← Back
CWE-20

12,894 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,894)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Chrome
Nov 21, 2024
Jan 9, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A missing check for popup window handling in Fullscreen in Google Chrome on macOS prior to 69.0.3497.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
3Debian
GoogleRedhat
5Chrome
Debian LinuxEnterprise Linux Desktop+2 more
Nov 21, 2024
Jan 9, 2019
N/A· v4
9.6 CRITICAL· v3
6.8 MEDIUM· v2
Missing validation in Mojo in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
1Google
1Chrome
Nov 21, 2024
Jan 9, 2019
N/A· v4
9.6 CRITICAL· v3
6.8 MEDIUM· v2
Using an ID that can be controlled by a compromised renderer which allows any frame to overwrite the page_state of any other frame in the same process in Navigation in Google Chrome on Chrome OS prior to 62.0.3202.74 all...Show more
Using an ID that can be controlled by a compromised renderer which allows any frame to overwrite the page_state of any other frame in the same process in Navigation in Google Chrome on Chrome OS prior to 62.0.3202.74 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.Show less
1Mcafee
1Mcafee Web Gateway
Jun 17, 2026
Jan 9, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Improper input validation in the proxy component of McAfee Web Gateway 7.8.2.0 and later allows remote attackers to cause a denial of service via a crafted HTTP request parameter.
2Debian
Wireshark
2Debian Linux
Wireshark
Jun 17, 2026
Jan 8, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the P_MUL dissector could crash. This was addressed in epan/dissectors/packet-p_mul.c by rejecting the invalid sequence number of zero.
2Debian
Wireshark
2Debian Linux
Wireshark
Jun 17, 2026
Jan 8, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In Wireshark 2.6.0 to 2.6.5, the 6LoWPAN dissector could crash. This was addressed in epan/dissectors/packet-6lowpan.c by avoiding use of a TVB before its creation.
1Microsoft
3Windows 10
Windows Server 2016Windows Server 2019
Jun 17, 2026
Jan 8, 2019
N/A· v4
8.4 HIGH· v3
7.7 HIGH· v2
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Windows Hyper-V Remote Code Execution Vulne...Show more
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Windows Hyper-V Remote Code Execution Vulnerability." This affects Windows Server 2016, Windows 10, Windows Server 2019, Windows 10 Servers. This CVE ID is unique from CVE-2019-0550.Show less
1Microsoft
3Windows 10
Windows Server 2016Windows Server 2019
Jun 17, 2026
Jan 8, 2019
N/A· v4
8.4 HIGH· v3
7.7 HIGH· v2
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Windows Hyper-V Remote Code Execution Vulne...Show more
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Windows Hyper-V Remote Code Execution Vulnerability." This affects Windows 10 Servers, Windows 10, Windows Server 2019. This CVE ID is unique from CVE-2019-0551.Show less
1Qualcomm
32Msm8996au Firmware
Sd 410 FirmwareSd 412 Firmware+29 more
Nov 21, 2024
Jan 3, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
QSEE unload attempt on a 3rd party TEE without previously loading results in a data abort in snapdragon automobile and snapdragon mobile in versions MSM8996AU, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429,...Show more
QSEE unload attempt on a 3rd party TEE without previously loading results in a data abort in snapdragon automobile and snapdragon mobile in versions MSM8996AU, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 650/52, SD 712 / SD 710 / SD 670, SD 810, SD 820, SD 820A, SD 835, SDA660, SDM439, SDM630, SDM660, SDX24, Snapdragon_High_Med_2016, SXR1130.Show less
5Canonical
DebianFedoraproject+2 more
11Debian Linux
Enterprise LinuxEnterprise Linux Desktop+8 more
Nov 21, 2024
Jan 3, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by Object.h SIGABRT, because of a wrong return value from PDFDoc::setup) by crafting a PDF file in whi...Show more
In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by Object.h SIGABRT, because of a wrong return value from PDFDoc::setup) by crafting a PDF file in which an xref data structure is mishandled during extractPDFSubtype processing.Show less
2Artifex
Debian
2Debian Linux
Ghostscript
Nov 21, 2024
Jan 2, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In Artifex Ghostscript before 9.26, a carefully crafted PDF file can trigger an extremely long running computation when parsing the file.
1Coreftp
1Core Ftp
Nov 21, 2024
Jan 2, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The server in Core FTP 2.0 build 653 on 32-bit platforms allows remote attackers to cause a denial of service (daemon crash) via a crafted XRMD command.
1Tobesoft
1Xplatform
Nov 21, 2024
Jan 2, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability in the ExtCommon.dll user extension module version 9.2, 9.2.1, 9.2.2 of Xplatform ActiveX could allow attacker to perform a command injection attack. The vulnerability is due to insufficient input validat...Show more
A vulnerability in the ExtCommon.dll user extension module version 9.2, 9.2.1, 9.2.2 of Xplatform ActiveX could allow attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command parameters. An crafted malicious parameters could cause arbitrary command to execute.Show less
4Canonical
DebianFreedesktop+1 more
10Debian Linux
Enterprise LinuxEnterprise Linux Desktop+7 more
Nov 21, 2024
Jan 1, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A reachable Object::dictLookup assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to the lack of a check for the dict data type, as demonstrated by use of the FileSpec class (in FileSpec.cc) in...Show more
A reachable Object::dictLookup assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to the lack of a check for the dict data type, as demonstrated by use of the FileSpec class (in FileSpec.cc) in pdfdetach.Show less
1Facebook
1Nuclide
Jun 17, 2026
Dec 31, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The hhvm-attach deep link handler in Nuclide did not properly sanitize the provided hostname parameter when rendering. As a result, a malicious URL could be used to render HTML and other content inside of the editor's co...Show more
The hhvm-attach deep link handler in Nuclide did not properly sanitize the provided hostname parameter when rendering. As a result, a malicious URL could be used to render HTML and other content inside of the editor's context, which could potentially be chained to lead to code execution. This issue affected Nuclide prior to v0.290.0.Show less
1Proxygen Project
1Proxygen
Jun 17, 2026
Dec 31, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue in the Proxygen handling of HTTP2 parsing of headers/trailers can lead to a denial-of-service attack. This affects Proxygen prior to v2018.12.31.00.
1Facebook
1Proxygen
Jun 17, 2026
Dec 31, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Proxygen fails to validate that a secondary auth manager is set before dereferencing it. That can cause a denial of service issue when parsing a Certificate/CertificateRequest HTTP2 Frame over a fizz (TLS 1.3) transport....Show more
Proxygen fails to validate that a secondary auth manager is set before dereferencing it. That can cause a denial of service issue when parsing a Certificate/CertificateRequest HTTP2 Frame over a fizz (TLS 1.3) transport. This issue affects Proxygen releases starting from v2018.10.29.00 until the fix in v2018.11.19.00.Show less
1Facebook
1Hhvm
Jun 17, 2026
Dec 31, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Malformed h2 frame can cause 'std::out_of_range' exception when parsing priority meta data. This behavior can lead to denial-of-service. This affects all supported versions of HHVM (3.25.2, 3.24.6, and 3.21.10 and belo...Show more
A Malformed h2 frame can cause 'std::out_of_range' exception when parsing priority meta data. This behavior can lead to denial-of-service. This affects all supported versions of HHVM (3.25.2, 3.24.6, and 3.21.10 and below) when using the proxygen server to handle HTTP2 requests.Show less
1Facebook
1Hhvm
Jun 17, 2026
Dec 31, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multipart-file uploads call variables to be improperly registered in the global scope. In cases where variables are not declared explicitly before being used this can lead to unexpected behavior. This affects all support...Show more
Multipart-file uploads call variables to be improperly registered in the global scope. In cases where variables are not declared explicitly before being used this can lead to unexpected behavior. This affects all supported versions of HHVM prior to the patch (3.25.1, 3.24.5, and 3.21.9 and below).Show less
1Cim Project
1Cim
Nov 21, 2024
Dec 30, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
public\install\install.php in CIM 0.9.3 allows remote attackers to reload the product via the public/install/#/step3 URI.