CWE-20
12,904 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,904)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical LinuxNetapp6Cn1610 Firmware Hci Management NodeLinux Kernel+3 moreNov 21, 2024 Mar 21, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An issue where a provided address with access_ok() is not checked was discovered in i915_gem_execbuffer2_ioctl in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the Linux kernel through 4.19.13. A local attacker can craft...Show more |
1Digi 1Transport Lr54 Firmware Nov 21, 2024 Mar 21, 2019 N/A· v4 9.9 CRITICAL· v3 9.0 HIGH· v2 Digi TransPort LR54 4.4.0.26 and possible earlier devices have Improper Input Validation that allows users with 'super' CLI access privileges to bypass a restricted shell and execute arbitrary commands as root. |
1Skyworthdigital 3Dt721 Cb Firmware Dt740 FirmwareDt741 Cb FirmwareNov 21, 2024 Mar 21, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered on Shenzhen Skyworth DT741 Converged Intelligent Terminal (G/EPON+IPTV) SDOTBGN1, DT721-cb SDOTBGN1, and DT741-cb SDOTBGN1 devices. A long password to the Web_passwd function allows remote attacke...Show more |
1Reputeinfosystems 1Repute Arforms Nov 21, 2024 Mar 21, 2019 N/A· v4 7.5 HIGH· v3 6.4 MEDIUM· v2 An issue was discovered in Repute ARForms 3.5.1 and prior. An attacker is able to delete any file on the server with web server privileges by sending a malicious request to admin-ajax.php. |
In yast2-printer up to and including version 4.0.2 the SMB printer settings don't escape characters in passwords properly. If a password with backticks or simliar characters is supplied this allows for executing code as...Show more |
1Ibm 1Rational Collaborative Lifecycle Management Nov 21, 2024 Mar 14, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 through 6.0.6) is vulnerable to HTTP header injection, caused by improper validation of input. By persuading a victim to visit a specially-crafted...Show more |
Insufficient input validation in Kernel Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064...Show more |
Insufficient input validation in Kernel Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064...Show more |
Insufficient input validation in Kernel Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064...Show more |
Insufficient input validation in Kernel Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064...Show more |
Insufficient input validation in Kernel Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064...Show more |
Insufficient input validation in User Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (a...Show more |
1Intel 1Server Platform Services Firmware Nov 21, 2024 Mar 14, 2019 N/A· v4 6.0 MEDIUM· v3 2.1 LOW· v2 Insufficient input validation in Intel(R) Server Platform Services HECI subsystem before version SPS_E5_04.00.04.393.0 may allow privileged user to potentially cause a denial of service via local access. |
1Intel 1Converged Security Management Engine Firmware Nov 21, 2024 Mar 14, 2019 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 Insufficient input validation in Intel(R) AMT in Intel(R) CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20 may allow a privileged user to potentially execute arbitrary code via local access. |
1Intel 2Converged Security Management Engine Firmware Trusted Execution Engine FirmwareNov 21, 2024 Mar 14, 2019 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 Insufficient input validation in Intel(r) CSME subsystem before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel(r) TXE before 3.1.60 or 4.0.10 may allow a privileged user to potentially enable an escalation of p...Show more |
1Intel 2Converged Security Management Engine Firmware Trusted Execution Engine FirmwareNov 21, 2024 Mar 14, 2019 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 Insufficient input validation in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel TXE before version 3.1.60 or 4.0.10 may allow an unauthenticated user to potentially modify data via physical ac...Show more |
1Intel 1Active Management Technology Firmware Nov 21, 2024 Mar 14, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Insufficient input validation in Intel(R) Active Management Technology (Intel(R) AMT) before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20 may allow an unauthenticated user to potentially cause a denial of service via n...Show more |
1Intel 1Converged Security Management Engine Firmware Nov 21, 2024 Mar 14, 2019 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 Insufficient input validation in Intel(R) AMT in Intel(R) CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20 may allow an unauthenticated user to potentially execute arbitrary code via physical access. |
An issue was discovered in Open Ticket Request System (OTRS) 5.0.31 and 6.0.13. Users updating to 6.0.13 (also patchlevel updates) or 5.0.31 (only major updates) will experience data loss in their agent preferences table...Show more |
1Sap 3Advanced Business Application Programming Platform Advanced Business Application Programming ServerSap KernelJun 17, 2026 Mar 12, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 ABAP Server (used in NetWeaver and Suite/ERP) and ABAP Platform does not sufficiently validate an XML document accepted from an untrusted source, leading to an XML External Entity (XEE) vulnerability. Fixed in Kernel 7.2...Show more |