CWE-20
12,834 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,834)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Hp 2Operations Orchestration Operations Orchestration ContentMay 6, 2026 Mar 22, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 HPE Operations Orchestration 10.x before 10.51 and Operations Orchestration content before 1.7.0 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Co...Show more |
The MPEG4Source::fragmentedRead function in MPEG4Extractor.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 allows remote attackers to execute arbitrary...Show more |
1Cisco 1Telepresence Video Communication Server Software May 6, 2026 Mar 12, 2016 N/A· v4 6.5 MEDIUM· v3 8.0 HIGH· v2 Cisco TelePresence Video Communication Server (VCS) X8.5.1 and X8.5.2 allows remote authenticated users to cause a denial of service (VoIP outage) via a crafted SIP message, aka Bug ID CSCuu43026. |
resolver.c in named in ISC BIND 9.10.x before 9.10.3-P4, when DNS cookies are enabled, allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via a malformed packet with more than...Show more |
3Canonical DebianIsc3Debian Linux DhcpUbuntu LinuxMay 6, 2026 Mar 9, 2016 N/A· v4 5.9 MEDIUM· v3 7.1 HIGH· v2 ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4 does not restrict the number of concurrent TCP sessions, which allows remote attackers to cause a denial of service (INSIST assertion failure or request-...Show more |
1Adobe 4Acrobat Acrobat DcAcrobat Reader+1 moreMay 6, 2026 Mar 9, 2016 N/A· v4 8.4 HIGH· v3 7.2 HIGH· v2 Untrusted search path vulnerability in Adobe Reader and Acrobat before 11.0.15, Acrobat and Acrobat Reader DC Classic before 15.006.30121, and Acrobat and Acrobat Reader DC Continuous before 15.010.20060 on Windows and O...Show more |
Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 mishandles signature validation for unspecified elements of XML documents, which allows remote attackers to spoof signatures via a modified doc...Show more |
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreMay 6, 2026 Mar 9, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote a...Show more |
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreMay 6, 2026 Mar 9, 2016 N/A· v4 6.5 MEDIUM· v3 7.1 HIGH· v2 The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote a...Show more |
The PDF library in Microsoft Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted PDF document, aka "Windows Remote Code Execution Vulnerability." |
1Microsoft 4Windows 10 Windows 8.1Windows Rt 8.1+1 moreMay 6, 2026 Mar 9, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 The PDF library in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted PDF document, aka "Windows Remote Co...Show more |
1Microsoft 6Windows 10 Windows 7Windows 8.1+3 moreMay 6, 2026 Mar 9, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow remote attackers to execute arbitrary code via crafted media content,...Show more |
1Microsoft 2Windows Server 2008 Windows VistaMay 6, 2026 Mar 9, 2016 N/A· v4 8.4 HIGH· v3 7.2 HIGH· v2 Microsoft Windows Vista SP2 and Server 2008 SP2 mishandle library loading, which allows local users to gain privileges via a crafted application, aka "Library Loading Input Validation Remote Code Execution Vulnerability....Show more |
1Microsoft 6Windows 10 Windows 7Windows 8.1+3 moreMay 6, 2026 Mar 9, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 allow remote attackers to execute arbitrary code via crafted media content, aka "Windows M...Show more |
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreMay 6, 2026 Mar 9, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 OLE in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitra...Show more |
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreMay 6, 2026 Mar 9, 2016 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 OLE in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitra...Show more |
WebKit/Source/core/layout/LayoutBlock.cpp in Blink, as used in Google Chrome before 49.0.2623.75, does not properly determine when anonymous block wrappers may exist, which allows remote attackers to cause a denial of se...Show more |
Cisco Prime Infrastructure 3.0 allows remote authenticated users to execute arbitrary code via a crafted HTTP request that is mishandled during viewing of a log file, aka Bug ID CSCuw81494. |
The HTTPS Proxy feature in Cisco AsyncOS before 8.5.3-051 and 9.x before 9.0.0-485 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (service outage) by leveraging certain intra...Show more |
Cisco NX-OS 7.1(1)N1(1) on Nexus 5500, 5600, and 6000 devices does not properly validate PDUs in SNMP packets, which allows remote attackers to cause a denial of service (SNMP application restart) via a crafted packet, a...Show more |