Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2020-06-08 CVE-2020-12803 Improper Input Validation vulnerability in multiple products
ODF documents can contain forms to be filled out by the user.
network
low complexity
libreoffice opensuse fedoraproject CWE-20
6.5
2020-06-05 CVE-2020-13646 Improper Input Validation vulnerability in Ijinshan Cheetah Free Wifi 5.1
In Cheetah free WiFi 5.1, the driver file (liebaonat.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x830020f8, 0x830020E0, 0x830020E4, or 0x8300210c.
local
low complexity
ijinshan CWE-20
7.8
2020-06-05 CVE-2020-10068 Improper Input Validation vulnerability in Zephyrproject Zephyr
In the Zephyr project Bluetooth subsystem, certain duplicate and back-to-back packets can cause incorrect behavior, resulting in a denial of service.
low complexity
zephyrproject CWE-20
6.5
2020-06-04 CVE-2020-12852 Improper Input Validation vulnerability in Pydio Cells 2.0.4
The update feature for Pydio Cells 2.0.4 allows an administrator user to set a custom update URL and the public RSA key used to validate the downloaded update package.
network
low complexity
pydio CWE-20
6.8
2020-06-04 CVE-2020-13832 Improper Input Validation vulnerability in Google Android 10.0
An issue was discovered on Samsung mobile devices with Q(10.0) (with TEEGRIS on Exynos chipsets) software.
network
low complexity
google CWE-20
critical
9.8
2020-06-03 CVE-2020-3238 Improper Input Validation vulnerability in Cisco IOX
A vulnerability in the Cisco Application Framework component of the Cisco IOx application environment could allow an authenticated, remote attacker to write or modify arbitrary files in the virtual instance that is running on the affected device.
network
low complexity
cisco CWE-20
8.1
2020-06-03 CVE-2020-3235 Improper Input Validation vulnerability in multiple products
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software on Catalyst 4500 Series Switches could allow an authenticated, remote attacker to cause a denial of service (DoS) condition.
network
low complexity
cisco oracle CWE-20
7.7
2020-06-03 CVE-2020-3230 Improper Input Validation vulnerability in Cisco IOS and IOS XE
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) implementation in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to prevent IKEv2 from establishing new security associations.
network
low complexity
cisco CWE-20
7.5
2020-06-03 CVE-2020-3228 Improper Input Validation vulnerability in Cisco IOS and IOS XE
A vulnerability in Security Group Tag Exchange Protocol (SXP) in Cisco IOS Software, Cisco IOS XE Software, and Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
8.6
2020-06-03 CVE-2020-3226 Improper Input Validation vulnerability in Cisco IOS and IOS XE
A vulnerability in the Session Initiation Protocol (SIP) library of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
8.6