← Back
CWE-20

12,884 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,884)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Powerdns
1Recursor
Nov 21, 2024
Jan 23, 2018
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
When api-config-dir is set to a non-empty value, which is not the case by default, the API in PowerDNS Recursor 4.x up to and including 4.0.6 and 3.x up to and including 3.7.4 allows an authorized user to update the Recu...Show more
When api-config-dir is set to a non-empty value, which is not the case by default, the API in PowerDNS Recursor 4.x up to and including 4.0.6 and 3.x up to and including 3.7.4 allows an authorized user to update the Recursor's ACL by adding and removing netmasks, and to configure forward zones. It was discovered that the new netmask and IP addresses of forwarded zones were not sufficiently validated, allowing an authenticated user to inject new configuration directives into the Recursor's configuration.Show less
1Netgain Systems
1Enterprise Manager
Nov 21, 2024
Jan 23, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
This vulnerability allows remote attackers to create arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability...Show more
This vulnerability allows remote attackers to create arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the org.apache.jsp.u.jsp.db.save_005fimage_jsp servlet, which listens on TCP port 8081 by default. When parsing the id parameter, the process does not properly validate user-supplied data, which can allow for the upload of files. An attacker can leverage this vulnerability to execute code under the context of Administrator. Was ZDI-CAN-5117.Show less
1Powerdns
1Recursor
Nov 21, 2024
Jan 22, 2018
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
Improper input validation bugs in DNSSEC validators components in PowerDNS version 4.1.0 allow attacker in man-in-the-middle position to deny existence of some data in DNS via packet replay.
1Nic
1Knot Resolver
Nov 21, 2024
Jan 22, 2018
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
Improper input validation bugs in DNSSEC validators components in Knot Resolver (prior version 1.5.2) allow attacker in man-in-the-middle position to deny existence of some data in DNS via packet replay.
1Zillya
1Zillya! Antivirus
Jun 17, 2026
Jan 21, 2018
N/A· v4
7.8 HIGH· v3
6.1 MEDIUM· v2
In Zillya! Antivirus 3.0.2230.0, the driver file (zef.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9C402424.
1Zillya
1Zillya! Antivirus
Jun 17, 2026
Jan 21, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In Zillya! Antivirus 3.0.2230.0, the driver file (zef.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9C40242C.
1Zillya
1Zillya! Antivirus
Jun 17, 2026
Jan 21, 2018
N/A· v4
7.8 HIGH· v3
6.1 MEDIUM· v2
In Zillya! Antivirus 3.0.2230.0, the driver file (zef.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9C402414.
1Smartmobilesoftware
1Gitstack
Jun 17, 2026
Jan 21, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in GitStack through 2.3.10. User controlled input is not sufficiently filtered, allowing an unauthenticated attacker to add a user to the server via the username and password fields to the rest/us...Show more
An issue was discovered in GitStack through 2.3.10. User controlled input is not sufficiently filtered, allowing an unauthenticated attacker to add a user to the server via the username and password fields to the rest/user/ URI.Show less
1Yandex
1Yandex Browser
Nov 21, 2024
Jan 19, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Yandex Browser before 16.9.0 allows remote attackers to spoof the address bar via window.open.
1Google
1Android
Nov 21, 2024
Jan 18, 2018
N/A· v4
5.7 MEDIUM· v3
5.7 MEDIUM· v2
In Samsung Gear products, Bluetooth link key is updated to the different key which is same with attacker's link key. It can be attacked without user's intention only if attacker can reveal the Bluetooth address of target...Show more
In Samsung Gear products, Bluetooth link key is updated to the different key which is same with attacker's link key. It can be attacked without user's intention only if attacker can reveal the Bluetooth address of target device and paired user's smartphoneShow less
3Debian
Libpam4j ProjectRedhat
3Debian Linux
Enterprise LinuxLibpam4j
Nov 21, 2024
Jan 18, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating. A user with a valid password for a disabled account would be able to bypass security restrictions and possib...Show more
It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating. A user with a valid password for a disabled account would be able to bypass security restrictions and possibly access sensitive information.Show less
1Cisco
1Nx Os
Nov 21, 2024
Jan 18, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability in management interface access control list (ACL) configuration of Cisco NX-OS System Software could allow an unauthenticated, remote attacker to bypass configured ACLs on the management interface. This c...Show more
A vulnerability in management interface access control list (ACL) configuration of Cisco NX-OS System Software could allow an unauthenticated, remote attacker to bypass configured ACLs on the management interface. This could allow traffic to be forwarded to the NX-OS CPU for processing, leading to high CPU utilization and a denial of service (DoS) condition. The vulnerability is due to a bad code fix in the 7.3.2 code train that could allow traffic to the management interface to be misclassified and not match the proper configured ACLs. An attacker could exploit this vulnerability by sending crafted traffic to the management interface. An exploit could allow the attacker to bypass the configured management interface ACLs and impact the CPU of the targeted device, resulting in a DoS condition. This vulnerability affects the following Cisco products running Cisco NX-OS System Software: Multilayer Director Switches, Nexus 2000 Series Switches, Nexus 3000 Series Switches, Nexus 5500 Platform Switches, Nexus 5600 Platform Switches, Nexus 6000 Series Switches, Nexus 7000 Series Switches, Nexus 7700 Series Switches, Nexus 9000 Series Switches in standalone NX-OS mode. Cisco Bug IDs: CSCvf31132.Show less
1Intel
1Minnowboard 3 Firmware
Nov 21, 2024
Jan 18, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Input validation error in Intel MinnowBoard 3 Firmware versions prior to 0.65 allow local attacker to cause denial of service via UEFI APIs.
1Malwarefox
1Anti Malware
Jun 17, 2026
Jan 16, 2018
N/A· v4
7.8 HIGH· v3
6.1 MEDIUM· v2
In Malwarefox Anti-Malware 2.72.169, the driver file (zam64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x800020...Show more
In Malwarefox Anti-Malware 2.72.169, the driver file (zam64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x80002054.Show less
1Malwarefox
1Anti Malware
Jun 17, 2026
Jan 16, 2018
N/A· v4
7.8 HIGH· v3
6.1 MEDIUM· v2
In Malwarefox Anti-Malware 2.72.169, the driver file (zam64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x800020...Show more
In Malwarefox Anti-Malware 2.72.169, the driver file (zam64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x80002010.Show less
1K7computing
5Antivirus
EndpointInternet Security+2 more
Nov 21, 2024
Jan 16, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In K7 Antivirus Premium before 15.1.0.53, user-controlled input to the K7Sentry device is not sufficiently authenticated: a local user with a LOW integrity process can access a raw hard disk by sending a specific IOCTL.
1K7computing
5Antivirus
EndpointInternet Security+2 more
Nov 21, 2024
Jan 16, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In K7 Antivirus Premium before 15.1.0.53, user-controlled input can be used to allow local users to write to arbitrary memory locations.
1Ibm
1Db2
Nov 21, 2024
Jan 16, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
IBM DB2 9.7, 10.1 before FP6, and 10.5 before FP8 on AIX, Linux, HP, Solaris and Windows allow remote authenticated users to cause a denial of service (daemon crash) via a SELECT statement with a subquery containing the...Show more
IBM DB2 9.7, 10.1 before FP6, and 10.5 before FP8 on AIX, Linux, HP, Solaris and Windows allow remote authenticated users to cause a denial of service (daemon crash) via a SELECT statement with a subquery containing the AVG OLAP function on an Oracle compatible database.Show less
1Ibm
1Algo Risk Application
Nov 21, 2024
Jan 16, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Algorithmics One-Algo Risk Application (ARA) 4.9.1 through 5.1.0 allows remote authenticated users to conduct clickjacking attacks via unspecified vectors. IBM X-Force ID: 109399.
1Google
1Android
Nov 21, 2024
Jan 12, 2018
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
In the hardware HEVC decoder, some media files could cause a page fault. This could lead to a remote denial of service of a critical system process with no additional execution privileges needed. User interaction is not...Show more
In the hardware HEVC decoder, some media files could cause a page fault. This could lead to a remote denial of service of a critical system process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-38495900.Show less