Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2020-11-12 CVE-2020-11201 Improper Input Validation vulnerability in Qualcomm products
Arbitrary access to DSP memory due to improper check in loaded library for data received from CPU side' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in QCM6125, QCS410, QCS603, QCS605, QCS610, QCS6125, SA6145P, SA6155, SA6155P, SA8155, SA8155P, SDA640, SDA845, SDM640, SDM830, SDM845, SDX50M, SDX55, SDX55M, SM6125, SM6150, SM6250, SM6250P, SM7125, SM7150, SM7150P, SM8150, SM8150P
local
low complexity
qualcomm CWE-20
7.8
2020-11-10 CVE-2020-0442 Improper Input Validation vulnerability in Google Android
In Message and toBundle of Notification.java, there is a possible UI slowdown or crash due to improper input validation.
network
low complexity
google CWE-20
7.5
2020-11-09 CVE-2020-8268 Improper Input Validation vulnerability in Json8-Merge-Patch Project Json8-Merge-Patch
Prototype pollution vulnerability in json8-merge-patch npm package < 1.0.3 may allow attackers to inject or modify methods and properties of the global object constructor.
network
low complexity
json8-merge-patch-project CWE-20
7.5
2020-11-09 CVE-2020-28349 Improper Input Validation vulnerability in Chirpstack Network Server 3.9.0
An inaccurate frame deduplication process in ChirpStack Network Server 3.9.0 allows a malicious gateway to perform uplink Denial of Service via malformed frequency attributes in CollectAndCallOnceCollect in internal/uplink/collect.go.
network
low complexity
chirpstack CWE-20
6.5
2020-11-06 CVE-2020-5643 Improper Input Validation vulnerability in Cybozu Garoon 5.0.0/5.0.1/5.0.2
Improper input validation vulnerability in Cybozu Garoon 5.0.0 to 5.0.2 allows a remote authenticated attacker to delete some data of the bulletin board via unspecified vector.
network
low complexity
cybozu CWE-20
6.5
2020-11-03 CVE-2020-15983 Improper Input Validation vulnerability in multiple products
Insufficient data validation in webUI in Google Chrome on ChromeOS prior to 86.0.4240.75 allowed a local attacker to bypass content security policy via a crafted HTML page.
local
low complexity
google fedoraproject debian opensuse CWE-20
7.8
2020-11-03 CVE-2020-15978 Improper Input Validation vulnerability in multiple products
Insufficient data validation in navigation in Google Chrome on Android prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page.
network
low complexity
google debian fedoraproject opensuse CWE-20
8.8
2020-11-03 CVE-2020-15977 Improper Input Validation vulnerability in multiple products
Insufficient data validation in dialogs in Google Chrome on OS X prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive information from disk via a crafted HTML page.
network
low complexity
google debian fedoraproject opensuse CWE-20
6.5
2020-10-27 CVE-2019-8857 Improper Input Validation vulnerability in Apple Iphone OS
The issue was addressed with improved validation when an iCloud Link is created.
local
low complexity
apple CWE-20
3.3
2020-10-27 CVE-2019-8853 Improper Input Validation vulnerability in Apple mac OS X
A validation issue was addressed with improved input sanitization.
local
low complexity
apple CWE-20
5.5