Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2017-08-18 CVE-2015-9048 Improper Input Validation vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in the processing of lost RTP packets.
network
low complexity
google CWE-20
critical
9.8
2017-08-18 CVE-2015-9046 Improper Input Validation vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in LTE where an assertion can be reached due to an improper bound on the size of a frequency list.
network
low complexity
google CWE-20
critical
9.8
2017-08-18 CVE-2015-9044 Improper Input Validation vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in LTE where an assertion can be reached due to an improper bound on the size of a frequency list.
network
low complexity
google CWE-20
critical
9.8
2017-08-18 CVE-2015-9039 Improper Input Validation vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in eMBMS where an assertion can be reached by a sequence of downlink messages.
network
low complexity
google CWE-20
critical
9.8
2017-08-18 CVE-2015-0574 Improper Input Validation vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, the validation of filesystem access was insufficient.
network
low complexity
google CWE-20
critical
9.8
2017-08-18 CVE-2014-9971 Improper Input Validation vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, disabling asserts causes an instruction inside of an assert to not be executed resulting in incorrect control flow.
network
low complexity
google CWE-20
critical
9.8
2017-08-18 CVE-2017-12859 Improper Input Validation vulnerability in Netapp Data Ontap
NetApp Data ONTAP before 8.2.5, when operating in 7-Mode in NFS environments, allows remote attackers to cause a denial of service via unspecified vectors.
network
high complexity
netapp CWE-20
5.9
2017-08-18 CVE-2015-3649 Improper Input Validation vulnerability in Open-Uri-Cached Project Open-Uri-Cached 0.0.5
The open-uri-cached rubygem allows local users to execute arbitrary Ruby code by creating a directory under /tmp containing "openuri-" followed by a crafted UID, and putting Ruby code in said directory once a meta file is created.
local
low complexity
open-uri-cached-project CWE-20
7.8
2017-08-18 CVE-2017-12939 Improper Input Validation vulnerability in Unity3D Unity Editor
A Remote Code Execution vulnerability was identified in all Windows versions of Unity Editor, e.g., before 5.3.8p2, 5.4.x before 5.4.5p5, 5.5.x before 5.5.4p3, 5.6.x before 5.6.3p1, and 2017.x before 2017.1.0p4.
network
low complexity
unity3d CWE-20
critical
9.8
2017-08-17 CVE-2017-6785 Improper Input Validation vulnerability in Cisco Unified Communications Manager 10.5(2.10000.5)/11.0(1.10000.10)/11.5(1.10000.6)
A vulnerability in configuration modification permissions validation for Cisco Unified Communications Manager could allow an authenticated, remote attacker to perform a horizontal privilege escalation where one user can modify another user's configuration.
network
low complexity
cisco CWE-20
4.3