Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2022-10-07 CVE-2022-32591 Improper Input Validation vulnerability in Google Android 11.0/12.0
In ril, there is a possible system crash due to an incorrect bounds check.
network
low complexity
google CWE-20
7.5
2022-09-30 CVE-2022-20850 Improper Input Validation vulnerability in Cisco products
A vulnerability in the CLI of stand-alone Cisco IOS XE SD-WAN Software and Cisco SD-WAN Software could allow an authenticated, local attacker to delete arbitrary files from the file system of an affected device.
local
low complexity
cisco CWE-20
7.1
2022-09-30 CVE-2022-20945 Improper Input Validation vulnerability in Cisco products
A vulnerability in the 802.11 association frame validation of Cisco Catalyst 9100 Series Access Points (APs) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device.
low complexity
cisco CWE-20
6.5
2022-09-30 CVE-2022-40277 Improper Input Validation vulnerability in Joplinapp Joplin 2.8.8
Joplin version 2.8.8 allows an external attacker to execute arbitrary commands remotely on any client that opens a link in a malicious markdown file, via Joplin.
local
low complexity
joplinapp CWE-20
7.8
2022-09-29 CVE-2014-0144 Improper Input Validation vulnerability in multiple products
QEMU before 2.0.0 block drivers for CLOOP, QCOW2 version 2 and various other image formats are vulnerable to potential memory corruptions, integer/buffer overflows or crash caused by missing input validations which could allow a remote user to execute arbitrary code on the host with the privileges of the QEMU process.
local
low complexity
qemu redhat CWE-20
8.6
2022-09-28 CVE-2022-36448 Improper Input Validation vulnerability in Insyde Insydeh2O
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5.
local
low complexity
insyde CWE-20
8.2
2022-09-26 CVE-2022-2856 Improper Input Validation vulnerability in multiple products
Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily browse to a malicious website via a crafted HTML page.
network
low complexity
google fedoraproject CWE-20
6.5
2022-09-26 CVE-2022-3075 Improper Input Validation vulnerability in multiple products
Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
network
low complexity
google fedoraproject CWE-20
critical
9.6
2022-09-26 CVE-2022-3201 Improper Input Validation vulnerability in multiple products
Insufficient validation of untrusted input in DevTools in Google Chrome on Chrome OS prior to 105.0.5195.125 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted HTML page.
network
low complexity
google fedoraproject debian CWE-20
5.4
2022-09-23 CVE-2022-26707 Improper Input Validation vulnerability in Apple Macos
An issue in the handling of environment variables was addressed with improved validation.
local
low complexity
apple CWE-20
5.5