Vulnerabilities > Improper Input Validation
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-07-25 | CVE-2017-9457 | Improper Input Validation vulnerability in Compulab Intense PC Firmware Cr2.2.0.400.2 Intense PC Phoenix SecureCore UEFI firmware does not perform capsule signature validation before upgrading the system firmware. | 6.7 |
2017-07-25 | CVE-2017-11499 | Improper Input Validation vulnerability in Nodejs Node.Js Node.js v4.0 through v4.8.3, all versions of v5.x, v6.0 through v6.11.0, v7.0 through v7.10.0, and v8.0 through v8.1.3 was susceptible to hash flooding remote DoS attacks as the HashTable seed was constant across a given released version of Node.js. | 7.5 |
2017-07-24 | CVE-2015-7703 | Improper Input Validation vulnerability in multiple products The "pidfile" or "driftfile" directives in NTP ntpd 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77, when ntpd is configured to allow remote configuration, allows remote attackers with an IP address that is allowed to send configuration requests, and with knowledge of the remote configuration password to write to arbitrary files via the :config command. | 7.5 |
2017-07-23 | CVE-2017-11555 | Improper Input Validation vulnerability in Libsass 3.4.5 There is an illegal address access in the Eval::operator function in eval.cpp in LibSass 3.4.5. | 7.5 |
2017-07-23 | CVE-2017-11553 | Improper Input Validation vulnerability in Exiv2 0.26 There is an illegal address access in the extend_alias_table function in localealias.c of Exiv2 0.26. | 7.5 |
2017-07-21 | CVE-2017-1267 | Improper Input Validation vulnerability in IBM Security Guardium IBM Security Guardium 10.0 and 10.1 processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code. | 7.5 |
2017-07-21 | CVE-2015-5195 | Improper Input Validation vulnerability in multiple products ntp_openssl.m4 in ntpd in NTP before 4.2.7p112 allows remote attackers to cause a denial of service (segmentation fault) via a crafted statistics or filegen configuration command that is not enabled during compilation. | 7.5 |
2017-07-21 | CVE-2015-5194 | Improper Input Validation vulnerability in multiple products The log_config_command function in ntp_parser.y in ntpd in NTP before 4.2.7p42 allows remote attackers to cause a denial of service (ntpd crash) via crafted logconfig commands. | 7.5 |
2017-07-21 | CVE-2015-3639 | Improper Input Validation vulnerability in PHPmybackuppro phpMyBackupPro 2.5 and earlier does not properly sanitize input strings, which allows remote authenticated users to execute arbitrary PHP code by storing a crafted string in a user configuration file. | 8.8 |
2017-07-20 | CVE-2017-11495 | Improper Input Validation vulnerability in Phicomm K2(Psg1218)-Firmware 22.5.11.5 PHICOMM K2(PSG1218) devices V22.5.11.5 and earlier allow unauthenticated remote code execution via a request to an unspecified ASP script; alternatively, the attacker can leverage unauthenticated access to this script to trigger a reboot via an ifType=reboot action. | 9.8 |