CWE-20
12,832 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,832)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The picture_Release function in misc/picture.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service (write access violation) via a crafted M2V file. |
The picture_pool_Delete function in misc/picture_pool.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service (DEP violation and application crash) via a crafte...Show more |
2Broadcom Symantec2Data Center Security Symantec Critical System ProtectionMay 6, 2026 Jan 21, 2015 N/A· v4 N/A· v3 9.0 HIGH· v2 The Agent Control Interface in the management server in Symantec Critical System Protection (SCSP) 5.2.9 before MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x before 6.0 MP1 allows remote authenti...Show more |
1Ibm 1Security Network Protection Xgs Firmware May 6, 2026 Jan 17, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 IBM Security Network Protection 5.1.x and 5.2.x before 5.2.0.0 FP5 and 5.3.x before 5.3.0.0 FP1 allows remote attackers to conduct clickjacking attacks via unspecified vectors. |
The vmd_decode function in libavcodec/vmdvideo.c in FFmpeg before 2.5.2 does not validate the relationship between a certain length value and the frame width, which allows remote attackers to cause a denial of service (o...Show more |
4Fedoraproject OpensuseOracle+1 more4Fedora OpensusePillow+1 moreMay 6, 2026 Jan 16, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that has a large size when it is decompressed. |
The Juniper MX Series routers with Junos 13.3R3 through 13.3Rx before 13.3R6, 14.1 before 14.1R4, 14.1X50 before 14.1X50-D70, and 14.2 before 14.2R2, when configured as a broadband edge (BBE) router, allows remote attack...Show more |
2Litech Openstack2Neutron Router Advertisement DaemonMay 6, 2026 Jan 15, 2015 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The L3 agent in OpenStack Neutron 2014.2.x before 2014.2.2, when using radvd 2.0+, allows remote authenticated users to cause a denial of service (blocked router update processing) by creating eight routers and assigning...Show more |
1Cisco 1Adaptive Security Appliance Software May 6, 2026 Jan 14, 2015 N/A· v4 N/A· v3 5.7 MEDIUM· v2 Cisco Adaptive Security Appliance (ASA) Software, when a DHCPv6 relay is configured, allows remote attackers to cause a denial of service (device reload) via crafted DHCP packets on the local network, aka Bug ID CSCur454...Show more |
1Cisco 1Anyconnect Secure Mobility Client May 6, 2026 Jan 14, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Cisco AnyConnect on Android and OS X does not properly verify the host type, which allows remote attackers to spoof authentication forms and possibly capture credentials via unspecified vectors, aka Bug IDs CSCuo24931 an...Show more |
1Adobe 4Adobe Air Adobe Air SdkAdobe Air Sdk And Compiler+1 moreMay 6, 2026 Jan 13, 2015 N/A· v4 N/A· v3 10.0 HIGH· v2 Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0.0.257 on Windows and OS X and before 11.2.202.429 on Linux, Adobe AIR before 16.0.0.245 on Windows and OS X and before 16.0.0.272 on Android, Adobe A...Show more |
1Malwarebytes 1Malwarebytes Anti Exploit May 6, 2026 Jan 13, 2015 N/A· v4 N/A· v3 2.1 LOW· v2 mbae.sys in Malwarebytes Anti-Exploit before 1.05.1.2014 allows local users to cause a denial of service (crash) via a crafted size in an unspecified IOCTL call, which triggers an out-of-bounds read. NOTE: some of these...Show more |
The High Availability (HA) subsystem in Cisco NX-OS on MDS 9000 devices allows remote attackers to cause a denial of service via crafted traffic, aka Bug ID CSCuo09129. |
2Opensuse Wireshark2Opensuse WiresharkMay 6, 2026 Jan 10, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 epan/dissectors/packet-smtp.c in the SMTP dissector in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 uses an incorrect length value for certain string-append operations, which allows remote attackers to cause...Show more |
3Opensuse OracleWireshark3Opensuse SolarisWiresharkMay 6, 2026 Jan 10, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 asn1/lpp/lpp.cnf in the LPP dissector in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 does not validate a certain index value, which allows remote attackers to cause a denial of service (out-of-bounds memory...Show more |
The outlookpa component in Cisco WebEx Meetings Server does not properly validate API input, which allows remote attackers to modify a meeting's invite list via a crafted URL, aka Bug ID CSCuj40254. |
7Canonical DebianLinux+4 more19Debian Linux Enterprise Linux AusEnterprise Linux Desktop+16 moreMay 6, 2026 Jan 9, 2015 N/A· v4 N/A· v3 2.1 LOW· v2 The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local users to obtain sen...Show more |
The frontend rendering component in TYPO3 4.5.x before 4.5.39, 4.6.x through 6.2.x before 6.2.9, and 7.x before 7.0.2, when config.prefixLocalAnchors is set to all or cached, allows remote attackers to have an unspecifie...Show more |
Hillstone HS TFTP Server 1.3.2 allows remote attackers to cause a denial of service (daemon crash) via a long filename in a (1) RRQ or (2) WRQ operation. |
apinit on Cray devices with CLE before 4.2.UP02 and 5.x before 5.1.UP00 does not use alpsauth data to validate the UID in a launch message, which allows local users to gain privileges via a modified aprun program, aka ID...Show more |