← Back
CWE-20

12,711 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,711)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zdaemon
1Zdaemon
Apr 23, 2026
Jul 25, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
ZDaemon 1.08.07 and earlier allows remote attackers to cause a denial of service (daemon crash) via a crafted type 6 command, which triggers a NULL pointer dereference.
1Emc Dantz
1Retrospect Backup Client
Apr 23, 2026
Jul 24, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
retroclient.exe in EMC Dantz Retrospect Backup Client 7.5.116 allows remote attackers to cause a denial of service (daemon crash) via malformed packets to TCP port 497, which trigger a NULL pointer dereference.
1Sierra
1Swat 4
Apr 23, 2026
Jul 24, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
SWAT 4 1.1 and earlier allows remote attackers to cause a denial of service (daemon crash) via a (1) VERIFYCONTENT or (2) GAMECONFIG command sent to the server before user session initialization, which triggers a NULL po...Show more
SWAT 4 1.1 and earlier allows remote attackers to cause a denial of service (daemon crash) via a (1) VERIFYCONTENT or (2) GAMECONFIG command sent to the server before user session initialization, which triggers a NULL pointer dereference; or (3) a GAMESPYRESPONSE command followed by a long RS string.Show less
1F Prot
2F Prot Antivirus
Scanning Engine
Apr 23, 2026
Jul 21, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The scanning engine before 4.4.4 in F-Prot Antivirus before 6.0.9.0 allows remote attackers to cause a denial of service (engine crash) via a CHM file with a large nb_dir value that triggers an out-of-bounds read.
1F Prot
2F Prot Antivirus
Scanning Engine
Apr 23, 2026
Jul 21, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple unspecified vulnerabilities in the scanning engine before 4.4.4 in F-Prot Antivirus before 6.0.9.0 allow remote attackers to cause a denial of service via (1) a crafted UPX-compressed file, which triggers an eng...Show more
Multiple unspecified vulnerabilities in the scanning engine before 4.4.4 in F-Prot Antivirus before 6.0.9.0 allow remote attackers to cause a denial of service via (1) a crafted UPX-compressed file, which triggers an engine crash; (2) a crafted Microsoft Office file, which triggers an infinite loop; or (3) an ASPack-compressed file, which triggers an engine crash.Show less
1Phpizabi
1Phpizabi
Apr 23, 2026
Jul 21, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
Unrestricted file upload vulnerability in the writeLogEntry function in system/v_cron_proc.php in PHPizabi 0.848b C1 HFP1, when register_globals is enabled, allows remote attackers to upload and execute arbitrary code vi...Show more
Unrestricted file upload vulnerability in the writeLogEntry function in system/v_cron_proc.php in PHPizabi 0.848b C1 HFP1, when register_globals is enabled, allows remote attackers to upload and execute arbitrary code via a filename in the CONF[CRON_LOGFILE] parameter and file contents in the CONF[LOCALE_LONG_DATE_TIME] parameter.Show less
1Opensuse
1Zypper
Apr 23, 2026
Jul 21, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
zypp-refresh-patches in zypper in SUSE openSUSE 10.2, 10.3, and 11.0 does not ask the user before accepting repository keys, which allows remote repositories to cause a denial of service (package data corruption) via a s...Show more
zypp-refresh-patches in zypper in SUSE openSUSE 10.2, 10.3, and 11.0 does not ask the user before accepting repository keys, which allows remote repositories to cause a denial of service (package data corruption) via a spoofed key.Show less
1Xine
1Xine Lib
Apr 23, 2026
Jul 18, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
xine-lib before 1.1.15 allows remote attackers to cause a denial of service (crash) via a crafted OGG file, as demonstrated by playing lol-ffplay.ogg with xine.
1Ffmpeg
1Lavf Demuxer
Apr 23, 2026
Jul 18, 2008
N/A· v4
N/A· v3
1.9 LOW· v2
The ffmpeg lavf demuxer allows user-assisted attackers to cause a denial of service (application crash) via a crafted GIF file, possibly related to gstreamer, as demonstrated by lol-giftopnm.gif.
1Thekelleys
1Dnsmasq
Apr 23, 2026
Jul 18, 2008
N/A· v4
N/A· v3
7.8 HIGH· v2
dnsmasq 2.25 allows remote attackers to cause a denial of service (daemon crash) by (1) renewing a nonexistent lease or (2) sending a DHCPREQUEST for an IP address that is not in the same network, related to the DHCP NAK...Show more
dnsmasq 2.25 allows remote attackers to cause a denial of service (daemon crash) by (1) renewing a nonexistent lease or (2) sending a DHCPREQUEST for an IP address that is not in the same network, related to the DHCP NAK response from the daemon.Show less
1Resiprocate
1Resiprocate
Apr 23, 2026
Jul 18, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
rutil/dns/DnsStub.cxx in ReSIProcate 1.3.2, as used by repro, allows remote attackers to cause a denial of service (daemon crash) via a SIP (1) INVITE or (2) OPTIONS message with a long domain name in a request URI, whic...Show more
rutil/dns/DnsStub.cxx in ReSIProcate 1.3.2, as used by repro, allows remote attackers to cause a denial of service (daemon crash) via a SIP (1) INVITE or (2) OPTIONS message with a long domain name in a request URI, which triggers an assert error.Show less
1Simpledns
1Simple Dns Plus
Apr 23, 2026
Jul 18, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Simple DNS Plus 4.1, 5.0, and possibly other versions before 5.1.101 allows remote attackers to cause a denial of service via multiple DNS reply packets.
1Resiprocate
1Resiprocate
Apr 23, 2026
Jul 17, 2008
N/A· v4
N/A· v3
7.8 HIGH· v2
Multiple unspecified vulnerabilities in ReSIProcate before 1.3.4 allow remote attackers to cause a denial of service (stack consumption) via unknown network traffic with a large "bytes-in-memory/bytes-on-wire ratio."
1Mozilla
1Firefox
Apr 23, 2026
Jul 17, 2008
N/A· v4
N/A· v3
2.6 LOW· v2
Mozilla Firefox before 2.0.0.16, and 3.x before 3.0.1, interprets '|' (pipe) characters in a command-line URI as requests to open multiple tabs, which allows remote attackers to access chrome:i URIs, or read arbitrary lo...Show more
Mozilla Firefox before 2.0.0.16, and 3.x before 3.0.1, interprets '|' (pipe) characters in a command-line URI as requests to open multiple tabs, which allows remote attackers to access chrome:i URIs, or read arbitrary local files via manipulations involving a series of URIs that is not entirely handled by a vector application, as exploited in conjunction with CVE-2008-2540. NOTE: this issue exists because of an insufficient fix for CVE-2005-2267.Show less
1Wireshark
1Wireshark
Apr 23, 2026
Jul 16, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The fragment_add_work function in epan/reassemble.c in Wireshark 0.8.19 through 1.0.1 allows remote attackers to cause a denial of service (crash) via a series of fragmented packets with non-sequential fragmentation offs...Show more
The fragment_add_work function in epan/reassemble.c in Wireshark 0.8.19 through 1.0.1 allows remote attackers to cause a denial of service (crash) via a series of fragmented packets with non-sequential fragmentation offset values, which lead to a buffer over-read.Show less
1Content Now
1Content Now
Apr 23, 2026
Jul 15, 2008
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Unrestricted file upload vulnerability in upload.php in ContentNow CMS 1.4.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct re...Show more
Unrestricted file upload vulnerability in upload.php in ContentNow CMS 1.4.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in upload/.Show less
1Webxell
1Webxell Editor
Apr 23, 2026
Jul 15, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Unrestricted file upload vulnerability in upload_pictures.php in WebXell Editor 0.1.3 allows remote attackers to execute arbitrary code by uploading a .php file with a jpeg content type, then accessing it via a direct re...Show more
Unrestricted file upload vulnerability in upload_pictures.php in WebXell Editor 0.1.3 allows remote attackers to execute arbitrary code by uploading a .php file with a jpeg content type, then accessing it via a direct request to the file in upload/.Show less
1Apple
1Safari
Apr 23, 2026
Jul 14, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Safari on Apple iPhone before 2.0 and iPod touch before 2.0 misinterprets a menu button press as user confirmation for visiting a web site with a (1) self-signed or (2) invalid certificate, which makes it easier for remo...Show more
Safari on Apple iPhone before 2.0 and iPod touch before 2.0 misinterprets a menu button press as user confirmation for visiting a web site with a (1) self-signed or (2) invalid certificate, which makes it easier for remote attackers to spoof web sites.Show less
1Apple
1Safari
Apr 23, 2026
Jul 14, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Safari on Apple iPhone before 2.0 and iPod touch before 2.0 allows remote attackers to spoof the address bar via Unicode ideographic spaces in the URL.
1Wireshark
1Wireshark
Apr 23, 2026
Jul 10, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The GSM SMS dissector in Wireshark (formerly Ethereal) 0.99.2 through 1.0.0 allows remote attackers to cause a denial of service (application crash) via unknown vectors.