CWE-20
12,849 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,849)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Adobe 4Acrobat Acrobat DcAcrobat Reader Dc+1 moreMay 6, 2026 Jan 11, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have a security bypass vulnerability when manipulating Form Data Format (FDF). |
1Microsoft 3Windows 7 Windows Server 2008Windows VistaMay 6, 2026 Jan 10, 2017 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 The Local Security Authority Subsystem Service (LSASS) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to cause a denial of service (reboot) via a crafted aut...Show more |
1F5 10Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+7 moreMay 6, 2026 Jan 10, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Under certain conditions for BIG-IP systems using a virtual server with an associated FastL4 profile and TCP analytics profile, a specific sequence of packets may cause the Traffic Management Microkernel (TMM) to restart...Show more |
3Hp IntelLenovo28Converged Hx5500 Appliance Converged Hx5510 ApplianceConverged Hx7500 Appliance+25 moreMay 6, 2026 Jan 9, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A Denial of Service in Intel Ethernet Controller's X710/XL710 with Non-Volatile Memory Images before version 5.05 allows a remote attacker to stop the controller from processing network traffic working under certain netw...Show more |
Installing a zero-permission Android application on certain Samsung Android devices with KK(4.4), L(5.0/5.1), and M(6.0) software can continually crash the system_server process in the Android OS. The zero-permission app...Show more |
1Kaspersky 3Anti Virus Internet SecurityTotal SecurityMay 6, 2026 Jan 6, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A local denial of service vulnerability exists in window broadcast message handling functionality of Kaspersky Anti-Virus software. Sending certain unhandled window messages, an attacker can cause application termination...Show more |
An off-path attacker can cause a preemptible client association to be demobilized in NTP 4.2.8p4 and earlier and NTPSec a5fb34b9cc89b92a8fef2f459004865c93bb7f92 by sending a crypto NAK packet to a victim client with a sp...Show more |
1F5 10Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+7 moreMay 6, 2026 Jan 3, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Virtual servers in F5 BIG-IP systems 11.6.1 before 11.6.1 HF1 and 12.1.x before 12.1.2, when configured to parse RADIUS messages via an iRule, allow remote attackers to cause a denial of service (Traffic Management Micro...Show more |
Borg (aka BorgBackup) before 1.0.9 has a flaw in the way duplicate archive names were processed during manifest recovery, potentially allowing an attacker to overwrite an archive. |
QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue. It occurs when a guest sends a Layer-2 packet smaller than 22 bytes. A privileged (CAP_SYS_RAWIO) guest...Show more |
A vulnerability in the Cisco Jabber Guest Server could allow an unauthenticated, remote attacker to initiate connections to arbitrary hosts. More Information: CSCvc31635. Known Affected Releases: 10.6(9). Known Fixed Rel...Show more |
The gsm_parse function in libavcodec/gsm_parser.c in FFmpeg before 3.1.5 allows remote attackers to cause a denial of service (assert fault) via a crafted AVI file. |
The avi_read_seek function in libavformat/avidec.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (assert fault) via a crafted AVI file. |
lynx: It was found that Lynx doesn't parse the authority component of the URL correctly when the host name part ends with '?', and could instead be tricked into connecting to a different host. |
Microsoft Excel 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016 misparses file formats, which makes it easier for remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Security Feature Bypass...Show more |
1Microsoft 4Excel Excel For MacExcel Viewer+1 moreMay 6, 2026 Dec 20, 2016 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, Excel Viewer, and Excel 2016 for Mac mishandle a registry check, which allows user-assisted remote a...Show more |
Google Chrome prior to 54.0 for iOS had insufficient validation of URLs for windows open by DOM, which allowed a remote attacker to bypass restrictions on navigation to certain URL schemes via crafted HTML pages. |
Multiple issues in Blink in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux allow a remote attacker to spoof various parts of browser UI via crafted HTML pages. |
Google Chrome prior to 54.0.2840.85 for Android incorrectly handled rapid transition into and out of full screen mode, which allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via crafted HTML pages...Show more |
1Siemens 2Simatic S7 300 Cpu Firmware Simatic S7 400 Cpu FirmwareJun 2, 2026 Dec 17, 2016 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A vulnerability has been identified in SIMATIC S7-300 CPU family (All versions), SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions), SIMATIC S7-400 PN/DP V6 and below CPU family (incl...Show more |