← Back
CWE-20

12,894 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,894)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Apple
CanonicalWebkit
8Icloud
Iphone OsItunes+5 more
Nov 21, 2024
Jan 11, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed wit...Show more
In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.Show less
3Apple
CanonicalWebkitgtk
8Icloud
Iphone OsItunes+5 more
Nov 21, 2024
Jan 11, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed wit...Show more
In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.Show less
3Apple
CanonicalWebkitgtk
8Icloud
Iphone OsItunes+5 more
Nov 21, 2024
Jan 11, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed wit...Show more
In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.Show less
1Apple
1Iphone Os
Nov 21, 2024
Jan 11, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In iOS before 11.2, an inconsistent user interface issue was addressed through improved state management.
1Cisco
1Asyncos
Nov 21, 2024
Jan 10, 2019
N/A· v4
8.6 HIGH· v3
7.8 HIGH· v2
A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to cause the CPU utilization to increase to 100 p...Show more
A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to cause the CPU utilization to increase to 100 percent, causing a denial of service (DoS) condition on an affected device. The vulnerability is due to improper filtering of email messages that contain references to whitelisted URLs. An attacker could exploit this vulnerability by sending a malicious email message that contains a large number of whitelisted URLs. A successful exploit could allow the attacker to cause a sustained DoS condition that could force the affected device to stop scanning and forwarding email messages.Show less
1Winscp
1Winscp
Nov 21, 2024
Jan 10, 2019
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
In WinSCP before 5.14 beta, due to missing validation, the scp implementation would accept arbitrary files sent by the server, potentially overwriting unrelated files. This affects TSCPFileSystem::SCPSink in core/ScpFile...Show more
In WinSCP before 5.14 beta, due to missing validation, the scp implementation would accept arbitrary files sent by the server, potentially overwriting unrelated files. This affects TSCPFileSystem::SCPSink in core/ScpFileSystem.cpp.Show less
1Redhat
1Modulemd
Nov 21, 2024
Jan 10, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
modulemd 1.3.1 and earlier uses an unsafe function for processing externally provided data, leading to remote code execution.
1Intel
1Optane Ssd Dc P4800x Firmware
Nov 21, 2024
Jan 10, 2019
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Firmware update routine in bootloader for Intel(R) Optane(TM) SSD DC P4800X before version E2010435 may allow a privileged user to potentially enable a denial of service via local access.
1Intel
1Optane Ssd Dc P4800x Firmware
Nov 21, 2024
Jan 10, 2019
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Insufficient write protection in firmware for Intel(R) Optane(TM) SSD DC P4800X before version E2010435 may allow a privileged user to potentially enable a denial of service via local access.
1Cisco
1Email Security Appliance Firmware
Nov 21, 2024
Jan 10, 2019
N/A· v4
8.6 HIGH· v3
7.8 HIGH· v2
A vulnerability in the Secure/Multipurpose Internet Mail Extensions (S/MIME) Decryption and Verification or S/MIME Public Key Harvesting features of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could a...Show more
A vulnerability in the Secure/Multipurpose Internet Mail Extensions (S/MIME) Decryption and Verification or S/MIME Public Key Harvesting features of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause an affected device to corrupt system memory. A successful exploit could cause the filtering process to unexpectedly reload, resulting in a denial of service (DoS) condition on the device. The vulnerability is due to improper input validation of S/MIME-signed emails. An attacker could exploit this vulnerability by sending a malicious S/MIME-signed email through a targeted device. If Decryption and Verification or Public Key Harvesting is configured, the filtering process could crash due to memory corruption and restart, resulting in a DoS condition. The software could then resume processing the same S/MIME-signed email, causing the filtering process to crash and restart again. A successful exploit could allow the attacker to cause a permanent DoS condition. This vulnerability may require manual intervention to recover the ESA.Show less
1Macpaw
1Cleanmymac X
Nov 21, 2024
Jan 10, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. An attacker with local access could exploit this vulnerability to modify t...Show more
An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. An attacker with local access could exploit this vulnerability to modify the file system as root.Show less
1Macpaw
1Cleanmymac X
Nov 21, 2024
Jan 10, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An exploitable denial-of-service vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. A user with local access can use this vulnerability to terminate a privileged...Show more
An exploitable denial-of-service vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. A user with local access can use this vulnerability to terminate a privileged helper application. An attacker would need local access to the machine for a successful exploit.Show less
1Macpaw
1Cleanmymac X
Nov 21, 2024
Jan 10, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. An attacker with local access could exploit this vulnerability to modify t...Show more
An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. An attacker with local access could exploit this vulnerability to modify the file system as root.Show less
1Macpaw
1Cleanmymac X
Nov 21, 2024
Jan 10, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. An attacker with local access could exploit this vulnerability to modify t...Show more
An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. An attacker with local access could exploit this vulnerability to modify the file system as root.Show less
1Macpaw
1Cleanmymac X
Nov 21, 2024
Jan 10, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
An exploitable privilege escalation vulnerability exists in the Clean My Mac X, version 4.04, helper service due to improper input validation. A user with local access can use this vulnerability to modify the file system...Show more
An exploitable privilege escalation vulnerability exists in the Clean My Mac X, version 4.04, helper service due to improper input validation. A user with local access can use this vulnerability to modify the file system as root. An attacker would need local access to the machine for a successful exploit.Show less
1Macpaw
1Cleanmymac X
Nov 21, 2024
Jan 10, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. An attacker with local access could exploit this vulnerability to modify t...Show more
An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. An attacker with local access could exploit this vulnerability to modify the file system as root.Show less
1Macpaw
1Cleanmymac X
Nov 21, 2024
Jan 10, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. An attacker with local access could exploit this vulnerability to modify t...Show more
An exploitable privilege escalation vulnerability exists in the helper service of Clean My Mac X, version 4.04, due to improper input validation. An attacker with local access could exploit this vulnerability to modify the file system as root.Show less
1Macpaw
1Cleanmymac X
Nov 21, 2024
Jan 10, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The CleanMyMac X software contains an exploitable privilege escalation vulnerability due to improper input validation. An attacker with local access can use this vulnerability to modify the file system as root.
1Macpaw
1Cleanmymac X
Nov 21, 2024
Jan 10, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The CleanMyMac X software contains an exploitable privilege escalation vulnerability due to improper input validation. An attacker with local access could use this vulnerability to modify the running kernel extensions on...Show more
The CleanMyMac X software contains an exploitable privilege escalation vulnerability due to improper input validation. An attacker with local access could use this vulnerability to modify the running kernel extensions on the system.Show less
1Macpaw
1Cleanmymac X
Nov 21, 2024
Jan 10, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
The CleanMyMac X software contains an exploitable privilege escalation vulnerability that exists due to improper input validation. An attacker with local access could use this vulnerability to modify the file system as r...Show more
The CleanMyMac X software contains an exploitable privilege escalation vulnerability that exists due to improper input validation. An attacker with local access could use this vulnerability to modify the file system as root.Show less