← Back
CWE-20

12,711 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,711)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wireshark
1Wireshark
Apr 23, 2026
Sep 4, 2008
N/A· v4
N/A· v3
3.3 LOW· v2
Unspecified vulnerability in Wireshark (formerly Ethereal) 0.99.6 through 1.0.2 allows attackers to cause a denial of service (crash) via a crafted Tektronix .rf5 file.
1Wireshark
1Wireshark
Apr 23, 2026
Sep 4, 2008
N/A· v4
N/A· v3
3.3 LOW· v2
Wireshark (formerly Ethereal) 0.10.14 through 1.0.2 allows attackers to cause a denial of service (crash) via a packet with crafted zlib-compressed data that triggers an invalid read in the tvb_uncompress function.
1Wireshark
1Wireshark
Apr 23, 2026
Sep 4, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Wireshark (formerly Ethereal) 0.9.7 through 1.0.2 allows attackers to cause a denial of service (hang) via a crafted NCP packet that triggers an infinite loop.
1Newsbeuter
1Newsbeuter
Apr 23, 2026
Sep 4, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The open-in-browser command in newsbeuter before 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in a feed URL.
2Mono
Mono Project
2Mono
Mono
Apr 23, 2026
Sep 4, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
CRLF injection vulnerability in Sys.Web in Mono 2.0 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the query string.
1Lxde
2Gpicview
Lightweight X11 Desktop Environment
Apr 23, 2026
Sep 4, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
src/main-win.c in GPicView 0.1.9 in Lightweight X11 Desktop Environment (LXDE) allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a filename.
1Cisco
1Adaptive Security Appliance 5500
Apr 23, 2026
Sep 4, 2008
N/A· v4
N/A· v3
7.1 HIGH· v2
The HTTP server in Cisco Adaptive Security Appliance (ASA) 5500 devices 8.0 before 8.0(3)15 and 8.1 before 8.1(1)5, when configured as a clientless SSL VPN endpoint, does not properly process URIs, which allows remote at...Show more
The HTTP server in Cisco Adaptive Security Appliance (ASA) 5500 devices 8.0 before 8.0(3)15 and 8.1 before 8.1(1)5, when configured as a clientless SSL VPN endpoint, does not properly process URIs, which allows remote attackers to cause a denial of service (device reload) via a URI in a crafted SSL or HTTP packet, aka Bug ID CSCsq19369.Show less
1Vmware
2Server
Vmware Server
Apr 23, 2026
Sep 3, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
An unspecified ISAPI extension in VMware Server before 1.0.7 build 108231 allows remote attackers to cause a denial of service (IIS crash) via a malformed request.
1Ultrashareware
1Ultra Office Control
Apr 23, 2026
Sep 2, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
The Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 and earlier in Ultra Shareware Ultra Office Control allows remote attackers to force the download of arbitrary files onto a client system via a URL i...Show more
The Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 and earlier in Ultra Shareware Ultra Office Control allows remote attackers to force the download of arbitrary files onto a client system via a URL in the first argument to the Open method, in conjunction with a full destination pathname in the first argument (SaveAsDocument argument) to the Save method.Show less
1Openbsd
1Openssh
Apr 23, 2026
Aug 27, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
Certain Red Hat Enterprise Linux (RHEL) 4 and 5 packages for OpenSSH, as signed in August 2008 using a legitimate Red Hat GPG key, contain an externally introduced modification (Trojan Horse) that allows the package auth...Show more
Certain Red Hat Enterprise Linux (RHEL) 4 and 5 packages for OpenSSH, as signed in August 2008 using a legitimate Red Hat GPG key, contain an externally introduced modification (Trojan Horse) that allows the package authors to have an unknown impact. NOTE: since the malicious packages were not distributed from any official Red Hat sources, the scope of this issue is restricted to users who may have obtained these packages through unofficial distribution points. As of 20080827, no unofficial distributions of this software are known.Show less
1Sun
2Opensolaris
Solaris
Apr 23, 2026
Aug 27, 2008
N/A· v4
N/A· v3
7.2 HIGH· v2
Unspecified vulnerability in the NFS Remote Procedure Calls (RPC) zones implementation in Sun Solaris 10 and OpenSolaris before snv_88 allows local administrators of non-global zones to read and modify NFS traffic for ar...Show more
Unspecified vulnerability in the NFS Remote Procedure Calls (RPC) zones implementation in Sun Solaris 10 and OpenSolaris before snv_88 allows local administrators of non-global zones to read and modify NFS traffic for arbitrary non-global zones, possibly leading to file modifications or a denial of service.Show less
1Ruby Lang
1Ruby
Apr 23, 2026
Aug 27, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The REXML module in Ruby 1.8.6 through 1.8.6-p287, 1.8.7 through 1.8.7-p72, and 1.9 allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML document with recursively nested entities,...Show more
The REXML module in Ruby 1.8.6 through 1.8.6-p287, 1.8.7 through 1.8.7-p72, and 1.9 allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML document with recursively nested entities, aka an "XML entity explosion."Show less
1Swfdec
1Swfdec
Apr 23, 2026
Aug 27, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Swfdec 0.6 before 0.6.8 allows remote attackers to cause a denial of service (application crash) via a 1x1 JPEG image.
1Realtime Internet Band Rehearsal
1Low Latency Internet Connection Tool
Apr 23, 2026
Aug 22, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Realtime Internet Band Rehearsal Low-Latency (Internet) Connection tool (llcon) before 2.1.2 allows remote attackers to cause a denial of service (application crash) via malformed protocol messages.
1Turnkeywebtools
1Php Live Helper
Apr 23, 2026
Aug 21, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Variable overwrite vulnerability in libsecure.php in Turnkey PHP Live Helper 2.0.1 and earlier, when register_globals is enabled, allows remote attackers to overwrite arbitrary variables related to the db config file. N...Show more
Variable overwrite vulnerability in libsecure.php in Turnkey PHP Live Helper 2.0.1 and earlier, when register_globals is enabled, allows remote attackers to overwrite arbitrary variables related to the db config file. NOTE: this can be leveraged for code injection by overwriting the language file.Show less
1Vmware
1Vmware Workstation
Apr 23, 2026
Aug 21, 2008
N/A· v4
N/A· v3
4.9 MEDIUM· v2
hcmon.sys in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, and VMware Server 1.0.x before 1.0.9 build 156507 and 2.0.x before 2.0.1 build 156745 uses the METHOD_NEIT...Show more
hcmon.sys in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, and VMware Server 1.0.x before 1.0.9 build 156507 and 2.0.x before 2.0.1 build 156745 uses the METHOD_NEITHER communication method for IOCTLs, which allows local users to cause a denial of service via a crafted IOCTL request.Show less
1Php
1Php
Apr 23, 2026
Aug 15, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
PHP 4.4.x before 4.4.9, and 5.x through 5.2.6, when used as a FastCGI module, allows remote attackers to cause a denial of service (crash) via a request with multiple dots preceding the extension, as demonstrated using f...Show more
PHP 4.4.x before 4.4.9, and 5.x through 5.2.6, when used as a FastCGI module, allows remote attackers to cause a denial of service (crash) via a request with multiple dots preceding the extension, as demonstrated using foo..php.Show less
1Hp
1Linux Imaging And Printing Project
Apr 23, 2026
Aug 14, 2008
N/A· v4
N/A· v3
4.9 MEDIUM· v2
The hpssd message parser in hpssd.py in HP Linux Imaging and Printing (HPLIP) 1.6.7 allows local users to cause a denial of service (process stop) via a crafted packet, as demonstrated by sending "msg=0" to TCP port 2207...Show more
The hpssd message parser in hpssd.py in HP Linux Imaging and Printing (HPLIP) 1.6.7 allows local users to cause a denial of service (process stop) via a crafted packet, as demonstrated by sending "msg=0" to TCP port 2207.Show less
1Flagship Industries
1Ventrilo
Apr 23, 2026
Aug 14, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The decryption function in Flagship Industries Ventrilo 3.0.2 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) by sending a type 0 packet with an invalid versio...Show more
The decryption function in Flagship Industries Ventrilo 3.0.2 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) by sending a type 0 packet with an invalid version followed by another packet to TCP port 3784.Show less
1Hmailserver
1Hmailserver
Apr 23, 2026
Aug 14, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Unspecified vulnerability in the IMAP server in hMailServer 4.4.1 allows remote authenticated users to cause a denial of service (resource exhaustion or daemon crash) via a long series of IMAP commands.