Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2020-10-12 CVE-2020-4781 Improper Input Validation vulnerability in IBM Curam Social Program Management 7.0.10.0/7.0.9.0
An improper input validation before calling java readLine() method may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, which could result in a denial of service.
network
low complexity
ibm CWE-20
6.5
2020-10-09 CVE-2020-9105 Improper Input Validation vulnerability in Huawei Taurus-An00B Firmware 10.1.0.156
Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have an insufficient input validation vulnerability.
local
low complexity
huawei CWE-20
6.7
2020-10-08 CVE-2020-3568 Improper Input Validation vulnerability in Cisco Asyncos
A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device.
network
low complexity
cisco CWE-20
5.8
2020-10-08 CVE-2020-3567 Improper Input Validation vulnerability in Cisco Industrial Network Director and Network Level Service
A vulnerability in the management REST API of Cisco Industrial Network Director (IND) could allow an authenticated, remote attacker to cause the CPU utilization to increase to 100 percent, resulting in a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-20
6.5
2020-10-06 CVE-2020-26597 Improper Input Validation vulnerability in Google Android 10.0/9.0
An issue was discovered on LG mobile devices with Android OS 9.0 and 10 software.
network
low complexity
google CWE-20
7.5
2020-10-06 CVE-2020-24807 Improper Input Validation vulnerability in Socket.Io-File Project Socket.Io-File
The socket.io-file package through 2.0.31 for Node.js relies on client-side validation of file types, which allows remote attackers to execute arbitrary code by uploading an executable file via a modified JSON name field.
local
low complexity
socket-io-file-project CWE-20
7.8
2020-10-02 CVE-2020-5986 Improper Input Validation vulnerability in Nvidia Virtual GPU Manager
NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which an input data size is not validated, which may lead to tampering or denial of service.
local
low complexity
nvidia CWE-20
5.5
2020-10-02 CVE-2020-5985 Improper Input Validation vulnerability in Nvidia Virtual GPU Manager
NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which an input data length is not validated, which may lead to tampering or denial of service.
local
low complexity
nvidia CWE-20
7.1
2020-09-30 CVE-2020-15731 Improper Input Validation vulnerability in Bitdefender Engines 7.84063/7.84892/7.84897
An improper Input Validation vulnerability in the code handling file renaming and recovery in Bitdefender Engines allows an attacker to write an arbitrary file in a location hardcoded in a specially-crafted malicious file name.
local
low complexity
bitdefender CWE-20
3.6
2020-09-29 CVE-2020-4607 Improper Input Validation vulnerability in IBM Security Verify Privilege Vault Remote On-Premises 1.3.2
IBM Security Secret Server (IBM Security Verify Privilege Vault Remote 1.2 ) could allow a local user to bypass security restrictions due to improper input validation.
local
low complexity
ibm CWE-20
7.8