← Back
CWE-20

12,834 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,834)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Phpmyadmin
1Phpmyadmin
May 6, 2026
Mar 1, 2016
N/A· v4
6.8 MEDIUM· v3
5.8 MEDIUM· v2
The checkHTTP function in libraries/Config.class.php in phpMyAdmin 4.5.x before 4.5.5.1 does not verify X.509 certificates from api.github.com SSL servers, which allows man-in-the-middle attackers to spoof these servers...Show more
The checkHTTP function in libraries/Config.class.php in phpMyAdmin 4.5.x before 4.5.5.1 does not verify X.509 certificates from api.github.com SSL servers, which allows man-in-the-middle attackers to spoof these servers and obtain sensitive information via a crafted certificate.Show less
1Wireshark
1Wireshark
May 6, 2026
Feb 28, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The dissect_nhdr_extopt function in epan/dissectors/packet-lbmc.c in the LBMC dissector in Wireshark 2.0.x before 2.0.2 does not validate length values, which allows remote attackers to cause a denial of service (stack-b...Show more
The dissect_nhdr_extopt function in epan/dissectors/packet-lbmc.c in the LBMC dissector in Wireshark 2.0.x before 2.0.2 does not validate length values, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted packet.Show less
1Wireshark
1Wireshark
May 6, 2026
Feb 28, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
wiretap/nettrace_3gpp_32_423.c in the 3GPP TS 32.423 Trace file parser in Wireshark 2.0.x before 2.0.2 does not ensure that a '\0' character is present at the end of certain strings, which allows remote attackers to caus...Show more
wiretap/nettrace_3gpp_32_423.c in the 3GPP TS 32.423 Trace file parser in Wireshark 2.0.x before 2.0.2 does not ensure that a '\0' character is present at the end of certain strings, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted file.Show less
1Wireshark
1Wireshark
May 6, 2026
Feb 28, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
epan/dissectors/packet-hiqnet.c in the HiQnet dissector in Wireshark 2.0.x before 2.0.2 does not validate the data type, which allows remote attackers to cause a denial of service (out-of-bounds read and application cras...Show more
epan/dissectors/packet-hiqnet.c in the HiQnet dissector in Wireshark 2.0.x before 2.0.2 does not validate the data type, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet.Show less
1Wireshark
1Wireshark
May 6, 2026
Feb 28, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
epan/dissectors/packet-http2.c in the HTTP/2 dissector in Wireshark 2.0.x before 2.0.2 does not limit the amount of header data, which allows remote attackers to cause a denial of service (memory consumption or applicati...Show more
epan/dissectors/packet-http2.c in the HTTP/2 dissector in Wireshark 2.0.x before 2.0.2 does not limit the amount of header data, which allows remote attackers to cause a denial of service (memory consumption or application crash) via a crafted packet.Show less
1Wireshark
1Wireshark
May 6, 2026
Feb 28, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
epan/dissectors/packet-x509af.c in the X.509AF dissector in Wireshark 2.0.x before 2.0.2 mishandles the algorithm ID, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
1Squid Cache
1Squid
May 6, 2026
Feb 27, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
http.cc in Squid 4.x before 4.0.7 relies on the HTTP status code after a response-parsing failure, which allows remote HTTP servers to cause a denial of service (assertion failure and daemon exit) via a malformed respons...Show more
http.cc in Squid 4.x before 4.0.7 relies on the HTTP status code after a response-parsing failure, which allows remote HTTP servers to cause a denial of service (assertion failure and daemon exit) via a malformed response.Show less
1Squid Cache
1Squid
May 6, 2026
Feb 27, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
http.cc in Squid 3.x before 3.5.15 and 4.x before 4.0.7 proceeds with the storage of certain data after a response-parsing failure, which allows remote HTTP servers to cause a denial of service (assertion failure and dae...Show more
http.cc in Squid 3.x before 3.5.15 and 4.x before 4.0.7 proceeds with the storage of certain data after a response-parsing failure, which allows remote HTTP servers to cause a denial of service (assertion failure and daemon exit) via a malformed response.Show less
1Squid Cache
1Squid
May 6, 2026
Feb 27, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Edge Side Includes (ESI) parser in Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not check buffer limits during XML parsing, which allows remote HTTP servers to cause a denial of service (assertion failure and da...Show more
The Edge Side Includes (ESI) parser in Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not check buffer limits during XML parsing, which allows remote HTTP servers to cause a denial of service (assertion failure and daemon exit) via a crafted XML document, related to esi/CustomParser.cc and esi/CustomParser.h.Show less
1Squid Cache
1Squid
May 6, 2026
Feb 27, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not properly append data to String objects, which allows remote servers to cause a denial of service (assertion failure and daemon exit) via a long string, as demonstrate...Show more
Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not properly append data to String objects, which allows remote servers to cause a denial of service (assertion failure and daemon exit) via a long string, as demonstrated by a crafted HTTP Vary header.Show less
1Is My Json Valid Project
1Is My Json Valid
May 6, 2026
Feb 23, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The is-my-json-valid package before 2.12.4 for Node.js has an incorrect exports['utc-millisec'] regular expression, which allows remote attackers to cause a denial of service (blocked event loop) via a crafted string.
1Linecorp
1Line
May 6, 2026
Feb 19, 2016
N/A· v4
5.7 MEDIUM· v3
3.5 LOW· v2
LINE 4.3.0.724 and earlier on Windows and 4.3.1 and earlier on OS X allows remote authenticated users to cause a denial of service (application crash) via a crafted post that is mishandled when displaying a Timeline.
4Debian
FedoraprojectOracle+1 more
4Debian Linux
FedoraVm Server+1 more
May 6, 2026
Feb 19, 2016
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
Xen 4.6.x and earlier allows local guest administrators to cause a denial of service (host reboot) via vectors related to multiple mappings of MMIO pages with different cachability settings.
1Hp
1Hp Ux Ipfilter
May 6, 2026
Feb 18, 2016
N/A· v4
5.9 MEDIUM· v3
2.6 LOW· v2
HPE IPFilter A.11.31.18.21 on HP-UX, when a certain keep-state configuration is enabled, allows remote attackers to cause a denial of service via unspecified UDP packets.
1Cisco
1Small Business Wireless Access Points Firmware
May 6, 2026
Feb 17, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Cisco Small Business 500 Wireless Access Point devices with firmware 1.0.4.4 allow remote attackers to set the system time via a crafted POST request, aka Bug ID CSCuy01457.
1Cybozu
1Office
May 6, 2026
Feb 17, 2016
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
customapp in Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to cause a denial of service via unspecified vectors, a different vulnerability than CVE-2015-8489.
1Cybozu
1Office
May 6, 2026
Feb 17, 2016
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
customapp in Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to cause a denial of service (excessive database locking) via a crafted CSV file, a different vulnerability than CVE-2016-1153.
1Ibm
1Emptoris Contract Management
May 6, 2026
Feb 15, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Emptoris Contract Management 9.5.0.x before 9.5.0.6 iFix15, 10.0.0.x and 10.0.1.x before 10.0.1.5 iFix5, 10.0.2.x before 10.0.2.7 iFix4, and 10.0.4.x before 10.0.4.0 iFix3 allows remote attackers to execute arbitrary...Show more
IBM Emptoris Contract Management 9.5.0.x before 9.5.0.6 iFix15, 10.0.0.x and 10.0.1.x before 10.0.1.5 iFix5, 10.0.2.x before 10.0.2.7 iFix4, and 10.0.4.x before 10.0.4.0 iFix3 allows remote attackers to execute arbitrary code by including a crafted Flash file.Show less
1Adobe
1Connect
May 6, 2026
Feb 10, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Adobe Connect before 9.5.2 allows remote attackers to spoof the user interface via unspecified vectors.
1Microsoft
2Windows Server 2008
Windows Server 2012
May 6, 2026
Feb 10, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Network Policy Server (NPS) in Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold and R2 misparses username queries, which allows remote attackers to cause a denial of service (RADIUS authentication outage...Show more
Network Policy Server (NPS) in Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold and R2 misparses username queries, which allows remote attackers to cause a denial of service (RADIUS authentication outage) via crafted requests, aka "Network Policy Server RADIUS Implementation Denial of Service Vulnerability."Show less