Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2020-01-24 CVE-2019-1354 Improper Input Validation vulnerability in Microsoft Visual Studio 2017
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'.
network
low complexity
microsoft CWE-20
8.8
2020-01-24 CVE-2019-1352 Improper Input Validation vulnerability in Microsoft Visual Studio 2017
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'.
network
low complexity
microsoft CWE-20
8.8
2020-01-24 CVE-2019-1350 Improper Input Validation vulnerability in Microsoft Visual Studio 2017
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'.
network
low complexity
microsoft CWE-20
8.8
2020-01-24 CVE-2019-1349 Improper Input Validation vulnerability in Microsoft Visual Studio 2017
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'.
network
low complexity
microsoft CWE-20
8.8
2020-01-24 CVE-2015-2689 Improper Input Validation vulnerability in Torproject TOR
Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle pending-connection resolve states during periods of high DNS load, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via crafted packets.
network
low complexity
torproject CWE-20
7.5
2020-01-24 CVE-2015-1525 Improper Input Validation vulnerability in Google Android
audio/AudioPolicyManagerBase.cpp in Android before 5.1 allows attackers to cause a denial of service (audio_policy application outage) via a crafted application that provides a NULL device address.
local
low complexity
google CWE-20
5.5
2020-01-24 CVE-2020-6962 Improper Input Validation vulnerability in Gehealthcare products
In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Telemetry Server Version 4.3, CARESCAPE Central Station (CSCS) Versions 1.X CARESCAPE Central Station (CSCS) Versions 2.X, B450 Version 2.X, B650 Version 1.X, B650 Version 2.X, B850 Version 1.X, B850 Version 2.X, an input validation vulnerability exists in the web-based system configuration utility that could allow an attacker to obtain arbitrary remote code execution.
network
low complexity
gehealthcare CWE-20
critical
10.0
2020-01-23 CVE-2012-5699 Improper Input Validation vulnerability in Babygekko
BabyGekko before 1.2.4 allows PHP file inclusion.
network
low complexity
babygekko CWE-20
critical
9.8
2020-01-22 CVE-2019-19836 Improper Input Validation vulnerability in Ruckuswireless Unleashed and Zonedirector 1200 Firmware
AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote code execution via a POST request that uses tools/_rcmdstat.jsp to write to a specified filename.
network
low complexity
ruckuswireless CWE-20
critical
9.8
2020-01-22 CVE-2011-3611 Improper Input Validation vulnerability in Usebb
A File Inclusion vulnerability exists in act parameter to admin.php in UseBB before 1.0.12.
network
low complexity
usebb CWE-20
7.2