Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2020-07-02 CVE-2020-15503 Improper Input Validation vulnerability in multiple products
LibRaw before 0.20-RC1 lacks a thumbnail size range check.
network
low complexity
libraw fedoraproject debian CWE-20
7.5
2020-07-02 CVE-2020-9497 Improper Input Validation vulnerability in multiple products
Apache Guacamole 1.1.0 and older do not properly validate datareceived from RDP servers via static virtual channels.
local
high complexity
apache fedoraproject debian CWE-20
4.4
2020-07-02 CVE-2020-7821 Improper Input Validation vulnerability in Nexaweb Nexacro 14 and Nexacro 17
Nexacro14/17 ExtCommonApiV13 Library under 2019.9.6 version contain a vulnerability that could allow remote attacker to execute arbitrary code by modifying the value of registry path.
network
low complexity
nexaweb CWE-20
critical
9.8
2020-07-02 CVE-2020-7820 Improper Input Validation vulnerability in Nexaweb Nexacro 14 and Nexacro 17
Nexacro14/17 ExtCommonApiV13 Library under 2019.9.6 version contain a vulnerability that could allow remote attacker to execute arbitrary code by setting the arguments to the vulnerable API.
network
low complexity
nexaweb CWE-20
critical
9.8
2020-06-30 CVE-2020-5970 Improper Input Validation vulnerability in Nvidia Virtual GPU Manager
NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which an input data size is not validated, which may lead to tampering or denial of service.
local
low complexity
nvidia CWE-20
7.1
2020-06-30 CVE-2020-14957 Improper Input Validation vulnerability in Arswp Windows Cleanup Assistant 3.2
In Windows cleaning assistant 3.2, the driver file (AtpKrnl.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x223CCD.
local
low complexity
arswp CWE-20
7.8
2020-06-30 CVE-2020-14956 Improper Input Validation vulnerability in Arswp Windows Cleanup Assistant 3.2
In Windows cleaning assistant 3.2, the driver file (AtpKrnl.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x223CCA.
local
low complexity
arswp CWE-20
7.8
2020-06-26 CVE-2020-3767 Improper Input Validation vulnerability in Adobe Coldfusion 2016/2018
ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have an insufficient input validation vulnerability.
network
low complexity
adobe CWE-20
6.5
2020-06-26 CVE-2020-14955 Improper Input Validation vulnerability in Jiangmin Antivirus 16.0.13.129
In Jiangmin Antivirus 16.0.13.129, the driver file (KVFG.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x220440.
local
low complexity
jiangmin CWE-20
5.5
2020-06-23 CVE-2020-12033 Improper Input Validation vulnerability in Rockwellautomation Factorytalk Services Platform
In Rockwell Automation FactoryTalk Services Platform, all versions, the redundancy host service (RdcyHost.exe) does not validate supplied identifiers, which could allow an unauthenticated, adjacent attacker to execute remote COM objects with elevated privileges.
low complexity
rockwellautomation CWE-20
8.8