CWE-20
12,947 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,947)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
AMD Graphics Driver for Windows 10, amdfender.sys may improperly handle input validation on InputBuffer which may result in a denial of service (DoS). |
Improper parameters validation in some trusted applications of the PSP contained in the AMD Graphics Driver may allow a local attacker to bypass security restrictions and achieve arbitrary code execution . |
1Dell 283Alienware 13 R3 Firmware Alienware 15 R3 FirmwareAlienware 15 R4 Firmware+280 moreJun 17, 2026 Nov 12, 2021 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM. |
1Dell 283Alienware 13 R3 Firmware Alienware 15 R3 FirmwareAlienware 15 R4 Firmware+280 moreJun 17, 2026 Nov 12, 2021 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM. |
1Dell 283Alienware 13 R3 Firmware Alienware 15 R3 FirmwareAlienware 15 R4 Firmware+280 moreJun 17, 2026 Nov 12, 2021 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM. |
1Lenovo 29Thinkpad 11e 3rd Gen Firmware Thinkpad 11e 4th Gen Celeron FirmwareThinkpad 11e 4th Gen I3 Firmware+26 moreJun 17, 2026 Nov 12, 2021 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A potential vulnerability in the SMI function to access EEPROM in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code. |
1Lenovo 133Ideapad S940 14iwl Firmware Ideapad Yoga S940 14iwl FirmwareThinkpad 10 Firmware+130 moreJun 17, 2026 Nov 12, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A potential vulnerability in the SMI callback function used in CSME configuration of some Lenovo Notebook and ThinkPad systems could be used to leak out data out of the SMRAM range. |
1Lenovo 20Thinkcentre E93 Firmware Thinkcentre M4500q FirmwareThinkcentre M600 Firmware+17 moreJun 17, 2026 Nov 12, 2021 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A potential vulnerability in the SMI callback function that saves and restore boot script tables used for resuming from sleep state in some ThinkCentre and ThinkStation models may allow an attacker with local access and...Show more |
1Lenovo 133Ideapad S940 14iwl Firmware Ideapad Yoga S940 14iwl FirmwareThinkpad 10 Firmware+130 moreJun 17, 2026 Nov 12, 2021 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A potential vulnerability in the SMI callback function used to access flash device in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code. |
1Ibm 2Security Guardium Key Lifecycle Manager Security Key Lifecycle ManagerJun 17, 2026 Nov 12, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and corre...Show more |
1Ibm 2Security Guardium Key Lifecycle Manager Security Key Lifecycle ManagerJun 17, 2026 Nov 12, 2021 N/A· v4 2.7 LOW· v3 4.0 MEDIUM· v2 IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and corre...Show more |
1Ibm 2Security Guardium Key Lifecycle Manager Security Key Lifecycle ManagerJun 17, 2026 Nov 12, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and corre...Show more |
1Qualcomm 163Apq8009 Firmware Apq8009w FirmwareApq8017 Firmware+160 moreJun 17, 2026 Nov 12, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Possible buffer overflow due to improper input validation in factory calibration and test DIAG command in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,...Show more |
1Zoom 5Zoom On Premise Meeting Connector Controller Zoom On Premise Meeting Connector MmrZoom On Premise Recording Connector+2 moreJun 17, 2026 Nov 11, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 The network proxy page on the web portal for the Zoom On-Premise Meeting Connector Controller before version 4.6.365.20210703, Zoom On-Premise Meeting Connector MMR before version 4.6.365.20210703, Zoom On-Premise Record...Show more |
2Cloudflare Debian2Debian Linux OctorpkiJun 17, 2026 Nov 11, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 If the ROA that a repository returns contains too many bits for the IP address then OctoRPKI will crash. |
2Cloudflare Debian2Debian Linux OctorpkiJun 17, 2026 Nov 11, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 OctoRPKI crashes when encountering a repository that returns an invalid ROA (just an encoded NUL (\0) character). |
2Cloudflare Debian2Debian Linux OctorpkiJun 17, 2026 Nov 11, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cron.daily/evil.roa), which would then be written to disk outside the bas...Show more |
2Oracle Pypa4Agile Plm Communications Cloud Native Core Network Function Cloud Native EnvironmentCommunications Cloud Native Core Policy+1 moreJun 17, 2026 Nov 10, 2021 N/A· v4 5.7 MEDIUM· v3 3.5 LOW· v2 A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vul...Show more |
1Siemens 1Simatic Rtls Locating Manager Jun 17, 2026 Nov 9, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.12). The affected application does not properly handle the import of large configuration files. A local attacker could import a spec...Show more |
3Fedoraproject GolangOracle3Fedora GoTimesten In Memory DatabaseJun 17, 2026 Nov 8, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Go before 1.16.10 and 1.17.x before 1.17.3 allows an archive/zip Reader.Open panic via a crafted ZIP archive containing an invalid name or an empty filename field. |