← Back
CWE-20

12,711 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,711)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Joomla
1Joomla
Apr 23, 2026
Sep 18, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
JRequest in Joomla! 1.5 before 1.5.7 does not sanitize variables that were set with JRequest::setVar, which allows remote attackers to conduct "variable injection" attacks and have unspecified other impact.
1Joomla
1Com Mailto
Apr 23, 2026
Sep 18, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The mailto (aka com_mailto) component in Joomla! 1.5 before 1.5.7 sends e-mail messages without validating the URL, which allows remote attackers to transmit spam.
1Vim
1Vim
Apr 23, 2026
Sep 18, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
Vim 3.0 through 7.x before 7.2.010 does not properly escape characters, which allows user-assisted attackers to (1) execute arbitrary shell commands by entering a K keystroke on a line that contains a ";" (semicolon) fol...Show more
Vim 3.0 through 7.x before 7.2.010 does not properly escape characters, which allows user-assisted attackers to (1) execute arbitrary shell commands by entering a K keystroke on a line that contains a ";" (semicolon) followed by a command, or execute arbitrary Ex commands by entering an argument after a (2) "Ctrl-]" (control close-square-bracket) or (3) "g]" (g close-square-bracket) keystroke sequence, a different issue than CVE-2008-2712.Show less
1Phpmyadmin
1Phpmyadmin
Apr 23, 2026
Sep 18, 2008
N/A· v4
N/A· v3
8.5 HIGH· v2
libraries/database_interface.lib.php in phpMyAdmin before 2.11.9.1 allows remote authenticated users to execute arbitrary code via a request to server_databases.php with a sort_by parameter containing PHP sequences, whic...Show more
libraries/database_interface.lib.php in phpMyAdmin before 2.11.9.1 allows remote authenticated users to execute arbitrary code via a request to server_databases.php with a sort_by parameter containing PHP sequences, which are processed by create_function.Show less
1Adobe
1Acrobat
Apr 23, 2026
Sep 15, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
A certain ActiveX control in Adobe Acrobat 9, when used with Microsoft Windows Vista and Internet Explorer 7, allows remote attackers to cause a denial of service (browser crash) via an src property value with an invalid...Show more
A certain ActiveX control in Adobe Acrobat 9, when used with Microsoft Windows Vista and Internet Explorer 7, allows remote attackers to cause a denial of service (browser crash) via an src property value with an invalid acroie:// URL.Show less
1Postfix
1Postfix
Apr 23, 2026
Sep 12, 2008
N/A· v4
N/A· v3
2.1 LOW· v2
Postfix 2.4 before 2.4.9, 2.5 before 2.5.5, and 2.6 before 2.6-20080902, when used with the Linux 2.6 kernel, leaks epoll file descriptors during execution of "non-Postfix" commands, which allows local users to cause a d...Show more
Postfix 2.4 before 2.4.9, 2.5 before 2.5.5, and 2.6 before 2.6-20080902, when used with the Linux 2.6 kernel, leaks epoll file descriptors during execution of "non-Postfix" commands, which allows local users to cause a denial of service (application slowdown or exit) via a crafted command, as demonstrated by a command in a .forward file.Show less
1Friendly Technologies
1Friendly Pppoe Client
Apr 23, 2026
Sep 11, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
A certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPoE Client 3.0.0.57 allows remote attackers to (1) create and read arbitrary registry values via the RegistryValue method, and (2) r...Show more
A certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPoE Client 3.0.0.57 allows remote attackers to (1) create and read arbitrary registry values via the RegistryValue method, and (2) read arbitrary files via the GetTextFile method.Show less
1Friendly Technologies
1Friendly Pppoe Client
Apr 23, 2026
Sep 11, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
A certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPoE Client 3.0.0.57 allows remote attackers to execute arbitrary programs via arguments to the RunApp method.
1Softalk Mail Server
1Softalk Mail Server
Apr 23, 2026
Sep 11, 2008
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The IMAP server in Softalk Mail Server (formerly WorkgroupMail) 8.5.1.431 allows remote authenticated users to cause a denial of service (resource consumption and daemon crash) via a long IMAP APPEND command with certain...Show more
The IMAP server in Softalk Mail Server (formerly WorkgroupMail) 8.5.1.431 allows remote authenticated users to cause a denial of service (resource consumption and daemon crash) via a long IMAP APPEND command with certain repeated parameters.Show less
1Netbsd
1Netbsd
Apr 23, 2026
Sep 11, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
NetBSD 3.0, 3.1, and 4.0, when a pppoe instance exists, does not properly check the length of a PPPoE packet tag, which allows remote attackers to cause a denial of service (system crash) via a crafted PPPoE packet.
1Ibm
1Db2 Universal Database
Apr 23, 2026
Sep 11, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in the JDBC Applet Server Service (aka db2jds) in IBM DB2 UDB 8 before Fixpak 17 allows remote attackers to cause a denial of service (service crash) via "malicious packets."
1Microsoft
1Windows Image Acquisition Logger
Apr 23, 2026
Sep 11, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
The Microsoft Windows Image Acquisition Logger ActiveX control allows remote attackers to force the download of arbitrary files onto a client system via a URL in the first argument to the Open method, in conjunction with...Show more
The Microsoft Windows Image Acquisition Logger ActiveX control allows remote attackers to force the download of arbitrary files onto a client system via a URL in the first argument to the Open method, in conjunction with a full destination pathname in the first argument to the Save method. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Microsoft
2Office
Office Onenote
Apr 23, 2026
Sep 11, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
Argument injection vulnerability in a URI handler in Microsoft Office XP SP3, 2003 SP2 and SP3, 2007 Office System Gold and SP1, and Office OneNote 2007 Gold and SP1 allow remote attackers to execute arbitrary code via a...Show more
Argument injection vulnerability in a URI handler in Microsoft Office XP SP3, 2003 SP2 and SP3, 2007 Office System Gold and SP1, and Office OneNote 2007 Gold and SP1 allow remote attackers to execute arbitrary code via a crafted onenote:// URL, aka "Uniform Resource Locator Validation Error Vulnerability."Show less
1Apple
1Bonjour
Apr 23, 2026
Sep 11, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
mDNSResponder in the Bonjour Namespace Provider in Apple Bonjour for Windows before 1.0.5 allows attackers to cause a denial of service (NULL pointer dereference and application crash) by resolving a crafted .local domai...Show more
mDNSResponder in the Bonjour Namespace Provider in Apple Bonjour for Windows before 1.0.5 allows attackers to cause a denial of service (NULL pointer dereference and application crash) by resolving a crafted .local domain name that contains a long label.Show less
1Hp
1Openvms
Apr 23, 2026
Sep 5, 2008
N/A· v4
N/A· v3
7.2 HIGH· v2
DCL (aka the CLI) in OpenVMS Alpha 8.3 allows local users to gain privileges via a long command line.
1Freebsd
1Freebsd
Apr 23, 2026
Sep 5, 2008
N/A· v4
N/A· v3
7.1 HIGH· v2
sys/netinet6/icmp6.c in the kernel in FreeBSD 6.3 through 7.1, NetBSD 3.0 through 4.0, and possibly other operating systems does not properly check the proposed new MTU in an ICMPv6 Packet Too Big Message, which allows r...Show more
sys/netinet6/icmp6.c in the kernel in FreeBSD 6.3 through 7.1, NetBSD 3.0 through 4.0, and possibly other operating systems does not properly check the proposed new MTU in an ICMPv6 Packet Too Big Message, which allows remote attackers to cause a denial of service (panic) via a crafted Packet Too Big Message.Show less
2Marvell
Netgear
288w8361w Bem1
Wn802t
Apr 23, 2026
Sep 5, 2008
N/A· v4
N/A· v3
6.3 MEDIUM· v2
The Marvell driver for the Netgear WN802T Wi-Fi access point with firmware 1.3.16 on the Marvell 88W8361P-BEM1 chipset does not properly parse the SSID information element in an association request, which allows remote a...Show more
The Marvell driver for the Netgear WN802T Wi-Fi access point with firmware 1.3.16 on the Marvell 88W8361P-BEM1 chipset does not properly parse the SSID information element in an association request, which allows remote authenticated users to cause a denial of service (device reboot or hang) or possibly execute arbitrary code via a "Null SSID."Show less
2Marvell
Netgear
288w8361w Bem1
Wn802t
Apr 23, 2026
Sep 5, 2008
N/A· v4
N/A· v3
6.3 MEDIUM· v2
The Marvell driver for the Netgear WN802T Wi-Fi access point with firmware 1.3.16 on the Marvell 88W8361P-BEM1 chipset does not properly parse EAPoL-Key packets, which allows remote authenticated users to cause a denial...Show more
The Marvell driver for the Netgear WN802T Wi-Fi access point with firmware 1.3.16 on the Marvell 88W8361P-BEM1 chipset does not properly parse EAPoL-Key packets, which allows remote authenticated users to cause a denial of service (device reboot or hang) or possibly execute arbitrary code via a malformed EAPoL-Key packet with a crafted "advertised length."Show less
2Atheros
Linksys
2Ar5416 Ac1e Chipset
Wrt350n
Apr 23, 2026
Sep 5, 2008
N/A· v4
N/A· v3
6.3 MEDIUM· v2
The driver for the Linksys WRT350N Wi-Fi access point with firmware 2.00.17 on the Atheros AR5416-AC1E chipset does not properly parse the Atheros vendor-specific information element in an association request, which allo...Show more
The driver for the Linksys WRT350N Wi-Fi access point with firmware 2.00.17 on the Atheros AR5416-AC1E chipset does not properly parse the Atheros vendor-specific information element in an association request, which allows remote authenticated users to cause a denial of service (device reboot or hang) or possibly execute arbitrary code via an Atheros information element with an invalid length, as demonstrated by an element that is too long.Show less
1Dreambox
1Dm500c
Apr 23, 2026
Sep 5, 2008
N/A· v4
N/A· v3
7.8 HIGH· v2
The web interface in Dreambox DM500C allows remote attackers to cause a denial of service (application hang) via a long URI.