Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2017-06-30 CVE-2017-10674 Improper Input Validation vulnerability in Antiy Antivirus Engine 5.0.0.06281654
Antiy Antivirus Engine 5.0.0.06281654 allows local users to cause a denial of service (BSOD) via a long third argument in a DeviceIoControl call.
local
low complexity
antiy CWE-20
5.5
2017-06-29 CVE-2017-10688 Improper Input Validation vulnerability in Libtiff 4.0.8
In LibTIFF 4.0.8, there is a assertion abort in the TIFFWriteDirectoryTagCheckedLong8Array function in tif_dirwrite.c.
network
low complexity
libtiff CWE-20
7.5
2017-06-29 CVE-2017-4997 Improper Input Validation vulnerability in Dell EMC Vasa Provider Virtual Appliance 8.3.0
EMC VASA Provider Virtual Appliance versions 8.3.x and prior has an unauthenticated remote code execution vulnerability that could potentially be exploited by malicious users to compromise the affected system.
network
low complexity
dell CWE-20
critical
9.8
2017-06-27 CVE-2015-2245 Improper Input Validation vulnerability in Huawei P7-L09 Firmware
Huawei Ascend P7 allows remote attackers to cause a denial of service (phone process crash).
network
low complexity
huawei CWE-20
7.5
2017-06-27 CVE-2014-8149 Improper Input Validation vulnerability in Opendaylight Defense4All 1.1.0
OpenDaylight defense4all 1.1.0 and earlier allows remote authenticated users to write report data to arbitrary files.
network
low complexity
opendaylight CWE-20
8.8
2017-06-27 CVE-2017-9982 Improper Input Validation vulnerability in Teamspeak Client 3.0.19
TeamSpeak Client 3.0.19 allows remote attackers to cause a denial of service (application crash) via the ᗪ Unicode character followed by the ༿ Unicode character.
network
low complexity
teamspeak CWE-20
7.5
2017-06-26 CVE-2015-3215 Improper Input Validation vulnerability in Redhat Virtio-Win
The NetKVM Windows Virtio driver allows remote attackers to cause a denial of service (guest crash) via a crafted length value in an IP packet, as demonstrated by a value that does not account for the size of the IP options.
network
low complexity
redhat CWE-20
7.5
2017-06-21 CVE-2017-9773 Improper Input Validation vulnerability in Horde Image
Denial of Service was found in Horde_Image 2.x before 2.5.0 via a crafted URL to the "Null" image driver.
network
low complexity
horde CWE-20
5.7
2017-06-20 CVE-2017-3098 Improper Input Validation vulnerability in Adobe Captivate
Adobe Captivate versions 9 and earlier have a remote code execution vulnerability in the quiz reporting feature that could be abused to read and write arbitrary files to the server.
network
low complexity
adobe CWE-20
critical
9.8
2017-06-18 CVE-2017-9741 Improper Input Validation vulnerability in Projectsend R754
install/make-config.php in ProjectSend r754 allows remote attackers to execute arbitrary PHP code via the dbprefix parameter, related to replacing TABLES_PREFIX in the configuration file.
network
low complexity
projectsend CWE-20
critical
9.8