← Back
CWE-20

12,832 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

JSON object

Loading...

CVEs (12,832)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mozilla
3Firefox
SeamonkeyThunderbird
May 6, 2026
Dec 11, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and SeaMonkey before 2.31 allow remote attackers to cause a denial of serv...Show more
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and SeaMonkey before 2.31 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.Show less
1Isc
1Bind
May 6, 2026
Dec 11, 2014
N/A· v4
N/A· v3
5.4 MEDIUM· v2
The GeoIP functionality in ISC BIND 9.10.0 through 9.10.1 allows remote attackers to cause a denial of service (assertion failure and named exit) via vectors related to (1) the lack of GeoIP databases for both IPv4 and I...Show more
The GeoIP functionality in ISC BIND 9.10.0 through 9.10.1 allows remote attackers to cause a denial of service (assertion failure and named exit) via vectors related to (1) the lack of GeoIP databases for both IPv4 and IPv6, or (2) IPv6 support with certain options.Show less
1Microsoft
1Internet Explorer
May 6, 2026
Dec 11, 2014
N/A· v4
N/A· v3
9.3 HIGH· v2
Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
1Microsoft
1Internet Explorer
May 6, 2026
Dec 11, 2014
N/A· v4
N/A· v3
9.3 HIGH· v2
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a differe...Show more
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-6327 and CVE-2014-6329.Show less
1Microsoft
1Internet Explorer
May 6, 2026
Dec 11, 2014
N/A· v4
N/A· v3
9.3 HIGH· v2
Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
1Microsoft
1Internet Explorer
May 6, 2026
Dec 11, 2014
N/A· v4
N/A· v3
9.3 HIGH· v2
Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
1Microsoft
1Internet Explorer
May 6, 2026
Dec 11, 2014
N/A· v4
N/A· v3
9.3 HIGH· v2
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
1Microsoft
1Internet Explorer
May 6, 2026
Dec 11, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Microsoft Internet Explorer 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."
1Microsoft
1Internet Explorer
May 6, 2026
Dec 11, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Microsoft Internet Explorer 8 through 11 allows remote attackers to bypass the XSS filter via a crafted attribute of an element in an HTML document, aka "Internet Explorer XSS Filter Bypass Vulnerability," a different vu...Show more
Microsoft Internet Explorer 8 through 11 allows remote attackers to bypass the XSS filter via a crafted attribute of an element in an HTML document, aka "Internet Explorer XSS Filter Bypass Vulnerability," a different vulnerability than CVE-2014-6328.Show less
1Microsoft
1Exchange Server
May 6, 2026
Dec 11, 2014
N/A· v4
N/A· v3
3.5 LOW· v2
Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 6 does not properly validate redirection tokens, which allows remote attackers to redirect users to arbitrary web sites and spoof the orig...Show more
Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 6 does not properly validate redirection tokens, which allows remote attackers to redirect users to arbitrary web sites and spoof the origin of e-mail messages via unspecified vectors, aka "Exchange URL Redirection Vulnerability."Show less
1Microsoft
1Internet Explorer
May 6, 2026
Dec 11, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Microsoft Internet Explorer 8 through 11 allows remote attackers to bypass the XSS filter via a crafted attribute of an element in an HTML document, aka "Internet Explorer XSS Filter Bypass Vulnerability," a different vu...Show more
Microsoft Internet Explorer 8 through 11 allows remote attackers to bypass the XSS filter via a crafted attribute of an element in an HTML document, aka "Internet Explorer XSS Filter Bypass Vulnerability," a different vulnerability than CVE-2014-6365.Show less
1Microsoft
1Internet Explorer
May 6, 2026
Dec 11, 2014
N/A· v4
N/A· v3
9.3 HIGH· v2
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a differe...Show more
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-6329 and CVE-2014-6376.Show less
1Cisco
1Unified Communications Domain Manager
May 6, 2026
Dec 10, 2014
N/A· v4
N/A· v3
6.5 MEDIUM· v2
The web framework in Cisco Unified Communications Domain Manager 8 allows remote authenticated administrators to execute arbitrary OS commands via crafted values, aka Bug ID CSCuq50205.
1Cisco
1Unified Computing System
May 6, 2026
Dec 10, 2014
N/A· v4
N/A· v3
7.2 HIGH· v2
Cisco Integrated Management Controller in Cisco Unified Computing System 2.2(2c)A and earlier allows local users to obtain shell access via a crafted map-nfs command, aka Bug ID CSCup05998.
1Apple
3Iphone Os
SafariTvos
May 6, 2026
Dec 10, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
WebKit in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1 allows remote attackers to bypass the Same Origin Policy via crafted Cascading Style Sheets (CSS) token sequences within an SVG file in the SRC...Show more
WebKit in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1 allows remote attackers to bypass the Same Origin Policy via crafted Cascading Style Sheets (CSS) token sequences within an SVG file in the SRC attribute of an IMG element.Show less
1Teeworlds
1Teeworlds
May 6, 2026
Dec 9, 2014
N/A· v4
N/A· v3
6.4 MEDIUM· v2
engine/server/server.cpp in Teeworlds 0.6.x before 0.6.3 allows remote attackers to read memory and cause a denial of service (crash) via unspecified vectors.
1Autodesk
1Design Review
May 6, 2026
Dec 8, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The AdView.AdViewer.1 ActiveX control in Autodesk Design Review (ADR) before 2013 Hotfix 1 allows remote attackers to execute arbitrary code via a crafted DWF file.
1Pyyaml
1Libyaml
May 6, 2026
Dec 8, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
scanner.c in LibYAML 0.1.5 and 0.1.6, as used in the YAML-LibYAML (aka YAML-XS) module for Perl, allows context-dependent attackers to cause a denial of service (assertion failure and crash) via vectors involving line-wr...Show more
scanner.c in LibYAML 0.1.5 and 0.1.6, as used in the YAML-LibYAML (aka YAML-XS) module for Perl, allows context-dependent attackers to cause a denial of service (assertion failure and crash) via vectors involving line-wrapping.Show less
1Yokogawa
1Fast/tools
May 6, 2026
Dec 6, 2014
N/A· v4
N/A· v3
3.2 LOW· v2
XML external entity (XXE) vulnerability in the WebHMI server in Yokogawa Electric Corporation FAST/TOOLS before R9.05-SP2 allows local users to cause a denial of service (CPU or network traffic consumption) or read arbit...Show more
XML external entity (XXE) vulnerability in the WebHMI server in Yokogawa Electric Corporation FAST/TOOLS before R9.05-SP2 allows local users to cause a denial of service (CPU or network traffic consumption) or read arbitrary files via unspecified vectors.Show less
3Canonical
DebianGnu
3Debian Linux
GlibcUbuntu Linux
May 6, 2026
Dec 5, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
iconvdata/ibm930.c in GNU C Library (aka glibc) before 2.16 allows context-dependent attackers to cause a denial of service (out-of-bounds read) via a multibyte character value of "0xffff" to the iconv function when conv...Show more
iconvdata/ibm930.c in GNU C Library (aka glibc) before 2.16 allows context-dependent attackers to cause a denial of service (out-of-bounds read) via a multibyte character value of "0xffff" to the iconv function when converting IBM930 encoded data to UTF-8.Show less