Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2017-07-25 CVE-2017-9457 Improper Input Validation vulnerability in Compulab Intense PC Firmware Cr2.2.0.400.2
Intense PC Phoenix SecureCore UEFI firmware does not perform capsule signature validation before upgrading the system firmware.
local
low complexity
compulab CWE-20
6.7
2017-07-25 CVE-2017-11499 Improper Input Validation vulnerability in Nodejs Node.Js
Node.js v4.0 through v4.8.3, all versions of v5.x, v6.0 through v6.11.0, v7.0 through v7.10.0, and v8.0 through v8.1.3 was susceptible to hash flooding remote DoS attacks as the HashTable seed was constant across a given released version of Node.js.
network
low complexity
nodejs CWE-20
7.5
2017-07-24 CVE-2015-7703 Improper Input Validation vulnerability in multiple products
The "pidfile" or "driftfile" directives in NTP ntpd 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77, when ntpd is configured to allow remote configuration, allows remote attackers with an IP address that is allowed to send configuration requests, and with knowledge of the remote configuration password to write to arbitrary files via the :config command.
network
low complexity
ntp oracle debian netapp redhat CWE-20
7.5
2017-07-23 CVE-2017-11555 Improper Input Validation vulnerability in Libsass 3.4.5
There is an illegal address access in the Eval::operator function in eval.cpp in LibSass 3.4.5.
network
low complexity
libsass CWE-20
7.5
2017-07-23 CVE-2017-11553 Improper Input Validation vulnerability in Exiv2 0.26
There is an illegal address access in the extend_alias_table function in localealias.c of Exiv2 0.26.
network
low complexity
exiv2 CWE-20
7.5
2017-07-21 CVE-2017-1267 Improper Input Validation vulnerability in IBM Security Guardium
IBM Security Guardium 10.0 and 10.1 processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code.
network
low complexity
ibm CWE-20
7.5
2017-07-21 CVE-2015-5195 Improper Input Validation vulnerability in multiple products
ntp_openssl.m4 in ntpd in NTP before 4.2.7p112 allows remote attackers to cause a denial of service (segmentation fault) via a crafted statistics or filegen configuration command that is not enabled during compilation.
network
low complexity
fedoraproject redhat debian canonical ntp CWE-20
7.5
2017-07-21 CVE-2015-5194 Improper Input Validation vulnerability in multiple products
The log_config_command function in ntp_parser.y in ntpd in NTP before 4.2.7p42 allows remote attackers to cause a denial of service (ntpd crash) via crafted logconfig commands.
7.5
2017-07-21 CVE-2015-3639 Improper Input Validation vulnerability in PHPmybackuppro
phpMyBackupPro 2.5 and earlier does not properly sanitize input strings, which allows remote authenticated users to execute arbitrary PHP code by storing a crafted string in a user configuration file.
network
low complexity
phpmybackuppro CWE-20
8.8
2017-07-20 CVE-2017-11495 Improper Input Validation vulnerability in Phicomm K2(Psg1218)-Firmware 22.5.11.5
PHICOMM K2(PSG1218) devices V22.5.11.5 and earlier allow unauthenticated remote code execution via a request to an unspecified ASP script; alternatively, the attacker can leverage unauthenticated access to this script to trigger a reboot via an ifType=reboot action.
network
low complexity
phicomm CWE-20
critical
9.8