Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2017-05-22 CVE-2017-9144 Improper Input Validation vulnerability in multiple products
In ImageMagick 7.0.5-5, a crafted RLE image can trigger a crash because of incorrect EOF handling in coders/rle.c.
network
low complexity
imagemagick debian CWE-20
6.5
2017-05-22 CVE-2017-2540 Improper Input Validation vulnerability in Apple mac OS X
An issue was discovered in certain Apple products.
local
low complexity
apple CWE-20
5.5
2017-05-22 CVE-2017-2511 Improper Input Validation vulnerability in Apple Safari
An issue was discovered in certain Apple products.
network
low complexity
apple CWE-20
6.5
2017-05-22 CVE-2017-2500 Improper Input Validation vulnerability in Apple Safari
An issue was discovered in certain Apple products.
network
low complexity
apple CWE-20
4.7
2017-05-22 CVE-2017-2495 Improper Input Validation vulnerability in Apple Iphone OS
An issue was discovered in certain Apple products.
network
low complexity
apple CWE-20
6.5
2017-05-22 CVE-2017-6637 Improper Input Validation vulnerability in Cisco Prime Collaboration Provisioning
A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software (prior to Release 11.1) could allow an authenticated, remote attacker to delete any file from an affected system.
network
low complexity
cisco CWE-20
6.5
2017-05-21 CVE-2017-9131 Improper Input Validation vulnerability in Mimosa Backhaul Radios and Client Radios
An issue was discovered on Mimosa Client Radios before 2.2.3 and Mimosa Backhaul Radios before 2.2.3.
network
low complexity
mimosa CWE-20
7.5
2017-05-21 CVE-2017-9046 Improper Input Validation vulnerability in Pmail Pegasus 4.72
winpm-32.exe in Pegasus Mail (aka Pmail) v4.72 build 572 allows code execution via a crafted ssgp.dll file that must be installed locally.
local
low complexity
pmail CWE-20
7.3
2017-05-19 CVE-2017-9091 Improper Input Validation vulnerability in Allen Disk Project Allen Disk 1.6
/admin/loginc.php in Allen Disk 1.6 doesn't check if isset($_SESSION['captcha']['code']) == 1, which leads to CAPTCHA bypass by emptying $_POST['captcha'].
network
low complexity
allen-disk-project CWE-20
7.5
2017-05-19 CVE-2017-9090 Improper Input Validation vulnerability in Allen Disk Project Allen Disk 1.6
reg.php in Allen Disk 1.6 doesn't check if isset($_SESSION['captcha']['code'])==1, which makes it possible to bypass the CAPTCHA via an empty $_POST['captcha'].
network
low complexity
allen-disk-project CWE-20
7.5