CWE-20
12,845 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,845)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Stack consumption vulnerability in Zend/zend_exceptions.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allows remote attackers to cause a denial of service (segmentation fault) via recursive method...Show more |
The phar_convert_to_other function in ext/phar/phar_object.c in PHP before 5.4.43, 5.5.x before 5.5.27, and 5.6.x before 5.6.11 does not validate a file pointer before a close operation, which allows remote attackers to...Show more |
2Php Redhat8Enterprise Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+5 moreMay 6, 2026 May 16, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The mcopy function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly restrict a certain offset value, which allows remote a...Show more |
2Php Redhat8Enterprise Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+5 moreMay 6, 2026 May 16, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The mget function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly maintain a certain pointer relationship, which allows r...Show more |
2Php Redhat8Enterprise Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+5 moreMay 6, 2026 May 16, 2016 N/A· v4 6.5 MEDIUM· v3 7.5 HIGH· v2 PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read or write to arbitrary files via crafted input to an applicatio...Show more |
2Php Redhat8Enterprise Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+5 moreMay 6, 2026 May 16, 2016 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read or write to arbitrary files via crafted input to an application...Show more |
IBM Cognos TM1 10.2.2 before FP5, when the host/pmhub/pm/admin AdminGroups setting is empty, allows remote authenticated users to cause a denial of service (configuration outage) via a non-empty value. |
3Google OpensuseRedhat6Chrome Enterprise Linux Desktop SupplementaryEnterprise Linux Server Supplementary+3 moreMay 6, 2026 May 14, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The JSGenericLowering class in compiler/js-generic-lowering.cc in Google V8, as used in Google Chrome before 50.0.2661.94, mishandles comparison operators, which allows remote attackers to obtain sensitive information vi...Show more |
3Google OpensuseRedhat6Chrome Enterprise Linux Desktop SupplementaryEnterprise Linux Server Supplementary+3 moreMay 6, 2026 May 14, 2016 N/A· v4 8.0 HIGH· v3 8.3 HIGH· v2 Blink, as used in Google Chrome before 50.0.2661.94, does not ensure that frames satisfy a check for the same renderer process in addition to a Same Origin Policy check, which allows remote attackers to cause a denial of...Show more |
3Google OpensuseRedhat6Chrome Enterprise Linux Desktop SupplementaryEnterprise Linux Server Supplementary+3 moreMay 6, 2026 May 14, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Blink, as used in Google Chrome before 50.0.2661.94, mishandles assertions in the WTF::BitArray and WTF::double_conversion::Vector classes, which allows remote attackers to cause a denial of service (out-of-bounds write)...Show more |
The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via crafted serialized values in a POST request. |
1F5 21Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+18 moreMay 6, 2026 May 13, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, 11.6.x before 11.6.1, and 12.x before 12.0.0 HF1; BIG-IP AAM 11.4.x before 11.4.1 HF10, 11.5.x be...Show more |
2Debian Enlightenment2Debian Linux Imlib2May 6, 2026 May 13, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 imlib2 before 1.4.7 allows remote attackers to cause a denial of service (segmentation fault) via a crafted GIF file. |
2Debian Enlightenment2Debian Linux Imlib2May 6, 2026 May 13, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 imlib2 before 1.4.7 allows remote attackers to cause a denial of service (segmentation fault) via a GIF image without a colormap. |
2Botan Project Fedoraproject2Botan FedoraMay 6, 2026 May 13, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Botan 1.11.x before 1.11.29 does not enforce TLS policy for (1) signature algorithms and (2) ECC curves, which allows remote attackers to conduct downgrade attacks via unspecified vectors. |
2Botan Project Debian2Botan Debian LinuxMay 6, 2026 May 13, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ressol function in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to cause a denial of service (infinite loop) via unspecified input to the OS2ECP function, related to a composite modulus. |
2Botan Project Debian2Botan Debian LinuxMay 6, 2026 May 13, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The BER decoder in Botan 0.10.x before 1.10.10 and 1.11.x before 1.11.19 allows remote attackers to cause a denial of service (application crash) via an empty BIT STRING in ASN.1 data. |
Panasonic FPWIN Pro 5.x through 7.x before 7.130 accesses an uninitialized pointer, which allows local users to cause a denial of service or possibly have unspecified other impact via unknown vectors. |
Panasonic FPWIN Pro 5.x through 7.x before 7.130 allows local users to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion." |
Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update 1 mishandles wildcards in name fields of X.509 certificates, which might allow man-in-the-middle attackers to spoof servers via a crafted c...Show more |