Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2020-12-15 CVE-2020-0368 Improper Input Validation vulnerability in Google Android 11.0
In queryInternal of CallLogProvider.java, there is a possible permission bypass due to improper input validation.
local
low complexity
google CWE-20
3.3
2020-12-11 CVE-2020-17439 Improper Input Validation vulnerability in UIP Project UIP 1.0
An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products.
network
low complexity
uip-project CWE-20
8.3
2020-12-11 CVE-2020-15375 Improper Input Validation vulnerability in Broadcom Fabric Operating System
Brocade Fabric OS versions before v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, v7.4.2g contain an improper input validation weakness in the command line interface when secccrypptocfg is invoked.
local
low complexity
broadcom CWE-20
6.7
2020-12-10 CVE-2020-26270 Improper Input Validation vulnerability in Google Tensorflow
In affected versions of TensorFlow running an LSTM/GRU model where the LSTM/GRU layer receives an input with zero-length results in a CHECK failure when using the CUDA backend.
local
low complexity
google CWE-20
3.3
2020-12-09 CVE-2020-27614 Improper Input Validation vulnerability in Anydesk
AnyDesk for macOS versions 6.0.2 and older have a vulnerability in the XPC interface that does not properly validate client requests and allows local privilege escalation.
local
low complexity
anydesk CWE-20
7.8
2020-12-08 CVE-2020-9977 Improper Input Validation vulnerability in Apple mac OS X
A validation issue existed in the entitlement verification.
local
low complexity
apple CWE-20
5.5
2020-12-03 CVE-2020-5680 Improper Input Validation vulnerability in Ec-Cube
Improper input validation vulnerability in EC-CUBE versions from 3.0.5 to 3.0.18 allows a remote attacker to cause a denial-of-service (DoS) condition via unspecified vector.
network
low complexity
ec-cube CWE-20
7.5
2020-11-24 CVE-2020-26890 Improper Input Validation vulnerability in multiple products
Matrix Synapse before 1.20.0 erroneously permits non-standard NaN, Infinity, and -Infinity JSON values in fields of m.room.member events, allowing remote attackers to execute a denial of service attack against the federation and common Matrix clients.
network
low complexity
matrix fedoraproject CWE-20
7.5
2020-11-23 CVE-2018-16723 Improper Input Validation vulnerability in V-Secure Jingyun Antivirus 2.4.2.39
In Jingyun Antivirus v2.4.2.39, the driver file (ZySandbox.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x12364020.
local
low complexity
v-secure CWE-20
7.8
2020-11-23 CVE-2018-16722 Improper Input Validation vulnerability in V-Secure Jingyun Antivirus 2.4.2.39
In Jingyun Antivirus v2.4.2.39, the driver file (ZySandbox.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x12360094, a related issue to CVE-2018-16305.
local
low complexity
v-secure CWE-20
7.8