Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2017-07-17 CVE-2017-1000016 Improper Input Validation vulnerability in PHPmyadmin
A weakness was discovered where an attacker can inject arbitrary values in to the browser cookies.
network
low complexity
phpmyadmin CWE-20
7.5
2017-07-17 CVE-2017-1000014 Improper Input Validation vulnerability in PHPmyadmin
phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a DOS weakness in the table editing functionality
network
low complexity
phpmyadmin CWE-20
7.5
2017-07-17 CVE-2017-1000001 Improper Input Validation vulnerability in Fedoraproject Fedmsg
FedMsg 0.18.1 and older is vulnerable to a message validation flaw resulting in message validation not being enabled if configured to be on.
network
low complexity
fedoraproject CWE-20
7.5
2017-07-13 CVE-2017-9788 Improper Input Validation vulnerability in multiple products
In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or reset before or between successive key=value assignments by mod_auth_digest.
network
low complexity
apache debian apple netapp redhat oracle CWE-20
critical
9.1
2017-07-13 CVE-2017-7672 Improper Input Validation vulnerability in Apache Struts
If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL.
network
high complexity
apache CWE-20
5.9
2017-07-12 CVE-2017-1285 Improper Input Validation vulnerability in IBM Websphere MQ 9.0.1/9.0.2
IBM WebSphere MQ 9.0.1 and 9.0.2 could allow an authenticated user with authority to send a specially crafted message that would cause a channel to remain in a running state but not process messages.
network
low complexity
ibm CWE-20
6.5
2017-07-11 CVE-2017-8611 Improper Input Validation vulnerability in Microsoft Edge
Microsoft Edge on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows remote attackers to spoof web content via a crafted web site, aka "Microsoft Edge Spoofing Vulnerability."
network
low complexity
microsoft CWE-20
6.5
2017-07-11 CVE-2017-8602 Improper Input Validation vulnerability in Microsoft Edge and Internet Explorer
Microsoft browsers on Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow a spoofing vulnerability in the way they parse HTTP content, aka "Microsoft Browser Spoofing Vulnerability."
network
low complexity
microsoft CWE-20
6.5
2017-07-11 CVE-2017-8599 Improper Input Validation vulnerability in Microsoft Edge
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to trick a user into loading a page with malicious content when the Edge Content Security Policy (CSP) fails to properly validate certain specially crafted documents, aka "Microsoft Edge Security Feature Bypass Vulnerability".
network
low complexity
microsoft CWE-20
6.5
2017-07-11 CVE-2017-8585 Improper Input Validation vulnerability in Microsoft .Net Framework
Microsoft .NET Framework 4.6, 4.6.1, 4.6.2, and 4.7 allow an attacker to send specially crafted requests to a .NET web application, resulting in denial of service, aka .NET Denial of Service Vulnerability.
network
low complexity
microsoft CWE-20
7.5