CWE-20
12,892 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,892)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In Bro through 2.5.5, there is a DoS in IRC protocol names command parsing in analyzer/protocol/irc/IRC.cc. |
When parsing a malformed JSON payload, libprocess in Apache Mesos versions 1.4.0 to 1.5.0 might crash due to an uncaught exception. Parsing chunked HTTP requests with trailers can lead to a libprocess crash too because o...Show more |
1F5 1Big Ip Access Policy Manager Jun 17, 2026 Sep 13, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 On BIG-IP APM 11.6.0-11.6.3.1, 12.1.0-12.1.3.3, 13.0.0, and 13.1.0-13.1.0.3, APMD may core when processing SAML Assertion or response containing certain elements. |
On F5 WebSafe Alert Server 1.0.0-4.2.6, a malicious, authenticated user can execute code on the alert server by using a maliciously crafted payload. |
A security feature bypass vulnerability exists when Lync for Mac 2011 fails to properly sanitize specially crafted messages, aka "Lync for Mac 2011 Security Feature Bypass Vulnerability." This affects Microsoft Lync. |
1Microsoft 5Windows 10 Windows 8.1Windows Rt 8.1+2 moreJun 17, 2026 Sep 13, 2018 N/A· v4 8.4 HIGH· v3 7.7 HIGH· v2 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Windows Hyper-V Remote Code Execution Vulne...Show more |
1Microsoft 4Windows 10 Windows 8.1Windows Server+1 moreJun 17, 2026 Sep 13, 2018 N/A· v4 6.8 MEDIUM· v3 6.8 MEDIUM· v2 A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka "Windows Hyper-V Denial of Service...Show more |
1Microsoft 2Windows 10 Windows Server 2016Jun 17, 2026 Sep 13, 2018 N/A· v4 6.2 MEDIUM· v3 5.5 MEDIUM· v2 A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka "Windows Hyper-V Denial of Service...Show more |
1Microsoft 2Windows 10 Windows Server 2016Jun 17, 2026 Sep 13, 2018 N/A· v4 6.2 MEDIUM· v3 5.5 MEDIUM· v2 A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka "Windows Hyper-V Denial of Service...Show more |
1Microsoft 6Windows 10 Windows 7Windows 8.1+3 moreJun 17, 2026 Sep 13, 2018 N/A· v4 5.4 MEDIUM· v3 5.2 MEDIUM· v2 An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka "Windows Hyper-V Information Dis...Show more |
A remote code execution vulnerability exists when Microsoft .NET Framework processes untrusted input, aka ".NET Framework Remote Code Execution Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Fr...Show more |
1Microsoft 2Windows 10 Windows Server 2016Nov 21, 2024 Sep 13, 2018 N/A· v4 8.4 HIGH· v3 7.7 HIGH· v2 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Windows Hyper-V Remote Code Execution Vulne...Show more |
1Intel 3Compute Card Firmware Compute Stick FirmwareNuc Kit FirmwareNov 21, 2024 Sep 12, 2018 N/A· v4 8.2 HIGH· v3 7.2 HIGH· v2 Improper input validation in firmware for Intel NUC Kits may allow a privileged user to potentially execute arbitrary code resulting in information disclosure, escalation of privilege and/or denial of service via local a...Show more |
Huawei ALP-L09 smart phones with versions earlier than ALP-L09 8.0.0.150(C432) have an insufficient input validation vulnerability due to lack of parameter check. An attacker tricks the user who has root privilege to ins...Show more |
Huawei ALP-L09 smart phones with versions earlier than ALP-L09 8.0.0.150(C432) have an insufficient input validation vulnerability due to lack of parameter check. An attacker tricks the user who has root privilege to ins...Show more |
1Huawei 2Leland Al00 Firmware Lleland Al00a FirmwareJun 17, 2026 Sep 12, 2018 N/A· v4 5.5 MEDIUM· v3 7.1 HIGH· v2 Some Huawei smart phones with software of Leland-AL00 8.0.0.114(C636), Leland-AL00A 8.0.0.171(C00) have a denial of service (DoS) vulnerability. An attacker can trick a user to install a malicious application to exploit...Show more |
In FreeBSD before 11.1-STABLE, 11.2-RELEASE-p3, 11.1-RELEASE-p14, 10.4-STABLE, and 10.4-RELEASE-p12, insufficient validation in the ELF header parser could allow a malicious ELF binary to cause a kernel crash or disclose...Show more |
In FreeBSD 11.x before 11.1-RELEASE and 10.x before 10.4-RELEASE, the qsort algorithm has a deterministic recursion pattern. Feeding a pathological input to the algorithm can lead to excessive stack usage and potential o...Show more |
1Siemens 3Scalance X300 Firmware Scalance X408 FirmwareScalance X414 FirmwareNov 21, 2024 Sep 12, 2018 N/A· v4 8.6 HIGH· v3 7.8 HIGH· v2 A vulnerability has been identified in SCALANCE X300 (All versions < V4.0.0), SCALANCE X408 (All versions < V4.0.0), SCALANCE X414 (All versions). The web interface on port 443/tcp could allow an attacker to cause a Deni...Show more |
SAP HANA (versions 1.0 and 2.0) Extended Application Services classic model OData parser does not sufficiently validate XML. By exploiting, an unauthorized hacker can cause the database server to crash. |