Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2017-09-07 CVE-2017-14169 Improper Input Validation vulnerability in multiple products
In the mxf_read_primer_pack function in libavformat/mxfdec.c in FFmpeg 3.3.3 -> 2.4, an integer signedness error might occur when a crafted file, which claims a large "item_num" field such as 0xffffffff, is provided.
network
low complexity
ffmpeg debian CWE-20
8.8
2017-09-06 CVE-2015-5186 Improper Input Validation vulnerability in Linux Audit Project Linux Audit
Audit before 2.4.4 in Linux does not sanitize escape characters in filenames.
network
low complexity
linux-audit-project CWE-20
5.3
2017-09-06 CVE-2015-0853 Improper Input Validation vulnerability in Pysvn Project Svn-Workbench 1.6.2
svn-workbench 1.6.2 and earlier on a system with xeyes installed allows local users to execute arbitrary commands by using the "Command Shell" menu item while in the directory trunk/$(xeyes).
network
low complexity
pysvn-project CWE-20
8.8
2017-09-02 CVE-2017-14098 Improper Input Validation vulnerability in Digium Asterisk
In the pjsip channel driver (res_pjsip) in Asterisk 13.x before 13.17.1 and 14.x before 14.6.1, a carefully crafted tel URI in a From, To, or Contact header could cause Asterisk to crash.
network
low complexity
digium CWE-20
7.5
2017-09-01 CVE-2017-12874 Improper Input Validation vulnerability in multiple products
The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XML messages by leveraging an incorrect check of return values in signature validation utilities.
network
low complexity
simplesamlphp debian CWE-20
7.5
2017-09-01 CVE-2017-14105 Improper Input Validation vulnerability in Aerohive Hivemanager Classic 8.0R1/8.1R1
HiveManager Classic through 8.1r1 allows arbitrary JSP code execution by modifying a backup archive before a restore, because the restore feature does not validate pathnames within the archive.
local
low complexity
aerohive CWE-20
7.8
2017-09-01 CVE-2017-3898 Improper Input Validation vulnerability in Mcafee Livesafe 14.0/16.0.2
A man-in-the-middle attack vulnerability in the non-certificate-based authentication mechanism in McAfee LiveSafe (MLS) versions prior to 16.0.3 allows network attackers to modify the Windows registry value associated with the McAfee update via the HTTP backend-response.
network
high complexity
mcafee CWE-20
5.9
2017-09-01 CVE-2017-12869 Improper Input Validation vulnerability in multiple products
The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authentication context restrictions and use an authentication source defined in config/authsources.php via vectors related to improper validation of user input.
network
low complexity
simplesamlphp debian CWE-20
7.5
2017-08-31 CVE-2017-0901 Improper Input Validation vulnerability in multiple products
RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any file on the filesystem.
network
low complexity
rubygems debian canonical redhat CWE-20
7.5
2017-08-31 CVE-2017-0900 Improper Input Validation vulnerability in multiple products
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against RubyGems clients who have issued a `query` command.
network
low complexity
rubygems debian redhat CWE-20
7.5