Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2020-03-10 CVE-2019-19279 Improper Input Validation vulnerability in Siemens Siprotec 4 and Siprotec Compact
A vulnerability has been identified in SIPROTEC 4 and SIPROTEC Compact relays equipped with EN100 Ethernet communication modules (All versions).
network
low complexity
siemens CWE-20
7.5
2020-03-10 CVE-2020-10255 Improper Input Validation vulnerability in multiple products
Modern DRAM chips (DDR4 and LPDDR4 after 2015) are affected by a vulnerability in deployment of internal mitigations against RowHammer attacks known as Target Row Refresh (TRR), aka the TRRespass issue.
network
high complexity
samsung micron skhynix CWE-20
critical
9.0
2020-03-10 CVE-2019-12433 Improper Input Validation vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition 11.7 through 11.11.
network
low complexity
gitlab CWE-20
5.3
2020-03-09 CVE-2020-10236 Improper Input Validation vulnerability in Froxlor
An issue was discovered in Froxlor before 0.10.14.
local
low complexity
froxlor CWE-20
6.1
2020-03-04 CVE-2020-3164 Improper Input Validation vulnerability in Cisco products
A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated remote attacker to cause high CPU usage on an affected device, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
5.3
2020-03-04 CVE-2020-3128 Improper Input Validation vulnerability in Cisco products
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system.
local
low complexity
cisco CWE-20
7.8
2020-03-04 CVE-2020-3127 Improper Input Validation vulnerability in Cisco products
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system.
local
low complexity
cisco CWE-20
7.8
2020-03-02 CVE-2020-6797 Improper Input Validation vulnerability in Mozilla Firefox
By downloading a file with the .fileloc extension, a semi-privileged extension could launch an arbitrary application on the user's computer.
network
low complexity
mozilla CWE-20
4.3
2020-02-28 CVE-2020-8132 Improper Input Validation vulnerability in Pdf-Image Project Pdf-Image
Lack of input validation in pdf-image npm package version <= 2.0.0 may allow an attacker to run arbitrary code if PDF file path is constructed based on untrusted user input.
network
low complexity
pdf-image-project CWE-20
critical
9.8
2020-02-27 CVE-2020-9430 Improper Input Validation vulnerability in multiple products
In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the WiMax DLMAP dissector could crash.
network
low complexity
wireshark fedoraproject opensuse debian CWE-20
7.5