← Back
CWE-20

12,832 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,832)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Videolan
1Vlc Media Player
May 6, 2026
Jan 21, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The picture_Release function in misc/picture.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service (write access violation) via a crafted M2V file.
1Videolan
1Vlc Media Player
May 6, 2026
Jan 21, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The picture_pool_Delete function in misc/picture_pool.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service (DEP violation and application crash) via a crafte...Show more
The picture_pool_Delete function in misc/picture_pool.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service (DEP violation and application crash) via a crafted FLV file.Show less
2Broadcom
Symantec
2Data Center Security
Symantec Critical System Protection
May 6, 2026
Jan 21, 2015
N/A· v4
N/A· v3
9.0 HIGH· v2
The Agent Control Interface in the management server in Symantec Critical System Protection (SCSP) 5.2.9 before MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x before 6.0 MP1 allows remote authenti...Show more
The Agent Control Interface in the management server in Symantec Critical System Protection (SCSP) 5.2.9 before MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x before 6.0 MP1 allows remote authenticated users to execute arbitrary commands by leveraging client-system access to upload a log file.Show less
1Ibm
1Security Network Protection Xgs Firmware
May 6, 2026
Jan 17, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
IBM Security Network Protection 5.1.x and 5.2.x before 5.2.0.0 FP5 and 5.3.x before 5.3.0.0 FP1 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
1Ffmpeg
1Ffmpeg
May 6, 2026
Jan 16, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
The vmd_decode function in libavcodec/vmdvideo.c in FFmpeg before 2.5.2 does not validate the relationship between a certain length value and the frame width, which allows remote attackers to cause a denial of service (o...Show more
The vmd_decode function in libavcodec/vmdvideo.c in FFmpeg before 2.5.2 does not validate the relationship between a certain length value and the frame width, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Sierra VMD video data.Show less
4Fedoraproject
OpensuseOracle+1 more
4Fedora
OpensusePillow+1 more
May 6, 2026
Jan 16, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that has a large size when it is decompressed.
1Juniper
1Junos
May 6, 2026
Jan 16, 2015
N/A· v4
N/A· v3
7.1 HIGH· v2
The Juniper MX Series routers with Junos 13.3R3 through 13.3Rx before 13.3R6, 14.1 before 14.1R4, 14.1X50 before 14.1X50-D70, and 14.2 before 14.2R2, when configured as a broadband edge (BBE) router, allows remote attack...Show more
The Juniper MX Series routers with Junos 13.3R3 through 13.3Rx before 13.3R6, 14.1 before 14.1R4, 14.1X50 before 14.1X50-D70, and 14.2 before 14.2R2, when configured as a broadband edge (BBE) router, allows remote attackers to cause a denial of service (jpppd crash and restart) by sending a crafted PAP Authenticate-Request after the PPPoE Discovery and LCP phase are complete.Show less
2Litech
Openstack
2Neutron
Router Advertisement Daemon
May 6, 2026
Jan 15, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The L3 agent in OpenStack Neutron 2014.2.x before 2014.2.2, when using radvd 2.0+, allows remote authenticated users to cause a denial of service (blocked router update processing) by creating eight routers and assigning...Show more
The L3 agent in OpenStack Neutron 2014.2.x before 2014.2.2, when using radvd 2.0+, allows remote authenticated users to cause a denial of service (blocked router update processing) by creating eight routers and assigning an ipv6 non-provider subnet to each.Show less
1Cisco
1Adaptive Security Appliance Software
May 6, 2026
Jan 14, 2015
N/A· v4
N/A· v3
5.7 MEDIUM· v2
Cisco Adaptive Security Appliance (ASA) Software, when a DHCPv6 relay is configured, allows remote attackers to cause a denial of service (device reload) via crafted DHCP packets on the local network, aka Bug ID CSCur454...Show more
Cisco Adaptive Security Appliance (ASA) Software, when a DHCPv6 relay is configured, allows remote attackers to cause a denial of service (device reload) via crafted DHCP packets on the local network, aka Bug ID CSCur45455.Show less
1Cisco
1Anyconnect Secure Mobility Client
May 6, 2026
Jan 14, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Cisco AnyConnect on Android and OS X does not properly verify the host type, which allows remote attackers to spoof authentication forms and possibly capture credentials via unspecified vectors, aka Bug IDs CSCuo24931 an...Show more
Cisco AnyConnect on Android and OS X does not properly verify the host type, which allows remote attackers to spoof authentication forms and possibly capture credentials via unspecified vectors, aka Bug IDs CSCuo24931 and CSCuo24940.Show less
1Adobe
4Adobe Air
Adobe Air SdkAdobe Air Sdk And Compiler+1 more
May 6, 2026
Jan 13, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0.0.257 on Windows and OS X and before 11.2.202.429 on Linux, Adobe AIR before 16.0.0.245 on Windows and OS X and before 16.0.0.272 on Android, Adobe A...Show more
Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0.0.257 on Windows and OS X and before 11.2.202.429 on Linux, Adobe AIR before 16.0.0.245 on Windows and OS X and before 16.0.0.272 on Android, Adobe AIR SDK before 16.0.0.272, and Adobe AIR SDK & Compiler before 16.0.0.272 do not properly validate files, which has unspecified impact and attack vectors.Show less
1Malwarebytes
1Malwarebytes Anti Exploit
May 6, 2026
Jan 13, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
mbae.sys in Malwarebytes Anti-Exploit before 1.05.1.2014 allows local users to cause a denial of service (crash) via a crafted size in an unspecified IOCTL call, which triggers an out-of-bounds read. NOTE: some of these...Show more
mbae.sys in Malwarebytes Anti-Exploit before 1.05.1.2014 allows local users to cause a denial of service (crash) via a crafted size in an unspecified IOCTL call, which triggers an out-of-bounds read. NOTE: some of these details are obtained from third party information.Show less
1Cisco
1Nx Os
May 6, 2026
Jan 10, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The High Availability (HA) subsystem in Cisco NX-OS on MDS 9000 devices allows remote attackers to cause a denial of service via crafted traffic, aka Bug ID CSCuo09129.
2Opensuse
Wireshark
2Opensuse
Wireshark
May 6, 2026
Jan 10, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
epan/dissectors/packet-smtp.c in the SMTP dissector in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 uses an incorrect length value for certain string-append operations, which allows remote attackers to cause...Show more
epan/dissectors/packet-smtp.c in the SMTP dissector in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 uses an incorrect length value for certain string-append operations, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.Show less
3Opensuse
OracleWireshark
3Opensuse
SolarisWireshark
May 6, 2026
Jan 10, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
asn1/lpp/lpp.cnf in the LPP dissector in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 does not validate a certain index value, which allows remote attackers to cause a denial of service (out-of-bounds memory...Show more
asn1/lpp/lpp.cnf in the LPP dissector in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 does not validate a certain index value, which allows remote attackers to cause a denial of service (out-of-bounds memory access and application crash) via a crafted packet.Show less
1Cisco
1Webex Meetings Server
May 6, 2026
Jan 10, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The outlookpa component in Cisco WebEx Meetings Server does not properly validate API input, which allows remote attackers to modify a meeting's invite list via a crafted URL, aka Bug ID CSCuj40254.
7Canonical
DebianLinux+4 more
19Debian Linux
Enterprise Linux AusEnterprise Linux Desktop+16 more
May 6, 2026
Jan 9, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local users to obtain sen...Show more
The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local users to obtain sensitive information from kernel memory via a crafted iso9660 image.Show less
1Typo3
1Typo3
May 6, 2026
Jan 4, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
The frontend rendering component in TYPO3 4.5.x before 4.5.39, 4.6.x through 6.2.x before 6.2.9, and 7.x before 7.0.2, when config.prefixLocalAnchors is set to all or cached, allows remote attackers to have an unspecifie...Show more
The frontend rendering component in TYPO3 4.5.x before 4.5.39, 4.6.x through 6.2.x before 6.2.9, and 7.x before 7.0.2, when config.prefixLocalAnchors is set to all or cached, allows remote attackers to have an unspecified impact (possibly resource consumption) via a "Cache Poisoning" attack using a URL with arbitrary arguments, which triggers a reload of the page.Show less
1Hillstone Software
1Hs Tftp Server
May 6, 2026
Dec 28, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Hillstone HS TFTP Server 1.3.2 allows remote attackers to cause a denial of service (daemon crash) via a long filename in a (1) RRQ or (2) WRQ operation.
1Cray
1Cray Linux Environment
May 6, 2026
Dec 27, 2014
N/A· v4
N/A· v3
7.2 HIGH· v2
apinit on Cray devices with CLE before 4.2.UP02 and 5.x before 5.1.UP00 does not use alpsauth data to validate the UID in a launch message, which allows local users to gain privileges via a modified aprun program, aka ID...Show more
apinit on Cray devices with CLE before 4.2.UP02 and 5.x before 5.1.UP00 does not use alpsauth data to validate the UID in a launch message, which allows local users to gain privileges via a modified aprun program, aka ID FN5912.Show less