CWE-20
12,815 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,815)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 4Exchange Server Sql ServerWindows 2000+1 moreApr 16, 2026 Sep 20, 2001 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) Windows NT 4.0, and (4) Windows 2000 allow remote attackers to cause a denial of service vi...Show more |
Cisco Catalyst 2900XL switch allows a remote attacker to create a denial of service via an empty UDP packet sent to port 161 (SNMP) when SNMP is disabled. |
1Cisco 6Vpn 3000 Concentrator Vpn 3005 ConcentratorVpn 3015 Concentrator+3 moreApr 16, 2026 Jun 18, 2001 N/A· v4 N/A· v3 7.1 HIGH· v2 Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via a flood of invalid login requests to (1) the SSL service, or (2) the telnet service, which do not properly disco...Show more |
The Microsoft Active Movie ActiveX Control in Internet Explorer 5 does not restrict which file types can be downloaded, which allows an attacker to download any type of file to a user's system by encoding it within an em...Show more |
The IOS HTTP service in Cisco routers and switches running IOS 11.1 through 12.1 allows remote attackers to cause a denial of service by requesting a URL that contains a %% string. |
1Microsoft 2Internet Information Server Internet Information ServicesApr 16, 2026 Apr 12, 2000 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IIS 4.0 and 5.0 allows remote attackers to cause a denial of service by sending many URLs with a large number of escaped characters, aka the "Myriad Escaped Characters" Vulnerability. |
3Bsdi FreebsdOpenbsd3Bsd Os FreebsdOpenbsdApr 16, 2026 Dec 30, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 ip_input.c in BSD-derived TCP/IP implementations allows remote attackers to cause a denial of service (crash or hang) via crafted packets. |
Windows NT Local Security Authority (LSA) allows remote attackers to cause a denial of service via malformed arguments to the LsaLookupSids function which looks up the SID, aka "Malformed Security Identifier Request." |
Oracle Web Listener 2.1 allows remote attackers to bypass access restrictions by replacing a character in the URL with its HTTP-encoded (hex) equivalent. |
Microsoft SQL 7.0 server allows a remote attacker to cause a denial of service via a malformed TDS packet. |
1Microsoft 3Commercial Internet System Internet Information ServerSite ServerApr 16, 2026 Aug 11, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers. |
Denial of service in Windows NT Local Security Authority (LSA) through a malformed LSA request. |
1Microsoft 4Windows 2000 Windows 95Windows 98+1 moreApr 16, 2026 Jul 3, 1999 N/A· v4 N/A· v3 7.8 HIGH· v2 Denial of service in various Windows systems via malformed, fragmented IGMP packets. |
An attacker can conduct a denial of service in Windows NT by executing a program with a malformed file image header. |
ICMP redirect messages may crash or lock up a host. |