Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2020-09-17 CVE-2020-0320 Improper Input Validation vulnerability in Google Android 11.0
In libstagefright, there is a possible resource exhaustion due to improper input validation.
network
low complexity
google CWE-20
6.5
2020-09-17 CVE-2020-0301 Improper Input Validation vulnerability in Google Android 11.0
In libstagefright, there is a possible resource exhaustion due to improper input validation.
network
low complexity
google CWE-20
6.5
2020-09-17 CVE-2020-0287 Improper Input Validation vulnerability in Google Android 11.0
In libmkvextractor, there is a possible resource exhaustion due to a missing bounds check.
network
low complexity
google CWE-20
6.5
2020-09-17 CVE-2020-14338 Improper Input Validation vulnerability in Redhat Xerces 2.11.0/2.12.0
A flaw was found in Wildfly's implementation of Xerces, specifically in the way the XMLSchemaValidator class in the JAXP component of Wildfly enforced the "use-grammar-pool-only" feature.
network
low complexity
redhat CWE-20
5.3
2020-09-16 CVE-2020-24377 Improper Input Validation vulnerability in Free products
A DNS rebinding vulnerability in the Freebox OS web interface in Freebox Server before 4.2.3.
network
low complexity
free CWE-20
critical
9.6
2020-09-16 CVE-2020-24376 Improper Input Validation vulnerability in Free products
A DNS rebinding vulnerability in the UPnP IGD implementations in Freebox v5 before 1.5.29 and Freebox Server before 4.2.3.
network
low complexity
free CWE-20
critical
9.6
2020-09-16 CVE-2020-24374 Improper Input Validation vulnerability in Free Freebox HD Firmware
A DNS rebinding vulnerability in Freebox v5 before 1.5.29.
network
low complexity
free CWE-20
critical
9.6
2020-09-16 CVE-2020-10715 Improper Input Validation vulnerability in Redhat Openshift
A content spoofing vulnerability was found in the openshift/console 3.11 and 4.x.
network
low complexity
redhat CWE-20
4.3
2020-09-16 CVE-2020-25614 Improper Input Validation vulnerability in Xmlquery Project Xmlquery
xmlquery before 1.3.1 lacks a check for whether a LoadURL response is in the XML format, which allows attackers to cause a denial of service (SIGSEGV) at xmlquery.(*Node).InnerText or possibly have unspecified other impact.
network
low complexity
xmlquery-project CWE-20
critical
9.8
2020-09-14 CVE-2020-13317 Improper Input Validation vulnerability in Gitlab
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8, and 13.3.4.
network
low complexity
gitlab CWE-20
4.9