CWE-20
12,710 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,710)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 2Internet Information Server Internet Information ServicesApr 16, 2026 Apr 12, 2000 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IIS 4.0 and 5.0 allows remote attackers to cause a denial of service by sending many URLs with a large number of escaped characters, aka the "Myriad Escaped Characters" Vulnerability. |
3Bsdi FreebsdOpenbsd3Bsd Os FreebsdOpenbsdApr 16, 2026 Dec 30, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 ip_input.c in BSD-derived TCP/IP implementations allows remote attackers to cause a denial of service (crash or hang) via crafted packets. |
Windows NT Local Security Authority (LSA) allows remote attackers to cause a denial of service via malformed arguments to the LsaLookupSids function which looks up the SID, aka "Malformed Security Identifier Request." |
Oracle Web Listener 2.1 allows remote attackers to bypass access restrictions by replacing a character in the URL with its HTTP-encoded (hex) equivalent. |
Microsoft SQL 7.0 server allows a remote attacker to cause a denial of service via a malformed TDS packet. |
1Microsoft 3Commercial Internet System Internet Information ServerSite ServerApr 16, 2026 Aug 11, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers. |
Denial of service in Windows NT Local Security Authority (LSA) through a malformed LSA request. |
1Microsoft 4Windows 2000 Windows 95Windows 98+1 moreApr 16, 2026 Jul 3, 1999 N/A· v4 N/A· v3 7.8 HIGH· v2 Denial of service in various Windows systems via malformed, fragmented IGMP packets. |
An attacker can conduct a denial of service in Windows NT by executing a program with a malformed file image header. |
ICMP redirect messages may crash or lock up a host. |