← Back
CWE-20

12,891 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,891)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Qualcomm
9Mdm9625 Firmware
Sd 425 FirmwareSd 430 Firmware+6 more
Nov 21, 2024
Apr 18, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile MDM9625, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 820, and SD 820A, no address argument validation...Show more
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile MDM9625, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 820, and SD 820A, no address argument validation performed on calls to a QSEE syscall may lead to arbitrary read/write or NULL Pointer exception when calling a downstream function.Show less
1Qualcomm
22Msm8909w Firmware
Sd 205 FirmwareSd 210 Firmware+19 more
Nov 21, 2024
Apr 18, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/...Show more
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, and SD 820A, in playready_licacq_process_response(), 'cbResponse' value is controlled by HLOS, and there is no validation on this length. If 'cbResponse' is too large, memory overread occurs.Show less
1Qualcomm
15Mdm9206 Firmware
Mdm9607 FirmwareMdm9635m Firmware+12 more
Nov 21, 2024
Apr 18, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 41...Show more
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, and SDX20, after loading a dynamically loaded code section, I-Cache is not invalidated, which could lead to executing code from stale cache lines.Show less
1Zohocorp
1Manageengine Desktop Central
Nov 21, 2024
Apr 18, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: a missing server-side check on the file type/extension when uploading and modifying scripts.
1Cpap
1Luna Cpap Machine Firmware
Nov 21, 2024
Apr 17, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
BMC Medical Luna CPAP Machines released prior to July 1, 2017, contain an improper input validation vulnerability which may allow an authenticated attacker to crash the CPAP's Wi-Fi module resulting in a denial-of-servic...Show more
BMC Medical Luna CPAP Machines released prior to July 1, 2017, contain an improper input validation vulnerability which may allow an authenticated attacker to crash the CPAP's Wi-Fi module resulting in a denial-of-service condition.Show less
1Symantec
1Endpoint Protection
Nov 21, 2024
Apr 16, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Symantec Endpoint Protection clients place detected malware in quarantine as part of the intended product functionality. The quarantine logs can be exported for review by the user in a variety of formats including .CSV f...Show more
Symantec Endpoint Protection clients place detected malware in quarantine as part of the intended product functionality. The quarantine logs can be exported for review by the user in a variety of formats including .CSV files. Prior to 14.0 MP1 and 12.1 RU6 MP7, the potential exists for file metadata to be interpreted and evaluated as a formula. Successful exploitation of an attack of this type requires considerable direct user-interaction from the user exporting and then opening the log files on the intended target client.Show less
1Symantec
1Endpoint Protection
Nov 21, 2024
Apr 16, 2018
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
A version of the SymEvent Driver that shipped with Symantec Endpoint Protection 12.1 RU6 MP6 and earlier fails to properly sanitize logged-in user input. SEP 14.0 and later are not impacted by this issue. A non-admin use...Show more
A version of the SymEvent Driver that shipped with Symantec Endpoint Protection 12.1 RU6 MP6 and earlier fails to properly sanitize logged-in user input. SEP 14.0 and later are not impacted by this issue. A non-admin user would need to be able to save an executable file to disk and then be able to successfully run that file. If properly constructed, the file could access the driver interface and potentially manipulate certain system calls. On all 32-bit systems and in most cases on 64-bit systems, this will result in a denial of service that will crash the system. In very narrow circumstances, and on 64-bit systems only, this could allow the user to run arbitrary code on the local machine with kernel-level privileges. This could result in a non-privileged user gaining privileged access on the local machine.Show less
1Hatena
1Hatena Bookmark
Nov 21, 2024
Apr 16, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Hatena Bookmark App for iOS Version 3.0 to 3.70 allows remote attackers to spoof the address bar via vectors related to URL display.
2Debian
Mediawiki
2Debian Linux
Mediawiki
Nov 21, 2024
Apr 13, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw were Spam blacklist is ineffective on encoded URLs inside file inclusion syntax's link parameter.
2Debian
Mediawiki
2Debian Linux
Mediawiki
Nov 21, 2024
Apr 13, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw making rawHTML mode apply to system messages.
2Debian
Mediawiki
2Debian Linux
Mediawiki
Nov 21, 2024
Apr 13, 2018
N/A· v4
5.4 MEDIUM· v3
4.0 MEDIUM· v2
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw allowing to evade SVG filter using default attribute values in DTD declaration.
1F5
13Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Analytics+10 more
Jun 17, 2026
Apr 13, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
On F5 BIG-IP 11.5.4 HF4-11.5.5, the Traffic Management Microkernel (TMM) may restart when processing a specific sequence of packets on IPv6 virtual servers.
3Canonical
DebianLinux
3Debian Linux
Linux KernelUbuntu Linux
Nov 21, 2024
Apr 13, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The kernel_wait4 function in kernel/exit.c in the Linux kernel before 4.13, when an unspecified architecture and compiler is used, might allow local users to cause a denial of service by triggering an attempted use of th...Show more
The kernel_wait4 function in kernel/exit.c in the Linux kernel before 4.13, when an unspecified architecture and compiler is used, might allow local users to cause a denial of service by triggering an attempted use of the -INT_MIN value.Show less
1F5
8Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Application Acceleration Manager+5 more
Nov 21, 2024
Apr 13, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Responses to SOCKS proxy requests made through F5 BIG-IP version 13.0.0, 12.0.0-12.1.3.1, 11.6.1-11.6.2, or 11.5.1-11.5.5 may cause a disruption of services provided by TMM. The data plane is impacted and exposed only wh...Show more
Responses to SOCKS proxy requests made through F5 BIG-IP version 13.0.0, 12.0.0-12.1.3.1, 11.6.1-11.6.2, or 11.5.1-11.5.5 may cause a disruption of services provided by TMM. The data plane is impacted and exposed only when a SOCKS proxy profile is attached to a Virtual Server. The control plane is not impacted by this vulnerability.Show less
1Hot Scripts Clone Project
1Hot Scripts Clone
Jun 17, 2026
Apr 12, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
PHP Scripts Mall Hot Scripts Clone Script Classified v3.1 uses the client side to enforce validation of an e-mail address, which allows remote attackers to modify a registered e-mail address by removing the validation co...Show more
PHP Scripts Mall Hot Scripts Clone Script Classified v3.1 uses the client side to enforce validation of an e-mail address, which allows remote attackers to modify a registered e-mail address by removing the validation code.Show less
1Website Seller Script Project
1Website Seller Script
Jun 17, 2026
Apr 12, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
PHP Scripts Mall Website Seller Script 2.0.3 uses the client side to enforce validation of an e-mail address, which allows remote attackers to modify a registered e-mail address by removing the validation code.
1Jungo
1Windriver
Nov 21, 2024
Apr 12, 2018
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
windrvr1260.sys in Jungo DriverWizard WinDriver 12.6.0 allows attackers to cause a denial of service (BSOD) via a 0x953827bf DeviceIoControl call.
1Jungo
1Windriver
Nov 21, 2024
Apr 12, 2018
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
windrvr1260.sys in Jungo DriverWizard WinDriver 12.6.0 allows attackers to cause a denial of service (BSOD) via a 0x953826DB DeviceIoControl call.
3Clusterlabs
DebianRedhat
3Debian Linux
Enterprise Linux Server EusPacemaker Command Line Interface
Nov 21, 2024
Apr 12, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd service did not properly remove the pcs debug argument from the /run_pcs query, possibly disclosing sensi...Show more
pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd service did not properly remove the pcs debug argument from the /run_pcs query, possibly disclosing sensitive information. A remote attacker with a valid token could use this flaw to elevate their privilege.Show less
1Microsoft
7Windows 10
Windows 7Windows 8.1+4 more
Nov 21, 2024
Apr 12, 2018
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability." This affects Windows 7, Window...Show more
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-1010, CVE-2018-1012, CVE-2018-1013, CVE-2018-1015.Show less