← Back
CWE-20

12,891 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,891)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Apache
Debian
2Debian Linux
Traffic Server
Nov 21, 2024
Feb 27, 2018
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prior and 7.0.0 and prior with the Host header and line folding. This can have issues when interacting with upstream proxies and the wrong host being used...Show more
There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prior and 7.0.0 and prior with the Host header and line folding. This can have issues when interacting with upstream proxies and the wrong host being used.Show less
1Foxitsoftware
1Mobilepdf
Nov 21, 2024
Feb 26, 2018
N/A· v4
5.5 MEDIUM· v3
2.9 LOW· v2
A denial-of-service issue was discovered in the Foxit MobilePDF app before 6.1 for iOS. This occurs when a user uploads a file that includes a hexadecimal Unicode character in the "filename" parameter via Wi-Fi, since th...Show more
A denial-of-service issue was discovered in the Foxit MobilePDF app before 6.1 for iOS. This occurs when a user uploads a file that includes a hexadecimal Unicode character in the "filename" parameter via Wi-Fi, since the app could fail to parse this.Show less
1Linux
1Linux Kernel
Nov 21, 2024
Feb 26, 2018
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
The f2fs implementation in the Linux kernel before 4.14 mishandles reference counts associated with f2fs_wait_discard_bios calls, which allows local users to cause a denial of service (BUG), as demonstrated by fstrim.
1Google
1Android
Nov 21, 2024
Feb 23, 2018
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
In all Qualcomm products with Android releases from CAF using the Linux kernel, when an access point sends a challenge text greater than 128 bytes, the host driver is unable to validate this potentially leading to authen...Show more
In all Qualcomm products with Android releases from CAF using the Linux kernel, when an access point sends a challenge text greater than 128 bytes, the host driver is unable to validate this potentially leading to authentication failure.Show less
1Seagate
2Blackarmor Nas 110 Firmware
Blackarmor Nas 220 Firmware
Nov 21, 2024
Feb 23, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmgt/localJob.php or the auth_name parameter to localhost/backupmgmt/pre_connect_check.php.
1Cisco
1Unified Customer Voice Portal
Nov 21, 2024
Feb 22, 2018
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
A vulnerability in the Interactive Voice Response (IVR) management connection interface for Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to cause the IVR connection to disconn...Show more
A vulnerability in the Interactive Voice Response (IVR) management connection interface for Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to cause the IVR connection to disconnect, creating a system-wide denial of service (DoS) condition. The vulnerability is due to improper handling of a TCP connection request when the IVR connection is already established. An attacker could exploit this vulnerability by initiating a crafted connection to the IP address of the targeted CVP device. An exploit could allow the attacker to disconnect the IVR to CVP connection, creating a DoS condition that prevents the CVP from accepting new, incoming calls while the IVR automatically attempts to re-establish the connection to the CVP. This vulnerability affects Cisco Unified Customer Voice Portal (CVP) Software Release 11.5(1). Cisco Bug IDs: CSCve70560.Show less
1Apache
1Vcl
Nov 21, 2024
Feb 21, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The Privileges portion of the web GUI and the XMLRPC API in Apache VCL 2.3.x before 2.3.2, 2.2.x before 2.2.2 and 2.1 allow remote authenticated users with nodeAdmin, manageGroup, resourceGrant, or userGrant permissions...Show more
The Privileges portion of the web GUI and the XMLRPC API in Apache VCL 2.3.x before 2.3.2, 2.2.x before 2.2.2 and 2.1 allow remote authenticated users with nodeAdmin, manageGroup, resourceGrant, or userGrant permissions to gain privileges, cause a denial of service, or conduct cross-site scripting (XSS) attacks by leveraging improper data validation.Show less
1Joyent
1Smartos
Nov 21, 2024
Feb 21, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-20170803-20170803T064301Z. An attacker must first obtain the ability to execute low-privileged code o...Show more
This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-20170803-20170803T064301Z. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the SMBIOC_TREE_RELE ioctl. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code under the context of the host OS. Was ZDI-CAN-4984.Show less
1Datto
8Alto 2 Firmware
Alto 3 FirmwareAlto Imaged Firmware+5 more
Nov 21, 2024
Feb 20, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Datto ALTO and SIRIS devices allow Remote Code Execution via unauthenticated requests to PHP scripts.
1Oxid Esales
1Eshop
Jun 17, 2026
Feb 19, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in OXID eShop Enterprise Edition before 5.3.7 and 6.x before 6.0.1. By entering specially crafted URLs, an attacker is able to bring the shop server to a standstill and hence, it stops working. Th...Show more
An issue was discovered in OXID eShop Enterprise Edition before 5.3.7 and 6.x before 6.0.1. By entering specially crafted URLs, an attacker is able to bring the shop server to a standstill and hence, it stops working. This is only valid if OXID High Performance Option is activated and Varnish is used.Show less
1Symantec
4Backup Exec System Recovery
Norton 360Norton Ghost+1 more
Nov 21, 2024
Feb 19, 2018
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
GEAR Software CD DVD Filter driver (aka GEARAspiWDM.sys), as used in Symantec Backup Exec System Recovery 8.5 and BESR 2010, Symantec System Recovery 2011, Norton 360, and Norton Ghost, allows local users to cause a deni...Show more
GEAR Software CD DVD Filter driver (aka GEARAspiWDM.sys), as used in Symantec Backup Exec System Recovery 8.5 and BESR 2010, Symantec System Recovery 2011, Norton 360, and Norton Ghost, allows local users to cause a denial of service (system crash) via unspecified vectors.Show less
2Gnu
Redhat
4Binutils
Enterprise Linux DesktopEnterprise Linux Server+1 more
Jun 17, 2026
Feb 18, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
In the coff_pointerize_aux function in coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, an index is not validated, which allows remote attackers to cause a denial o...Show more
In the coff_pointerize_aux function in coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, an index is not validated, which allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via a crafted file, as demonstrated by objcopy of a COFF object.Show less
1Tendacn
1Ac15 Firmware
Jun 17, 2026
Feb 15, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered on Tenda AC15 V15.03.1.16_multi devices. A remote, unauthenticated attacker can gain remote code execution on the device with a crafted password parameter for the COOKIE header.
1Hp
1Intelligent Management Center
Nov 21, 2024
Feb 15, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P4 was found.
1Hp
1Intelligent Management Center
Nov 21, 2024
Feb 15, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0506 was found.
1Hp
1Moonshot Provisioning Manager Appliance
Nov 21, 2024
Feb 15, 2018
N/A· v4
9.1 CRITICAL· v3
8.5 HIGH· v2
A Remote Denial of Service vulnerability in Hewlett Packard Enterprise Moonshot Provisioning Manager Appliance version v1.20 was found.
1Hp
1Moonshot Provisioning Manager Appliance
Nov 21, 2024
Feb 15, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A Remote Code Execution vulnerability in Hewlett Packard Enterprise Moonshot Provisioning Manager Appliance version v1.20 was found.
1Hp
1Moonshot Provisioning Manager Appliance
Nov 21, 2024
Feb 15, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A Remote Code Execution vulnerability in Hewlett Packard Enterprise Moonshot Provisioning Manager Appliance version v1.20 was found.
1Hp
1Matrix Operating Environment
Nov 21, 2024
Feb 15, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An improper input validation vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found.
1Hp
1Matrix Operating Environment
Nov 21, 2024
Feb 15, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A clickjacking vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found.