← Back
CWE-20

12,815 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,815)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
4Exchange Server
Sql ServerWindows 2000+1 more
Apr 16, 2026
Sep 20, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) Windows NT 4.0, and (4) Windows 2000 allow remote attackers to cause a denial of service vi...Show more
Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) Windows NT 4.0, and (4) Windows 2000 allow remote attackers to cause a denial of service via malformed inputs.Show less
1Cisco
1Catalyst 2900
Apr 16, 2026
Aug 14, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Cisco Catalyst 2900XL switch allows a remote attacker to create a denial of service via an empty UDP packet sent to port 161 (SNMP) when SNMP is disabled.
1Cisco
6Vpn 3000 Concentrator
Vpn 3005 ConcentratorVpn 3015 Concentrator+3 more
Apr 16, 2026
Jun 18, 2001
N/A· v4
N/A· v3
7.1 HIGH· v2
Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via a flood of invalid login requests to (1) the SSL service, or (2) the telnet service, which do not properly disco...Show more
Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via a flood of invalid login requests to (1) the SSL service, or (2) the telnet service, which do not properly disconnect the user after several failed login attempts.Show less
1Microsoft
1Internet Explorer
Apr 16, 2026
May 13, 2000
N/A· v4
N/A· v3
7.5 HIGH· v2
The Microsoft Active Movie ActiveX Control in Internet Explorer 5 does not restrict which file types can be downloaded, which allows an attacker to download any type of file to a user's system by encoding it within an em...Show more
The Microsoft Active Movie ActiveX Control in Internet Explorer 5 does not restrict which file types can be downloaded, which allows an attacker to download any type of file to a user's system by encoding it within an email message or news post.Show less
1Cisco
1Ios
Apr 16, 2026
Apr 26, 2000
N/A· v4
N/A· v3
7.1 HIGH· v2
The IOS HTTP service in Cisco routers and switches running IOS 11.1 through 12.1 allows remote attackers to cause a denial of service by requesting a URL that contains a %% string.
1Microsoft
2Internet Information Server
Internet Information Services
Apr 16, 2026
Apr 12, 2000
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IIS 4.0 and 5.0 allows remote attackers to cause a denial of service by sending many URLs with a large number of escaped characters, aka the "Myriad Escaped Characters" Vulnerability.
3Bsdi
FreebsdOpenbsd
3Bsd Os
FreebsdOpenbsd
Apr 16, 2026
Dec 30, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
ip_input.c in BSD-derived TCP/IP implementations allows remote attackers to cause a denial of service (crash or hang) via crafted packets.
1Microsoft
1Windows Nt
Apr 16, 2026
Dec 16, 1999
N/A· v4
N/A· v3
7.8 HIGH· v2
Windows NT Local Security Authority (LSA) allows remote attackers to cause a denial of service via malformed arguments to the LsaLookupSids function which looks up the SID, aka "Malformed Security Identifier Request."
1Oracle
1Web Listener
Apr 16, 2026
Nov 25, 1999
N/A· v4
N/A· v3
7.5 HIGH· v2
Oracle Web Listener 2.1 allows remote attackers to bypass access restrictions by replacing a character in the URL with its HTTP-encoded (hex) equivalent.
1Microsoft
1Sql Server
Apr 16, 2026
Nov 19, 1999
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Microsoft SQL 7.0 server allows a remote attacker to cause a denial of service via a malformed TDS packet.
1Microsoft
3Commercial Internet System
Internet Information ServerSite Server
Apr 16, 2026
Aug 11, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Jul 20, 1999
N/A· v4
N/A· v3
7.8 HIGH· v2
Denial of service in Windows NT Local Security Authority (LSA) through a malformed LSA request.
1Microsoft
4Windows 2000
Windows 95Windows 98+1 more
Apr 16, 2026
Jul 3, 1999
N/A· v4
N/A· v3
7.8 HIGH· v2
Denial of service in various Windows systems via malformed, fragmented IGMP packets.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Jun 30, 1999
N/A· v4
N/A· v3
7.8 HIGH· v2
An attacker can conduct a denial of service in Windows NT by executing a program with a malformed file image header.
2Microware
Novell
2Netware
Os 9
Apr 16, 2026
Jan 1, 1997
N/A· v4
N/A· v3
5.0 MEDIUM· v2
ICMP redirect messages may crash or lock up a host.