← Back
CWE-20

12,861 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,861)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microfocus
1Sentinel
May 13, 2026
Mar 30, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability was discovered in NetIQ Sentinel Server 8.0 before 8.0.1 that may allow remote denial of service.
1Imagemagick
1Imagemagick
May 13, 2026
Mar 30, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
ImageMagick allows remote attackers to cause a denial of service (application crash) via a crafted wpg file.
1Imagemagick
1Imagemagick
May 13, 2026
Mar 30, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
ImageMagick allows remote attackers to cause a denial of service (application crash) via a crafted viff file.
1Imagemagick
1Imagemagick
May 13, 2026
Mar 30, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The xwd file handler in ImageMagick allows remote attackers to cause a denial of service (segmentation fault and application crash) via a malformed xwd file.
1Imagemagick
1Imagemagick
May 13, 2026
Mar 30, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The dpx file handler in ImageMagick allows remote attackers to cause a denial of service (segmentation fault and application crash) via a malformed dpx file.
1Imagemagick
1Imagemagick
May 13, 2026
Mar 30, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
ImageMagick allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafted xwd image.
1Imagemagick
1Imagemagick
May 13, 2026
Mar 30, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
ImageMagick allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafted dpc image.
1Imagemagick
1Imagemagick
May 13, 2026
Mar 30, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
ImageMagick allows remote attackers to cause a denial of service (file descriptor consumption) via a crafted file.
1Imagemagick
1Imagemagick
May 13, 2026
Mar 30, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
ImageMagick allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafted pnm file.
1Projectatomic
1Bubblewrap
May 13, 2026
Mar 29, 2017
N/A· v4
10.0 CRITICAL· v3
7.5 HIGH· v2
When executing a program via the bubblewrap sandbox, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal's input buffer, allowing an attacker to escape the...Show more
When executing a program via the bubblewrap sandbox, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal's input buffer, allowing an attacker to escape the sandbox.Show less
1Gnu
1Binutils
May 13, 2026
Mar 29, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has an aout_link_add_symbols function in bfd/aoutx.h that has an off-by-one vulnerability because it does not carefully check th...Show more
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has an aout_link_add_symbols function in bfd/aoutx.h that has an off-by-one vulnerability because it does not carefully check the string offset. The vulnerability could lead to a GNU linker (ld) program crash.Show less
1Call Cc
1Chicken
May 13, 2026
Mar 29, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The string-translate* procedure in the data-structures unit in CHICKEN before 4.10.0 allows remote attackers to cause a denial of service (crash).
1Ruby Lang
1Ruby
May 13, 2026
Mar 29, 2017
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
DL::dlopen in Ruby 1.8, 1.9.0, 1.9.2, 1.9.3, 2.0.0 before patchlevel 648, and 2.1 before 2.1.8 opens libraries with tainted names.
1Extraputty
1Extraputty
May 13, 2026
Mar 27, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The TFTP server in ExtraPuTTY 0.30 and earlier allows remote attackers to cause a denial of service (crash) via a large (1) read or (2) write TFTP protocol message.
1Ntp
1Ntp
May 13, 2026
Mar 27, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote attackers to cause a denial of service (ntpd crash) via a malformed mode configuration directive.
1Ntp
1Ntp
May 13, 2026
Mar 27, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote authenticated users to cause a denial of service (daemon crash) via an invalid setting in a :config directive, related to the unpeer option.
1Gnu
1Bash
May 13, 2026
Mar 27, 2017
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
The path autocompletion feature in Bash 4.4 allows local users to gain privileges via a crafted filename starting with a " (double quote) character and a command substitution metacharacter.
1Amd
1Ryzen
May 13, 2026
Mar 25, 2017
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
The AMD Ryzen processor with AGESA microcode through 2017-01-27 allows local users to cause a denial of service (system hang) via an application that makes a long series of FMA3 instructions, as demonstrated by the Flops...Show more
The AMD Ryzen processor with AGESA microcode through 2017-01-27 allows local users to cause a denial of service (system hang) via an application that makes a long series of FMA3 instructions, as demonstrated by the Flops test suite.Show less
1Linux
1Linux Kernel
May 13, 2026
Mar 24, 2017
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
The vmw_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.10.5 does not check for a zero value of certain levels data, which allows local users to cause a denial of se...Show more
The vmw_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.10.5 does not check for a zero value of certain levels data, which allows local users to cause a denial of service (ZERO_SIZE_PTR dereference, and GPF and possibly panic) via a crafted ioctl call for a /dev/dri/renderD* device.Show less
1Huawei
1Ar3200 Firmware
May 13, 2026
Mar 24, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Huawei AR3200 routers with software before V200R007C00SPC600 allow remote attackers to cause a denial of service or execute arbitrary code via a crafted packet.