CWE-20
12,892 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,892)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
python-kdcproxy before 0.3.2 allows remote attackers to cause a denial of service via a large POST request. |
Improper input validation leads to buffer overwrite in the WLAN function that handles WLAN roam buffer in Snapdragon Mobile in version SD 845. |
1Qualcomm 3Sd 845 Firmware Sd 850 FirmwareSda660 FirmwareNov 21, 2024 Oct 29, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Improper input validation leads to buffer overwrite in the WLAN function that handles WMI commands in Snapdragon Mobile in version SD 845, SD 850, SDA660 |
1Qualcomm 2Sd 845 Firmware Sd 850 FirmwareNov 21, 2024 Oct 26, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Unapproved TrustZone applications can be loaded and executed in Snapdragon Mobile in version SD 845, SD 850 |
Splunk Enterprise 6.2.x before 6.2.14, 6.3.x before 6.3.10, 6.4.x before 6.4.7, and 6.5.x before 6.5.3; and Splunk Light before 6.6.0 allow remote attackers to cause a denial of service via a crafted HTTP request. |
Splunkd in Splunk Enterprise 6.2.x before 6.2.14 6.3.x before 6.3.11, and 6.4.x before 6.4.8; and Splunk Light before 6.5.0 allow remote attackers to cause a denial of service via a malformed HTTP request. |
Advantech WebAccess 8.3.1 and earlier has a .dll component that is susceptible to external control of file name or path vulnerability, which may allow an arbitrary file deletion when processing. |
2Alibaba Pippo2Fastjson PippoNov 21, 2024 Oct 23, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary code via a crafted JSON request, as demonstrated by a crafted rmi:// URI i...Show more |
1Qualcomm 21Msm8909w Firmware Msm8996au FirmwareSd 205 Firmware+18 moreNov 21, 2024 Oct 23, 2018 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 Secure app running in non secure space can restart TZ by calling Widevine app API repeatedly in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in versions MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 410/1...Show more |
Lack of an authentication mechanism in KERUI Wifi Endoscope Camera (YPC99) allows an attacker to watch or block the camera stream. The RTSP server on port 7070 accepts the command STOP to stop streaming, and the command...Show more |
2Debian Teeworlds2Debian Linux TeeworldsNov 21, 2024 Oct 20, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Teeworlds before 0.6.5, connection packets could be forged. There was no challenge-response involved in the connection build up. A remote attacker could send connection packets from a spoofed IP address and occupy all...Show more |
4Canonical DebianMozilla+1 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Server+7 moreNov 25, 2025 Oct 18, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability can occur when capturing a media stream when the media source type is changed as the capture is occurring. This can result in stream data being cast to the wrong type causing a potentially exploitable cra...Show more |
4Canonical DebianMozilla+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreNov 25, 2025 Oct 18, 2018 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A vulnerability where the JavaScript JIT compiler inlines Array.prototype.push with multiple arguments that results in the stack pointer being off by 8 bytes after a bailout. This leaks a memory address to the calling fu...Show more |
4Canonical DebianMozilla+1 more11Debian Linux Enterprise Linux DesktopEnterprise Linux Server+8 moreNov 21, 2024 Oct 18, 2018 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data stored in the local cache in the user profile directory. This issue is only exploitable in combination with another vulnerabi...Show more |
The displayed addressbar URL can be spoofed on Firefox for Android using a javascript: URI in concert with JavaScript to insert text before the loaded domain name, scrolling the loaded domain out of view to the right. Th...Show more |
3Canonical DebianMozilla4Debian Linux FirefoxThunderbird+1 moreNov 25, 2025 Oct 18, 2018 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 In the previous mitigations for Spectre, the resolution or precision of various methods was reduced to counteract the ability to measure precise time intervals. In that work PerformanceNavigationTiming was not adjusted b...Show more |
1Cisco 1Wireless Lan Controller Software Nov 21, 2024 Oct 17, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol component of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause a denial of s...Show more |
A vulnerability in the Precision Time Protocol (PTP) feature of Cisco Nexus 5500, 5600, and 6000 Series Switches running Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (...Show more |
A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco NX-OS Software could allow an authenticated, remote attacker to cause the SNMP application of an affected device to restart...Show more |
1Cisco 1Wireless Lan Controller Software Nov 21, 2024 Oct 17, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability in the web-based interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to view system information that under normal circumstances should be prohibited....Show more |