← Back
CWE-20

12,710 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,710)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Linksys
1Wrt54g
Apr 23, 2026
Mar 10, 2008
N/A· v4
N/A· v3
7.8 HIGH· v2
The Linksys WRT54G router allows remote attackers to cause a denial of service (device restart) via a long username and password to the FTP interface.
1Snom
1320 Sip Phone
Apr 23, 2026
Mar 10, 2008
N/A· v4
N/A· v3
9.4 HIGH· v2
snomControl.swf in the central phone server for the Snom 320 SIP Phone allows remote attackers to cause a denial of service (application crash and corruption of call logs) via a "'); (double quote, quote, close parenthes...Show more
snomControl.swf in the central phone server for the Snom 320 SIP Phone allows remote attackers to cause a denial of service (application crash and corruption of call logs) via a "'); (double quote, quote, close parenthesis, semicolon) sequence in the "Call a number" field.Show less
1Belkin
1F5d7230 4
Apr 23, 2026
Mar 10, 2008
N/A· v4
N/A· v3
7.8 HIGH· v2
cgi-bin/setup_virtualserver.exe on the Belkin F5D7230-4 router with firmware 9.01.10 allows remote attackers to cause a denial of service (control center outage) via an HTTP request with invalid POST data and a "Connecti...Show more
cgi-bin/setup_virtualserver.exe on the Belkin F5D7230-4 router with firmware 9.01.10 allows remote attackers to cause a denial of service (control center outage) via an HTTP request with invalid POST data and a "Connection: Keep-Alive" header.Show less
1Ibm
1Lotus Quickr Server
Apr 23, 2026
Mar 9, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
IBM Lotus Quickr 8.0 server, and possibly QuickPlace 7.x, does not properly identify URIs containing cross-site scripting (XSS) attack strings, which allows remote attackers to inject arbitrary web script or HTML via a C...Show more
IBM Lotus Quickr 8.0 server, and possibly QuickPlace 7.x, does not properly identify URIs containing cross-site scripting (XSS) attack strings, which allows remote attackers to inject arbitrary web script or HTML via a Calendar OpenDocument action to main.nsf with a Count parameter containing a JavaScript event in a malformed element, as demonstrated by an onload event in an IFRAME element.Show less
1Synce
1Synce
Apr 23, 2026
Mar 4, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
The Utils::runScripts function in src/utils.cpp in vdccm 0.92 through 0.10.0 in SynCE (SynCE-dccm) allows remote attackers to execute arbitrary commands via shell metacharacters in a certain string to TCP port 5679.
1Vocera
1Wireless Handset
Apr 23, 2026
Mar 3, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Vocera Communications wireless handsets, when using Protected Extensible Authentication Protocol (PEAP), do not validate server certificates, which allows remote wireless access points to steal hashed passwords and condu...Show more
Vocera Communications wireless handsets, when using Protected Extensible Authentication Protocol (PEAP), do not validate server certificates, which allows remote wireless access points to steal hashed passwords and conduct man-in-the-middle (MITM) attacks.Show less
1Symantec
1Backup Exec For Windows Server
Apr 23, 2026
Feb 29, 2008
N/A· v4
N/A· v3
5.1 MEDIUM· v2
The PVATLCalendar.PVCalendar.1 ActiveX control in pvcalendar.ocx in the scheduler component in the Media Server in Symantec Backup Exec for Windows Server (BEWS) 11d 11.0.6235 and 11.0.7170, and 12.0 12.0.1364, exposes t...Show more
The PVATLCalendar.PVCalendar.1 ActiveX control in pvcalendar.ocx in the scheduler component in the Media Server in Symantec Backup Exec for Windows Server (BEWS) 11d 11.0.6235 and 11.0.7170, and 12.0 12.0.1364, exposes the unsafe Save method, which allows remote attackers to cause a denial of service (browser crash), or create or overwrite arbitrary files, via string values of the (1) _DOWText0, (2) _DOWText1, (3) _DOWText2, (4) _DOWText3, (5) _DOWText4, (6) _DOWText5, (7) _DOWText6, (8) _MonthText0, (9) _MonthText1, (10) _MonthText2, (11) _MonthText3, (12) _MonthText4, (13) _MonthText5, (14) _MonthText6, (15) _MonthText7, (16) _MonthText8, (17) _MonthText9, (18) _MonthText10, and (19) _MonthText11 properties. NOTE: the vendor states "Authenticated user involvement required," but authentication is not needed to attack a client machine that loads this control.Show less
1Opera
1Opera Browser
Apr 23, 2026
Feb 29, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Opera before 9.26 allows user-assisted remote attackers to read arbitrary files by tricking a user into typing the characters of the target filename into a file input.
1Smarty
1Smarty
Apr 23, 2026
Feb 28, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
The modifier.regex_replace.php plugin in Smarty before 2.6.19, as used by Serendipity (S9Y) and other products, allows attackers to call arbitrary PHP functions via templates, related to a '\0' character in a search stri...Show more
The modifier.regex_replace.php plugin in Smarty before 2.6.19, as used by Serendipity (S9Y) and other products, allows attackers to call arbitrary PHP functions via templates, related to a '\0' character in a search string.Show less
1Intervideo
1Windvd Media Center
Apr 23, 2026
Feb 28, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
InterVideo IMC Server (aka IMCSvr.exe) and InterVideo Home Theater (aka IHT.exe) in InterVideo WinDVD Media Center 2.11.15.0 allow remote attackers to cause a denial of service (NULL dereference and application crash) vi...Show more
InterVideo IMC Server (aka IMCSvr.exe) and InterVideo Home Theater (aka IHT.exe) in InterVideo WinDVD Media Center 2.11.15.0 allow remote attackers to cause a denial of service (NULL dereference and application crash) via a crafted packet with two CRLF sequences. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Spyce
1Spyce
Apr 23, 2026
Feb 25, 2008
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Spyce - Python Server Pages (PSP) 2.1.3 allows remote attackers to obtain sensitive information via a direct request for spyce/examples/automaton.spy, which reveals the path in an error message.
1The Sword Project
2Diatheke Front End
Sword
Apr 23, 2026
Feb 25, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
diatheke.pl in The SWORD Project Diatheke 1.5.9 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the range parameter.
1Symantec Veritas
1Storage Foundation
Apr 23, 2026
Feb 21, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Volume Manager Scheduler Service (aka VxSchedService.exe) in Symantec Veritas Storage Foundation 5.0 for Windows allows remote attackers to cause a denial of service (daemon crash or hang) via malformed packets.
1Hitachi
2Sewb3 Mi Platform
Sewb3 Platform
Apr 23, 2026
Feb 21, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Unspecified vulnerability in the SEWB3 messaging service in Hitachi SEWB3/PLATFORM and SEWB3/MI-PLATFORM 01-00 through 02-14-/A allows remote attackers to cause a denial of service (service outage) via "invalid data."
1Apple
1Iphoto
Apr 23, 2026
Feb 19, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
The Digital Photo Access Protocol (DPAP) server for iPhoto 4.0.3 allows remote attackers to cause a denial of service (crash) via a malformed dpap: URI, a different vulnerability than CVE-2008-0043.
1Intermate
1Winipds
Apr 23, 2026
Feb 15, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
ipdsserver.exe in Intermate WinIPDS 3.3 G52-33-021 allows remote attackers to cause a denial of service (CPU consumption) via short packets on TCP port 5001 with the 3, 5, 7, 13, 14, or 15 packet types.
1Cisco
2Session Initiation Protocol (sip) Firmware
Skinny Client Control Protocol (sccp) Firmware
Apr 23, 2026
Feb 15, 2008
N/A· v4
N/A· v3
7.8 HIGH· v2
The HTTP server in Cisco Unified IP Phone 7935 and 7936 running SCCP firmware allows remote attackers to cause a denial of service (reboot) via a crafted HTTP request.
1Cisco
2Session Initiation Protocol (sip) Firmware
Skinny Client Control Protocol (sccp) Firmware
Apr 23, 2026
Feb 15, 2008
N/A· v4
N/A· v3
7.8 HIGH· v2
Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SCCP firmware allows remote attackers to cause a denial of service (reboot) via a long ICMP echo request (ping) packet.
1Microsoft
2Office
Works
Apr 23, 2026
Feb 12, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section header index table information...Show more
Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section header index table information, aka "Microsoft Works File Converter Index Table Vulnerability."Show less
1Microsoft
2Office
Works
Apr 23, 2026
Feb 12, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section length headers, aka "M...Show more
wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section length headers, aka "Microsoft Works File Converter Input Validation Vulnerability."Show less