CWE-20
12,849 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,849)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 1Aironet Access Point Software May 6, 2026 Aug 22, 2016 N/A· v4 6.5 MEDIUM· v3 6.1 MEDIUM· v2 The Aggregated MAC Protocol Data Unit (AMPDU) implementation on Cisco Aironet 1800, 2800, and 3800 devices with software before 8.2.121.0 and 8.3.x before 8.3.102.0 allows remote attackers to cause a denial of service (d...Show more |
1Cisco 1Ip Phone 8800 Series Firmware May 6, 2026 Aug 22, 2016 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Cisco IP Phone 8800 devices with software 11.0(1) allow remote attackers to cause a denial of service (memory corruption) via a crafted HTTP request, aka Bug ID CSCuz03038. |
1Cisco 1Application Policy Infrastructure Controller Enterprise Module May 6, 2026 Aug 18, 2016 N/A· v4 8.8 HIGH· v3 8.5 HIGH· v2 The Grapevine update process in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0 allows remote authenticated users to execute arbitrary commands as root via a crafted upgrade parameter,...Show more |
1Microsoft 8Live Meeting LyncOffice+5 moreMay 6, 2026 Aug 9, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office 2007 SP3, Office 2010 SP2, Word Viewer, Skype for Business 2016, Lync 2013 SP1, Lync 2010, Lync 2010 Atte...Show more |
1Microsoft 8Live Meeting LyncOffice+5 moreMay 6, 2026 Aug 9, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office 2007 SP3, Office 2010 SP2, Word Viewer, Skype for Business 2016, Lync 2013 SP1, Lync 2010, Lync 2010 Atte...Show more |
1Microsoft 12Live Meeting LyncOffice+9 moreMay 6, 2026 Aug 9, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 The Windows font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3;...Show more |
The mustendd driver in IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x, when the jumbo_frames feature is not enabled, allows remote attackers to cause a denial of service (FC1763 or FC5899 adapter crash) via crafted packet...Show more |
Cisco IOS 15.5(3)S3, 15.6(1)S2, 15.6(2)S1, and 15.6(2)T1 does not properly dequeue invalid NTP packets, which allows remote attackers to cause a denial of service (interface wedge) by sending many crafted NTP packets, ak...Show more |
1Cisco 2Rv180 Vpn Router Firmware Rv180w Vpn Router FirmwareMay 6, 2026 Aug 8, 2016 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Cisco RV180 and RV180W devices allow remote authenticated users to execute arbitrary commands as root via a crafted HTTP request, aka Bug ID CSCuz48592. |
2Fedoraproject Openbsd2Fedora OpensshMay 6, 2026 Aug 7, 2016 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password authentication, which allows remote attackers to cause a denial of service (crypt CPU consumption) vi...Show more |
The is_ashmem_file function in drivers/staging/android/ashmem.c in a certain Qualcomm Innovation Center (QuIC) Android patch for the Linux kernel 3.x mishandles pointer validation within the KGSL Linux Graphics Module, w...Show more |
The vfe31_proc_general function in drivers/media/video/msm/vfe/msm_vfe31.c in the MSM-VFE31 driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other pr...Show more |
Blink, as used in Google Chrome before 52.0.2743.116, allows remote attackers to spoof the address bar via vectors involving a provisional URL for an initially empty document, related to FrameLoader.cpp and ScopedPageLoa...Show more |
2Oracle Wireshark2Solaris WiresharkMay 6, 2026 Aug 7, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 epan/dissectors/packet-pktap.c in the Ethernet dissector in Wireshark 2.x before 2.0.4 mishandles the packet-header data type, which allows remote attackers to cause a denial of service (application crash) via a crafted...Show more |
2Oracle Wireshark2Solaris WiresharkMay 6, 2026 Aug 7, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 wiretap/netscreen.c in the NetScreen file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer processing, which allows remote attackers to cause a denial of service (applicat...Show more |
wiretap/toshiba.c in the Toshiba file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer processing, which allows remote attackers to cause a denial of service (application...Show more |
epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles the reserved C/T value, which allows remote attackers to cause a denial of service (application...Show more |
epan/crypt/airpdcap.c in the IEEE 802.11 dissector in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles the lack of an EAPOL_RSN_KEY, which allows remote attackers to cause a denial of service (application...Show more |
4Canonical DebianLibgd+1 more4Debian Linux LeapLibgd+1 moreMay 6, 2026 Aug 7, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remote attackers to cause a denial of service (application crash) via an invalid col...Show more |
epan/dissectors/packet-wap.c in Wireshark 2.x before 2.0.5 omits an overflow check in the tvb_get_guintvar function, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet, relate...Show more |