Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2017-06-13 CVE-2016-8218 Improper Input Validation vulnerability in Cloudfoundry Cf-Release
An issue was discovered in Cloud Foundry Foundation routing-release versions prior to 0.142.0 and cf-release versions 203 to 231.
network
low complexity
cloudfoundry CWE-20
critical
9.8
2017-06-09 CVE-2017-2179 Improper Input Validation vulnerability in IPA Appgoat 3.0.0/3.0.1/3.0.2
Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.2 and earlier allows remote code execution via unspecified vectors, a different vulnerability than CVE-2017-2181 and CVE-2017-2182.
network
low complexity
ipa CWE-20
8.8
2017-06-09 CVE-2016-7821 Improper Input Validation vulnerability in Buffalotech Wnc01Wh Firmware 1.0.0.8
Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allow remote attackers to cause a denial of service against the management screen via unspecified vectors.
network
low complexity
buffalotech CWE-20
6.5
2017-06-08 CVE-2015-3913 Improper Input Validation vulnerability in Huawei products
The IP stack in multiple Huawei Campus series switch models allows remote attackers to cause a denial of service (reboot) via a crafted ICMP request message.
network
low complexity
huawei CWE-20
7.5
2017-06-08 CVE-2015-1379 Improper Input Validation vulnerability in Dest-Unreach Socat
The signal handler implementations in socat before 1.7.3.0 and 2.0.0-b8 allow remote attackers to cause a denial of service (process freeze or crash).
network
low complexity
dest-unreach CWE-20
7.5
2017-06-08 CVE-2014-3498 Improper Input Validation vulnerability in Redhat Ansible
The user module in ansible before 1.6.6 allows remote authenticated users to execute arbitrary commands.
network
low complexity
redhat CWE-20
8.8
2017-06-08 CVE-2017-9022 Improper Input Validation vulnerability in multiple products
The gmp plugin in strongSwan before 5.5.3 does not properly validate RSA public keys before calling mpz_powm_sec, which allows remote peers to cause a denial of service (floating point exception and process crash) via a crafted certificate.
network
low complexity
strongswan debian canonical CWE-20
7.5
2017-06-08 CVE-2017-6638 Improper Input Validation vulnerability in Cisco Anyconnect Secure Mobility Client
A vulnerability in how DLL files are loaded with Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to install and run an executable file with privileges equivalent to the Microsoft Windows SYSTEM account.
local
low complexity
cisco CWE-20
7.8
2017-06-07 CVE-2015-8538 Improper Input Validation vulnerability in Libdwarf Project Libdwarf
dwarf_leb.c in libdwarf allows attackers to cause a denial of service (SIGSEGV).
network
low complexity
libdwarf-project CWE-20
6.5
2017-06-07 CVE-2015-5175 Improper Input Validation vulnerability in Apache CXF Fediz
Application plugins in Apache CXF Fediz before 1.1.3 and 1.2.x before 1.2.1 allow remote attackers to cause a denial of service.
network
low complexity
apache CWE-20
7.5