CWE-20
12,934 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,934)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Slackware 13.1, 13.37, 14.0 and 14.1 contain world-writable permissions on the iodbctest and iodbctestw programs within the libiodbc package, which could allow local users to use RPATH information to execute arbitrary co...Show more |
Slackware 14.0 and 14.1, and Slackware LLVM 3.0-i486-2 and 3.3-i486-2, contain world-writable permissions on the /tmp directory which could allow remote attackers to execute arbitrary code with root privileges. |
3Canonical DebianMono Project3Debian Linux MonoUbuntu LinuxNov 21, 2024 Nov 21, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 mono 2.10.x ASP.NET Web Form Hash collision DoS |
2Debian Pam Shield Project2Debian Linux Pam ShieldNov 21, 2024 Nov 21, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 pam_shield before 0.9.4: Default configuration does not perform protective action |
Dolibarr ERP/CRM 3.3.1 does not properly validate user input in viewimage.php and barcode.lib.php which allows remote attackers to execute arbitrary commands. |
4Debian FedoraprojectMediawiki+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Nov 20, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to cause a denial of service (application crash) by sending a specially crafted request. |
2Canonical Gnupg2Gnupg Ubuntu LinuxNov 21, 2024 Nov 20, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 kbx/keybox-search.c in GnuPG before 1.4.19, 2.0.x before 2.0.27, and 2.1.x before 2.1.2 does not properly handle bitwise left-shifts, which allows remote attackers to cause a denial of service (invalid read operation) vi...Show more |
2Debian Weborf Project2Debian Linux WeborfNov 21, 2024 Nov 20, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Weborf before 0.12.5 is affected by a Denial of Service (DOS) due to malformed fields in HTTP. |
Unspecified vulnerability in statusnet through 2010 due to the way addslashes are used in SQL string escapes.. |
2Debian Smarty2Debian Linux SmartyNov 21, 2024 Nov 20, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_private_special_variable.php file. |
1Cloudfoundry 2Cf Deployment Routing ReleaseJun 17, 2026 Nov 19, 2019 N/A· v4 8.6 HIGH· v3 7.8 HIGH· v2 Cloud Foundry Routing, all versions before 0.193.0, does not properly validate nonce input. A remote unauthenticated malicious user could forge an HTTP route service request using an invalid nonce that will cause the Gor...Show more |
ktsuss versions 1.4 and prior spawns the GTK interface to run as root. This can allow a local attacker to escalate privileges to root and use the "GTK_MODULES" environment variable to possibly execute arbitrary code. |
2Phusion Redhat2Openshift PassengerNov 21, 2024 Nov 19, 2019 N/A· v4 7.5 HIGH· v3 6.4 MEDIUM· v2 RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process. |
Falconpl before 0.9.6.9-git20120606 misuses the libcurl API which may allow remote attackers to interfere with security checks. |
nginx http proxy module does not verify peer identity of https origin server which could facilitate man-in-the-middle attack (MITM) |
2Openpegasus Redhat2Enterprise Linux Tog PegasusNov 21, 2024 Nov 19, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 tog-Pegasus has a package hash collision DoS vulnerability |
3Fedoraproject RedhatTrusted Boot Project3Enterprise Linux FedoraTrusted BootNov 21, 2024 Nov 18, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Trusted Boot (tboot) before 1.8.2 has a 'loader.c' Security Bypass Vulnerability |
Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers with read access and HTTP access to Jenkins master to insert data and execute arbitrary code. |
A specially crafted Bitcoin script can cause a discrepancy between the specified SLP consensus rules and the validation result of the slpjs npm package. An attacker could create a specially crafted Bitcoin script in orde...Show more |
A specially crafted Bitcoin script can cause a discrepancy between the specified SLP consensus rules and the validation result of the slp-validate@1.0.0 npm package. An attacker could create a specially crafted Bitcoin s...Show more |