Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2017-08-02 CVE-2017-12145 Improper Input Validation vulnerability in Libquicktime 1.2.4
In libquicktime 1.2.4, an allocation failure was found in the function quicktime_read_ftyp in ftyp.c, which allows attackers to cause a denial of service via a crafted file.
network
low complexity
libquicktime CWE-20
6.5
2017-08-02 CVE-2017-12143 Improper Input Validation vulnerability in Libquicktime 1.2.4
In libquicktime 1.2.4, an allocation failure was found in the function quicktime_read_info in lqt_quicktime.c, which allows attackers to cause a denial of service via a crafted file.
network
low complexity
libquicktime CWE-20
6.5
2017-08-01 CVE-2017-8571 Improper Input Validation vulnerability in Microsoft Outlook
Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, and Outlook 2016 as packaged in Microsoft Office allows a security feature bypass vulnerability due to the way that it handles input, aka "Microsoft Office Outlook Security Feature Bypass Vulnerability".
local
low complexity
microsoft CWE-20
7.8
2017-07-31 CVE-2017-1460 Improper Input Validation vulnerability in IBM I
IBM i OSPF 6.1, 7.1, 7.2, and 7.3 is vulnerable when a rogue router spoofs its origin.
network
low complexity
ibm CWE-20
7.5
2017-07-31 CVE-2016-9719 Improper Input Validation vulnerability in IBM Infosphere Master Data Management Server
IBM InfoSphere Master Data Management Server 10.1.
network
low complexity
ibm CWE-20
5.7
2017-07-31 CVE-2016-9717 Improper Input Validation vulnerability in IBM Infosphere Master Data Management Server
HTTP Parameter Override is identified in the IBM Infosphere Master Data Management (MDM) 10.1.
network
low complexity
ibm CWE-20
6.5
2017-07-31 CVE-2017-9497 Improper Input Validation vulnerability in Cisco Mx011Anm Firmware Mx011An2.9P6S1Prodsey
The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) devices allows physically proximate attackers to execute arbitrary commands as root by pulling up the diagnostics menu on the set-top box, and then posting to a Web Inspector route.
low complexity
cisco CWE-20
6.8
2017-07-28 CVE-2017-6256 Improper Input Validation vulnerability in Nvidia GPU Driver
NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a value passed from a user to the driver is not correctly validated and used as the index to an array which may lead to denial of service or potential escalation of privileges.
local
low complexity
nvidia CWE-20
7.8
2017-07-28 CVE-2017-6255 Improper Input Validation vulnerability in Nvidia GPU Driver
NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where an improper input parameter handling may lead to a denial of service or potential escalation of privileges.
local
low complexity
nvidia CWE-20
7.8
2017-07-28 CVE-2017-6254 Improper Input Validation vulnerability in Nvidia GPU Driver
NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a pointer passed from an user to the driver is used without validation which may lead to denial of service or potential escalation of privileges.
local
low complexity
nvidia CWE-20
7.8