A· v4
N/A· v3
7.2 HIGH· v2
The ABI in the Linux kernel 2.6.28 and earlier on s390, powerpc, sparc64, and mips 64-bit platforms requires that a 32-bit argument in a 64-bit register was properly sign extended when sent from a user-mode application,...Show more
The ABI in the Linux kernel 2.6.28 and earlier on s390, powerpc, sparc64, and mips 64-bit platforms requires that a 32-bit argument in a 64-bit register was properly sign extended when sent from a user-mode application, but cannot verify this, which allows local users to cause a denial of service (crash) or possibly gain privileges via a crafted system call.Show less
1Ktorrent
1Ktorrent
Apr 23, 2026
Jan 15, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Eval injection vulnerability in the web interface plugin in KTorrent before 3.1.4 allows remote attackers to execute arbitrary PHP code via unspecified parameters to this interface's PHP scripts.
1Xrdp
1Xrdp
Apr 23, 2026
Jan 15, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
The rdp_rdp_process_color_pointer_pdu function in rdp/rdp_rdp.c in xrdp 0.4.1 and earlier allows remote RDP servers to have an unknown impact via input data that sets crafted values for certain length variables, leading...Show more
The rdp_rdp_process_color_pointer_pdu function in rdp/rdp_rdp.c in xrdp 0.4.1 and earlier allows remote RDP servers to have an unknown impact via input data that sets crafted values for certain length variables, leading to a buffer overflow.Show less
1Ibm
1Websphere Datapower Xml Security Gateway Xs40
Apr 23, 2026
Jan 15, 2009
N/A· v4
N/A· v3
7.8 HIGH· v2
The IBM WebSphere DataPower XML Security Gateway XS40 with firmware 3.6.1.5 allows remote attackers to cause a denial of service (device reboot) by sending data over an established SSL connection, as demonstrated by the...Show more
The IBM WebSphere DataPower XML Security Gateway XS40 with firmware 3.6.1.5 allows remote attackers to cause a denial of service (device reboot) by sending data over an established SSL connection, as demonstrated by the abc\r\n\r\n string data.Show less
1Tincan
1Phplist
Apr 23, 2026
Jan 12, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
phplist before 2.10.8 allows remote attackers to include files via unknown vectors, related to a "local file include vulnerability."
1Nortel
1Multimedia Communication Server 5100
Apr 23, 2026
Jan 8, 2009
N/A· v4
N/A· v3
7.8 HIGH· v2
Multiple unspecified vulnerabilities in the UNIStim File Transfer Protocol (UFTP) processing in IP Client Manager (IPCM) in Nortel Multimedia Communication Server (MSC) 5100 3.0.13 allow remote attackers to cause a denia...Show more
Multiple unspecified vulnerabilities in the UNIStim File Transfer Protocol (UFTP) processing in IP Client Manager (IPCM) in Nortel Multimedia Communication Server (MSC) 5100 3.0.13 allow remote attackers to cause a denial of service (device outage) via a UFTP message that has a negative block size or other crafted Connection Details values.Show less
1Faststone
1Image Viewer
Apr 23, 2026
Jan 8, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
FastStone Image Viewer 3.6 allows user-assisted attackers to cause a denial of service (application crash) via a malformed BMP image with large width and height values, possibly a related issue to CVE-2007-1942.
1Entrouvert
1Lasso
Apr 23, 2026
Jan 7, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Lasso 2.2.1 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a simi...Show more
Lasso 2.2.1 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.Show less
1Openssl
1Openssl
Apr 23, 2026
Jan 7, 2009
N/A· v4
N/A· v3
5.8 MEDIUM· v2
OpenSSL 0.9.8i and earlier does not properly check the return value from the EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA...Show more
OpenSSL 0.9.8i and earlier does not properly check the return value from the EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys.Show less
1Samba
1Samba
Apr 23, 2026
Jan 5, 2009
N/A· v4
N/A· v3
6.3 MEDIUM· v2
Samba 3.2.0 through 3.2.6, when registry shares are enabled, allows remote authenticated users to access the root filesystem via a crafted connection request that specifies a blank share name.
1Nokia
16131 Nfc
Apr 23, 2026
Jan 2, 2009
N/A· v4
N/A· v3
7.8 HIGH· v2
The Nokia 6131 Near Field Communication (NFC) phone with 05.12 firmware allows remote attackers to cause a denial of service (device crash) via (1) a large value in the payload length field in an NDEF record, or a certai...Show more
The Nokia 6131 Near Field Communication (NFC) phone with 05.12 firmware allows remote attackers to cause a denial of service (device crash) via (1) a large value in the payload length field in an NDEF record, or a certain length for a (2) tel: or (3) sms: NDEF URI.Show less