Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2017-06-13 CVE-2014-9965 Improper Input Validation vulnerability in Google Android
In all Android releases from CAF using the Linux kernel, a vulnerability exists in the parsing of an SCM call.
local
low complexity
google CWE-20
7.8
2017-06-13 CVE-2014-9962 Improper Input Validation vulnerability in Google Android
In all Android releases from CAF using the Linux kernel, a vulnerability exists in the parsing of a DRM provisioning command.
local
low complexity
google CWE-20
7.8
2017-06-13 CVE-2017-6690 Improper Input Validation vulnerability in Cisco ASR 5000 Software 21.0.V0.65839/21.3.M0.67005
A vulnerability in the file check operation of Cisco ASR 5000 Series Aggregated Services Routers running the Cisco StarOS operating system could allow an authenticated, remote attacker to overwrite or modify arbitrary files on an affected system.
network
low complexity
cisco CWE-20
4.9
2017-06-13 CVE-2017-6680 Improper Input Validation vulnerability in Cisco Ultra Services Framework 21.0.0
A vulnerability in the AutoVNF logging function of Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to create arbitrary directories on the affected system.
network
low complexity
cisco CWE-20
7.5
2017-06-13 CVE-2017-6674 Improper Input Validation vulnerability in Cisco Firesight System
A vulnerability in the feature-license management functionality of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass URL filters that have been configured for an affected device.
network
low complexity
cisco CWE-20
7.5
2017-06-13 CVE-2017-6671 Improper Input Validation vulnerability in Cisco Email Security Appliance Firmware 10.0.1087/9.7.1066
A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured filters on the device, as demonstrated by the Attachment Filter.
network
low complexity
cisco CWE-20
7.5
2017-06-13 CVE-2017-6667 Improper Input Validation vulnerability in Cisco Context Service Development KIT 2.0
A vulnerability in the update process for the dynamic JAR file of the Cisco Context Service software development kit (SDK) could allow an unauthenticated, remote attacker to execute arbitrary code on the affected device with the privileges of the web server.
network
low complexity
cisco CWE-20
critical
9.8
2017-06-13 CVE-2017-6656 Improper Input Validation vulnerability in Cisco IP Phone 8800 Series 11.0(0.1)
A vulnerability in Session Initiation Protocol (SIP) call handling of Cisco IP Phone 8800 Series devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to the SIP process unexpectedly restarting.
network
high complexity
cisco CWE-20
5.9
2017-06-13 CVE-2017-4994 Improper Input Validation vulnerability in multiple products
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v263; UAA release 2.x versions prior to v2.7.4.18, 3.6.x versions prior to v3.6.12, 3.9.x versions prior to v3.9.14, and other versions prior to v4.3.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.16, 24.x versions prior to v24.11, 30.x versions prior to 30.4, and other versions prior to v40.
network
low complexity
pivotal-software cloudfoundry CWE-20
7.5
2017-06-13 CVE-2017-2773 Improper Input Validation vulnerability in Pivotal Software Cloud Foundry Elastic Runtime
An issue was discovered in Pivotal PCF Elastic Runtime 1.6.x versions prior to 1.6.60, 1.7.x versions prior to 1.7.41, 1.8.x versions prior to 1.8.23, and 1.9.x versions prior to 1.9.1.
network
low complexity
pivotal-software CWE-20
critical
9.8