← Back
CWE-20

12,882 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,882)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Malwarebytes
1Malwarebytes
Nov 21, 2024
Jan 8, 2018
N/A· v4
7.8 HIGH· v3
6.1 MEDIUM· v2
In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e0...Show more
In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e010. NOTE: the vendor reported that they "have not been able to reproduce the issue on any Windows operating system version (32-bit or 64-bit).Show less
1Wp Dbmanager Project
1Wp Dbmanager
Nov 21, 2024
Jan 5, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The "Sql Run Query" panel in WP-DBManager (aka Database Manager) plugin before 2.7.2 for WordPress allows remote attackers to read arbitrary files by leveraging failure to sufficiently limit queries, as demonstrated by u...Show more
The "Sql Run Query" panel in WP-DBManager (aka Database Manager) plugin before 2.7.2 for WordPress allows remote attackers to read arbitrary files by leveraging failure to sufficiently limit queries, as demonstrated by use of LOAD_FILE in an INSERT statement.Show less
1Advantech
1Webaccess
Nov 21, 2024
Jan 5, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An Improper Input Validation issue was discovered in Advantech WebAccess versions prior to 8.3. WebAccess allows some inputs that may cause the program to crash.
1K7computing
1Antivirus
Nov 21, 2024
Jan 4, 2018
N/A· v4
7.8 HIGH· v3
6.1 MEDIUM· v2
In K7 Antivirus 15.1.0306, the driver file (K7Sentry.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x95002610.
1K7computing
1Antivirus
Nov 21, 2024
Jan 4, 2018
N/A· v4
7.8 HIGH· v3
6.1 MEDIUM· v2
In K7 Antivirus 15.1.0306, the driver file (K7FWHlpr.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x83002168.
1K7computing
1Antivirus
Nov 21, 2024
Jan 4, 2018
N/A· v4
7.8 HIGH· v3
6.1 MEDIUM· v2
In K7 Antivirus 15.1.0306, the driver file (K7Sentry.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x950025b0.
1K7computing
1Antivirus
Nov 21, 2024
Jan 4, 2018
N/A· v4
7.8 HIGH· v3
6.1 MEDIUM· v2
In K7 Antivirus 15.1.0306, the driver file (K7Sentry.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x95002578.
1Cisco
4Webex Business Suite
Webex MeetingsWebex Meetings Server+1 more
Nov 21, 2024
Jan 4, 2018
N/A· v4
9.6 CRITICAL· v3
9.3 HIGH· v2
A vulnerability in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow a remote attacker to execute arbitrary code on the system of a targeted user. The attacker could exploit this...Show more
A vulnerability in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow a remote attacker to execute arbitrary code on the system of a targeted user. The attacker could exploit this vulnerability by sending the user a link or email attachment with a malicious ARF file and persuading the user to follow the link or launch the file. Successful exploitation could allow the attacker to execute arbitrary code on the user's system. This vulnerability affects Cisco WebEx Business Suite meeting sites, Cisco WebEx Meetings sites, Cisco WebEx Meetings Server, and Cisco WebEx ARF players. Cisco Bug IDs: CSCvg78853, CSCvg78856, CSCvg78857.Show less
2Pivotal Software
Vmware
3Spring Boot
Spring Data RestSpring Data Rest
Jun 26, 2026
Jan 4, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON...Show more
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbitrary Java code.Show less
1Samsung
1Samsung Mobile
Nov 21, 2024
Jan 4, 2018
N/A· v4
8.4 HIGH· v3
7.2 HIGH· v2
On Samsung mobile devices with L(5.x), M(6.x), and N(7.x) software and Exynos chipsets, attackers can execute arbitrary code in the bootloader because S Boot omits a size check during a copy of ramfs data to memory. The...Show more
On Samsung mobile devices with L(5.x), M(6.x), and N(7.x) software and Exynos chipsets, attackers can execute arbitrary code in the bootloader because S Boot omits a size check during a copy of ramfs data to memory. The Samsung ID is SVE-2017-10598.Show less
1K7computing
1Total Security
Nov 21, 2024
Jan 4, 2018
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
In K7 Total Security before 15.1.0.305, user-controlled input to the K7Sentry device is not sufficiently sanitized: the user-controlled input can be used to compare an arbitrary memory address with a fixed value, which i...Show more
In K7 Total Security before 15.1.0.305, user-controlled input to the K7Sentry device is not sufficiently sanitized: the user-controlled input can be used to compare an arbitrary memory address with a fixed value, which in turn can be used to read the contents of arbitrary memory. Similarly, the product crashes upon a \\.\K7Sentry DeviceIoControl call with an invalid kernel pointer.Show less
1K7computing
1Antivirus
Nov 21, 2024
Jan 3, 2018
N/A· v4
7.8 HIGH· v3
6.1 MEDIUM· v2
In K7 AntiVirus 15.1.0306, the driver file (K7FWHlpr.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x8300211C.
1K7computing
1Antivirus
Nov 21, 2024
Jan 3, 2018
N/A· v4
7.8 HIGH· v3
6.1 MEDIUM· v2
In K7 AntiVirus 15.1.0306, the driver file (K7FWHlpr.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x83002100.
1K7computing
1Antivirus
Nov 21, 2024
Jan 3, 2018
N/A· v4
7.8 HIGH· v3
6.1 MEDIUM· v2
In K7 AntiVirus 15.1.0306, the driver file (K7FWHlpr.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x8300215F.
1K7computing
1Antivirus
Nov 21, 2024
Jan 3, 2018
N/A· v4
7.8 HIGH· v3
6.1 MEDIUM· v2
In K7 AntiVirus 15.1.0306, the driver file (K7FWHlpr.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x83002124.
1K7computing
1Antivirus
Nov 21, 2024
Jan 3, 2018
N/A· v4
7.8 HIGH· v3
6.1 MEDIUM· v2
In K7 AntiVirus 15.1.0306, the driver file (K7FWHlpr.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x8300212C.
1K7computing
1Antivirus
Nov 21, 2024
Jan 3, 2018
N/A· v4
7.8 HIGH· v3
6.1 MEDIUM· v2
In K7 AntiVirus 15.1.0306, the driver file (K7FWHlpr.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x8300215B.
1K7computing
1Antivirus
Nov 21, 2024
Jan 3, 2018
N/A· v4
7.8 HIGH· v3
6.1 MEDIUM· v2
In K7 AntiVirus 15.1.0306, the driver file (K7FWHlpr.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x83002128.
1K7computing
1Antivirus
Nov 21, 2024
Jan 3, 2018
N/A· v4
7.8 HIGH· v3
6.1 MEDIUM· v2
In K7 AntiVirus 15.1.0306, the driver file (K7FWHlpr.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x830020F0.
1K7computing
1Antivirus
Nov 21, 2024
Jan 3, 2018
N/A· v4
7.8 HIGH· v3
6.1 MEDIUM· v2
In K7 AntiVirus 15.1.0306, the driver file (K7FWHlpr.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x830020FC.