← Back
CWE-20

12,840 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,840)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Squid Cache
1Squid
May 6, 2026
Apr 19, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The FwdState::connectedToPeer method in FwdState.cc in Squid before 3.5.14 and 4.0.x before 4.0.6 does not properly handle SSL handshake errors when built with the --with-openssl option, which allows remote attackers to...Show more
The FwdState::connectedToPeer method in FwdState.cc in Squid before 3.5.14 and 4.0.x before 4.0.6 does not properly handle SSL handshake errors when built with the --with-openssl option, which allows remote attackers to cause a denial of service (application crash) via a plaintext HTTP message.Show less
1Huawei
1Ar3200 Firmware
May 6, 2026
Apr 18, 2016
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
Huawei AR3200 routers with software before V200R006C10SPC300 allow remote authenticated users to cause a denial of service (restart) via crafted packets.
2Fedoraproject
Libreswan
2Fedora
Libreswan
May 6, 2026
Apr 18, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Libreswan 3.16 might allow remote attackers to cause a denial of service (daemon restart) via an IKEv2 aes_xcbc transform.
5Canonical
DebianGoogle+2 more
5Chrome
Debian LinuxLeap+2 more
May 6, 2026
Apr 18, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The media subsystem in Google Chrome before 50.0.2661.75 does not initialize an unspecified data structure, which allows remote attackers to cause a denial of service (invalid read operation) via unknown vectors.
1Google
1Android
May 6, 2026
Apr 18, 2016
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
server/content/SyncStorageEngine.java in SyncStorageEngine in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 mismanages certain authority data, which allows attackers to cause...Show more
server/content/SyncStorageEngine.java in SyncStorageEngine in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 mismanages certain authority data, which allows attackers to cause a denial of service (reboot loop) via a crafted application, aka internal bug 26513719.Show less
1Google
1Android
May 6, 2026
Apr 18, 2016
N/A· v4
6.2 MEDIUM· v3
4.9 MEDIUM· v2
The Minikin library in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not properly consider negative size values in font data, which allows remote attackers to cause a denial of service (m...Show more
The Minikin library in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not properly consider negative size values in font data, which allows remote attackers to cause a denial of service (memory corruption and reboot loop) via a crafted font, aka internal bug 26413177.Show less
1Google
1Android
May 6, 2026
Apr 18, 2016
N/A· v4
6.5 MEDIUM· v3
9.3 HIGH· v2
A Qualcomm Power Management kernel driver in Android 6.x before 2016-04-01 allows attackers to gain privileges via a crafted application that leverages root access, aka internal bug 26866053.
1Google
1Android
May 6, 2026
Apr 18, 2016
N/A· v4
8.4 HIGH· v3
10.0 HIGH· v2
An unspecified media codec in mediaserver in Android 6.x before 2016-04-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 262...Show more
An unspecified media codec in mediaserver in Android 6.x before 2016-04-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 26220548.Show less
2Canonical
Xen
2Ubuntu Linux
Xen
May 6, 2026
Apr 15, 2016
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Xen and the Linux kernel through 4.5.x do not properly suppress hugetlbfs support in x86 PV guests, which allows local PV guest OS users to cause a denial of service (guest OS crash) by attempting to access a hugetlbfs m...Show more
Xen and the Linux kernel through 4.5.x do not properly suppress hugetlbfs support in x86 PV guests, which allows local PV guest OS users to cause a denial of service (guest OS crash) by attempting to access a hugetlbfs mapped area.Show less
2Fedoraproject
Uninett
2Fedora
Mod Auth Mellon
May 6, 2026
Apr 15, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The am_read_post_data function in mod_auth_mellon before 0.11.1 does not check if the ap_get_client_block function returns an error, which allows remote attackers to cause a denial of service (segmentation fault and proc...Show more
The am_read_post_data function in mod_auth_mellon before 0.11.1 does not check if the ap_get_client_block function returns an error, which allows remote attackers to cause a denial of service (segmentation fault and process crash) via a crafted POST data.Show less
1Juniper
1Junos
May 6, 2026
Apr 15, 2016
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Juniper Junos OS before 12.1X46-D45, 12.1X47 before 12.1X47-D30, 12.3 before 12.3R11, 12.3X48 before 12.3X48-D25, 13.2 before 13.2R8, 13.3 before 13.3R7, 14.1 before 14.1R6, 14.2 before 14.2R4, 15.1 before 15.1R1 or 15.1...Show more
Juniper Junos OS before 12.1X46-D45, 12.1X47 before 12.1X47-D30, 12.3 before 12.3R11, 12.3X48 before 12.3X48-D25, 13.2 before 13.2R8, 13.3 before 13.3R7, 14.1 before 14.1R6, 14.2 before 14.2R4, 15.1 before 15.1R1 or 15.1F2, and 15.1X49 before 15.1X49-D15 allow local users to gain privileges via crafted combinations of CLI commands and arguments, a different vulnerability than CVE-2015-3003, CVE-2014-3816, and CVE-2014-0615.Show less
1Juniper
1Screenos
May 6, 2026
Apr 15, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
The administrative web services interface in Juniper ScreenOS before 6.3.0r21 allows remote attackers to cause a denial of service (reboot) via a crafted SSL packet.
1Dell
1Emc Unisphere
May 6, 2026
Apr 15, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An HTTP servlet in vApp Manager in EMC Unisphere for VMAX Virtual Appliance before 8.2.0 allows remote attackers to write to arbitrary files via a crafted pathname.
6Debian
FedoraprojectMercurial+3 more
14Debian Linux
Enterprise Linux DesktopEnterprise Linux Hpc Node+11 more
May 6, 2026
Apr 13, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted name when converting a Git repository.
6Debian
FedoraprojectMercurial+3 more
14Debian Linux
Enterprise Linux DesktopEnterprise Linux Hpc Node+11 more
May 6, 2026
Apr 13, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted git ext:: URL when cloning a subrepository.
4Canonical
DebianNovell+1 more
5Debian Linux
Suse Linux Enterprise DebuginfoSuse Linux Enterprise Real Time Extension+2 more
May 6, 2026
Apr 13, 2016
N/A· v4
4.4 MEDIUM· v3
1.7 LOW· v2
The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to generate a continuous stream of WARN messages and cause a denial...Show more
The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to generate a continuous stream of WARN messages and cause a denial of service (disk consumption) by leveraging a system with access to a passed-through MSI or MSI-X capable physical PCI device and XEN_PCI_OP_enable_msi operations, aka "Linux pciback missing sanity checks."Show less
4Canonical
Git ProjectOpensuse+1 more
4Git
OpensuseSoftware Collections+1 more
May 6, 2026
Apr 13, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 do not properly restrict the allowed protocols, which might al...Show more
The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 do not properly restrict the allowed protocols, which might allow remote attackers to execute arbitrary code via a URL in a (a) .gitmodules file or (b) unknown other sources in a submodule.Show less
1Huawei
2Mate S Firmware
P8 Firmware
May 6, 2026
Apr 13, 2016
N/A· v4
6.1 MEDIUM· v3
7.8 HIGH· v2
The Video0 driver in Huawei P8 smartphones with software GRA-UL00 before GRA-UL00C00B350, GRA-UL10 before GRA-UL10C00B350, GRA-TL00 before GRA-TL00C01B350, GRA-CL00 before GRA-CL00C92B350, and GRA-CL10 before GRA-CL10C92...Show more
The Video0 driver in Huawei P8 smartphones with software GRA-UL00 before GRA-UL00C00B350, GRA-UL10 before GRA-UL10C00B350, GRA-TL00 before GRA-TL00C01B350, GRA-CL00 before GRA-CL00C92B350, and GRA-CL10 before GRA-CL10C92B350 and Mate S smartphones with software CRR-TL00 before CRR-TL00C01B160SP01, CRR-UL00 before CRR-UL00C00B160, and CRR-CL00 before CRR-CL00C92B161 allows attackers to obtain sensitive information from stack memory or cause a denial of service (system crash) via a crafted application, which triggers an invalid memory access.Show less
1Cisco
1Ios Xr
May 6, 2026
Apr 12, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Cisco IOS XR 4.2.3, 4.3.0, 4.3.4, and 5.3.1 on ASR 9000 devices allows remote attackers to cause a denial of service (CRC and symbol errors, and interface flap) via crafted bit patterns in packets, aka Bug ID CSCuv78548.
1Microsoft
1Xml Core Services
May 6, 2026
Apr 12, 2016
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
Microsoft XML Core Services 3.0 allows remote attackers to execute arbitrary code via a crafted web site, aka "MSXML 3.0 Remote Code Execution Vulnerability."