Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2020-09-16 CVE-2020-24376 Improper Input Validation vulnerability in Free products
A DNS rebinding vulnerability in the UPnP IGD implementations in Freebox v5 before 1.5.29 and Freebox Server before 4.2.3.
network
low complexity
free CWE-20
critical
9.6
2020-09-16 CVE-2020-24374 Improper Input Validation vulnerability in Free Freebox HD Firmware
A DNS rebinding vulnerability in Freebox v5 before 1.5.29.
network
low complexity
free CWE-20
critical
9.6
2020-09-16 CVE-2020-10715 Improper Input Validation vulnerability in Redhat Openshift
A content spoofing vulnerability was found in the openshift/console 3.11 and 4.x.
network
low complexity
redhat CWE-20
4.3
2020-09-16 CVE-2020-25614 Improper Input Validation vulnerability in Xmlquery Project Xmlquery
xmlquery before 1.3.1 lacks a check for whether a LoadURL response is in the XML format, which allows attackers to cause a denial of service (SIGSEGV) at xmlquery.(*Node).InnerText or possibly have unspecified other impact.
network
low complexity
xmlquery-project CWE-20
critical
9.8
2020-09-14 CVE-2020-13317 Improper Input Validation vulnerability in Gitlab
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8, and 13.3.4.
network
low complexity
gitlab CWE-20
4.9
2020-09-11 CVE-2020-9239 Improper Input Validation vulnerability in Huawei products
Huawei smartphones BLA-A09 versions 8.0.0.123(C212),versions earlier than 8.0.0.123(C567),versions earlier than 8.0.0.123(C797);BLA-TL00B versions earlier than 8.1.0.326(C01);Berkeley-L09 versions earlier than 8.0.0.163(C10),versions earlier than 8.0.0.163(C432),Versions earlier than 8.0.0.163(C636),Versions earlier than 8.0.0.172(C10);Duke-L09 versions Duke-L09C10B187, versions Duke-L09C432B189, versions Duke-L09C636B189;HUAWEI P20 versions earlier than 8.0.1.16(C00);HUAWEI P20 Pro versions earlier than 8.1.0.152(C00);Jimmy-AL00A versions earlier than Jimmy-AL00AC00B172;LON-L29D versions LON-L29DC721B192;NEO-AL00D versions earlier than 8.1.0.172(C786);Stanford-AL00 versions Stanford-AL00C00B123;Toronto-AL00 versions earlier than Toronto-AL00AC00B225;Toronto-AL00A versions earlier than Toronto-AL00AC00B225;Toronto-TL10 versions earlier than Toronto-TL10C01B225 have an information vulnerability.
local
low complexity
huawei CWE-20
5.5
2020-09-09 CVE-2020-24074 Improper Input Validation vulnerability in Silk-V3-Decoder Project Silk-V3-Decoder 20160922
The decode program in silk-v3-decoder Version:20160922 Build By kn007 does not strictly check data, resulting in a buffer overflow.
network
low complexity
silk-v3-decoder-project CWE-20
critical
9.8
2020-09-09 CVE-2020-6348 Improper Input Validation vulnerability in SAP 3D Visual Enterprise Viewer 9
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated GIF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.
network
low complexity
sap CWE-20
4.3
2020-09-09 CVE-2020-6344 Improper Input Validation vulnerability in SAP 3D Visual Enterprise Viewer 9
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PDF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.
network
low complexity
sap CWE-20
4.3
2020-09-09 CVE-2020-6338 Improper Input Validation vulnerability in SAP 3D Visual Enterprise Viewer 9
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated RH file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.
network
low complexity
sap CWE-20
4.3