← Back
CWE-20

12,934 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,934)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Slackware
1Slackware Linux
Nov 21, 2024
Nov 21, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Slackware 13.1, 13.37, 14.0 and 14.1 contain world-writable permissions on the iodbctest and iodbctestw programs within the libiodbc package, which could allow local users to use RPATH information to execute arbitrary co...Show more
Slackware 13.1, 13.37, 14.0 and 14.1 contain world-writable permissions on the iodbctest and iodbctestw programs within the libiodbc package, which could allow local users to use RPATH information to execute arbitrary code with root privileges.Show less
1Slackware
1Slackware Linux
Nov 21, 2024
Nov 21, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Slackware 14.0 and 14.1, and Slackware LLVM 3.0-i486-2 and 3.3-i486-2, contain world-writable permissions on the /tmp directory which could allow remote attackers to execute arbitrary code with root privileges.
3Canonical
DebianMono Project
3Debian Linux
MonoUbuntu Linux
Nov 21, 2024
Nov 21, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
mono 2.10.x ASP.NET Web Form Hash collision DoS
2Debian
Pam Shield Project
2Debian Linux
Pam Shield
Nov 21, 2024
Nov 21, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
pam_shield before 0.9.4: Default configuration does not perform protective action
1Dolibarr
1Dolibarr Erp/crm
Nov 21, 2024
Nov 20, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Dolibarr ERP/CRM 3.3.1 does not properly validate user input in viewimage.php and barcode.lib.php which allows remote attackers to execute arbitrary commands.
4Debian
FedoraprojectMediawiki+1 more
4Debian Linux
Enterprise LinuxFedora+1 more
Nov 21, 2024
Nov 20, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to cause a denial of service (application crash) by sending a specially crafted request.
2Canonical
Gnupg
2Gnupg
Ubuntu Linux
Nov 21, 2024
Nov 20, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
kbx/keybox-search.c in GnuPG before 1.4.19, 2.0.x before 2.0.27, and 2.1.x before 2.1.2 does not properly handle bitwise left-shifts, which allows remote attackers to cause a denial of service (invalid read operation) vi...Show more
kbx/keybox-search.c in GnuPG before 1.4.19, 2.0.x before 2.0.27, and 2.1.x before 2.1.2 does not properly handle bitwise left-shifts, which allows remote attackers to cause a denial of service (invalid read operation) via a crafted keyring file, related to sign extensions and "memcpy with overlapping ranges."Show less
2Debian
Weborf Project
2Debian Linux
Weborf
Nov 21, 2024
Nov 20, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Weborf before 0.12.5 is affected by a Denial of Service (DOS) due to malformed fields in HTTP.
1Status
1Statusnet
Nov 21, 2024
Nov 20, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Unspecified vulnerability in statusnet through 2010 due to the way addslashes are used in SQL string escapes..
2Debian
Smarty
2Debian Linux
Smarty
Nov 21, 2024
Nov 20, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_private_special_variable.php file.
1Cloudfoundry
2Cf Deployment
Routing Release
Jun 17, 2026
Nov 19, 2019
N/A· v4
8.6 HIGH· v3
7.8 HIGH· v2
Cloud Foundry Routing, all versions before 0.193.0, does not properly validate nonce input. A remote unauthenticated malicious user could forge an HTTP route service request using an invalid nonce that will cause the Gor...Show more
Cloud Foundry Routing, all versions before 0.193.0, does not properly validate nonce input. A remote unauthenticated malicious user could forge an HTTP route service request using an invalid nonce that will cause the Gorouter to crash.Show less
1Ktsuss Project
1Ktsuss
Nov 21, 2024
Nov 19, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
ktsuss versions 1.4 and prior spawns the GTK interface to run as root. This can allow a local attacker to escalate privileges to root and use the "GTK_MODULES" environment variable to possibly execute arbitrary code.
2Phusion
Redhat
2Openshift
Passenger
Nov 21, 2024
Nov 19, 2019
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process.
1Falconpl
1Falconpl
Nov 21, 2024
Nov 19, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Falconpl before 0.9.6.9-git20120606 misuses the libcurl API which may allow remote attackers to interfere with security checks.
2Debian
F5
2Debian Linux
Nginx
Nov 21, 2024
Nov 19, 2019
N/A· v4
4.8 MEDIUM· v3
5.8 MEDIUM· v2
nginx http proxy module does not verify peer identity of https origin server which could facilitate man-in-the-middle attack (MITM)
2Openpegasus
Redhat
2Enterprise Linux
Tog Pegasus
Nov 21, 2024
Nov 19, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
tog-Pegasus has a package hash collision DoS vulnerability
3Fedoraproject
RedhatTrusted Boot Project
3Enterprise Linux
FedoraTrusted Boot
Nov 21, 2024
Nov 18, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Trusted Boot (tboot) before 1.8.2 has a 'loader.c' Security Bypass Vulnerability
1Jenkins
1Jenkins
Nov 21, 2024
Nov 18, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers with read access and HTTP access to Jenkins master to insert data and execute arbitrary code.
1Simpleledger
1Slpjs
Jun 17, 2026
Nov 15, 2019
N/A· v4
6.1 MEDIUM· v3
4.9 MEDIUM· v2
A specially crafted Bitcoin script can cause a discrepancy between the specified SLP consensus rules and the validation result of the slpjs npm package. An attacker could create a specially crafted Bitcoin script in orde...Show more
A specially crafted Bitcoin script can cause a discrepancy between the specified SLP consensus rules and the validation result of the slpjs npm package. An attacker could create a specially crafted Bitcoin script in order to cause a hard-fork from the SLP consensus. Affected users can upgrade to any version >= 0.21.4.Show less
1Simpleledger
1Slp Validate
Jun 17, 2026
Nov 15, 2019
N/A· v4
6.1 MEDIUM· v3
4.9 MEDIUM· v2
A specially crafted Bitcoin script can cause a discrepancy between the specified SLP consensus rules and the validation result of the slp-validate@1.0.0 npm package. An attacker could create a specially crafted Bitcoin s...Show more
A specially crafted Bitcoin script can cause a discrepancy between the specified SLP consensus rules and the validation result of the slp-validate@1.0.0 npm package. An attacker could create a specially crafted Bitcoin script in order to cause a hard-fork from the SLP consensus. All versions >1.0.0 have been patched.Show less