CWE-20
12,934 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,934)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user input |
Cryptocat before 2.0.22 Link Markup Decorator HTML Handling Weakness |
Cryptocat before 2.0.22 has Remote Denial of Service via username |
Insecure temporary file vulnerability in Redis 2.6 related to /tmp/redis.ds. |
Insecure temporary file vulnerability in Redis before 2.6 related to /tmp/redis-%p.vm. |
cartridges/openshift-origin-cartridge-mongodb-2.2/info/bin/dump.sh in OpenShift does not properly create files in /tmp. |
2Debian Glpi Project2Debian Linux GlpiNov 21, 2024 Nov 1, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 GLPI 0.83.7 has Local File Inclusion in common.tabs.php. |
3Fedoraproject RedhatSensiolabs3Enterprise Linux FedoraSymfonyNov 21, 2024 Nov 1, 2019 N/A· v4 8.1 HIGH· v3 4.9 MEDIUM· v2 php-symfony2-Validator has loss of information during serialization |
4Debian GnomeOpensuse+1 more4Debian Linux Enterprise LinuxEvince+1 moreNov 21, 2024 Nov 1, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 evince is missing a check on number of pages which can lead to a segmentation fault |
1Honeywell 25H2w2gr1 Firmware H2w2pc1m FirmwareH2w2per3 Firmware+22 moreJun 17, 2026 Oct 31, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Honeywell equIP series IP cameras Multiple equIP Series Cameras, A vulnerability exists in the affected products where a specially crafted HTTP packet request could result in a denial of service. |
Chicken before 4.8.0 is susceptible to algorithmic complexity attacks related to hash table collisions. |
2Call Cc Debian2Chicken Debian LinuxNov 21, 2024 Oct 31, 2019 N/A· v4 6.5 MEDIUM· v3 5.0 MEDIUM· v2 Chicken before 4.8.0 does not properly handle NUL bytes in certain strings, which allows an attacker to conduct "poisoned NUL byte attack." |
2Fedoraproject Mantisbt2Fedora MantisbtNov 21, 2024 Oct 31, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 MantisBT 1.2.12 before 1.2.15 allows authenticated users to by the workflow restriction and close issues. |
2Baseurl Debian2Debian Linux YumNov 21, 2024 Oct 31, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 yum does not properly handle bad metadata, which allows an attacker to cause a denial of service and possibly have other unspecified impact via a Trojan horse file in the metadata of a remote repository. |
2Debian Mumble2Debian Linux MumbleNov 21, 2024 Oct 31, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Mumble: murmur-server has DoS due to malformed client query |
2Debian Transmissionbt2Debian Linux TransmissionNov 21, 2024 Oct 30, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Transmission before 1.92 allows an attacker to cause a denial of service (crash) or possibly have other unspecified impact via a large number of tr arguments in a magnet link. |
rpcbind 0.2.0 does not properly validate (1) /tmp/portmap.xdr and (2) /tmp/rpcbind.xdr, which can be created by an attacker before the daemon is started. |
SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers to execute arbitrary PHP code. |
Mapserver 5.2, 5.4 and 5.6 before 5.6.5-2 improperly validates symbol index values during Mapfile parsing. |
qtparted has insecure library loading which may allow arbitrary code execution |