Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2017-05-09 CVE-2017-0353 Improper Input Validation vulnerability in Nvidia GPU Driver
All versions of the NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler for DxgDdiEscape where due to improper locking on certain conditions may lead to a denial of service
local
low complexity
nvidia CWE-20
5.5
2017-05-09 CVE-2017-0350 Improper Input Validation vulnerability in Nvidia GPU Driver
All versions of the NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where a value passed from a user to the driver is not correctly validated and used in an offset calculation may lead to denial of service or potential escalation of privileges.
local
low complexity
nvidia CWE-20
7.8
2017-05-09 CVE-2017-0346 Improper Input Validation vulnerability in Nvidia GPU Driver
All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where the size of an input buffer is not validated, leading to denial of service or potential escalation of privileges.
local
low complexity
nvidia CWE-20
7.8
2017-05-09 CVE-2016-9253 Improper Input Validation vulnerability in F5 products
In F5 BIG-IP 12.1.0 through 12.1.2, specific websocket traffic patterns may cause a disruption of service for virtual servers configured to use the websocket profile.
network
low complexity
f5 CWE-20
7.5
2017-05-05 CVE-2016-6877 Improper Input Validation vulnerability in Citrix Xenmobile Server
Citrix XenMobile Server before 10.5.0.24 allows man-in-the-middle attackers to trigger HTTP 302 redirections via vectors involving the HTTP Host header and a cached page.
network
high complexity
citrix CWE-20
5.3
2017-05-05 CVE-2016-9692 Improper Input Validation vulnerability in IBM Websphere Cast Iron Solution
IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to External Service Interaction attack, caused by improper validation of user-supplied input.
network
low complexity
ibm CWE-20
8.6
2017-05-04 CVE-2017-3733 Improper Input Validation vulnerability in multiple products
During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this can cause OpenSSL 1.1.0 before 1.1.0e to crash (dependent on ciphersuite).
network
low complexity
openssl hp CWE-20
7.5
2017-05-03 CVE-2017-6620 Improper Input Validation vulnerability in Cisco Small Business RV Series Router Firmware 1.0.1.19
A vulnerability in the remote management access control list (ACL) feature of the Cisco CVR100W Wireless-N VPN Router could allow an unauthenticated, remote attacker to bypass the remote management ACL.
network
low complexity
cisco CWE-20
5.8
2017-05-03 CVE-2017-7428 Improper Input Validation vulnerability in Netiq Imanager
NetIQ iManager 3.x before 3.0.3.1 has an issue in the renegotiation of connection parameters with Tomcat.
network
low complexity
netiq CWE-20
5.3
2017-05-02 CVE-2017-6551 Improper Input Validation vulnerability in Pexip Infinity
Pexip Infinity before 14.2 allows remote attackers to cause a denial of service (service restart) or execute arbitrary code via vectors related to Conferencing Nodes.
network
low complexity
pexip CWE-20
critical
9.8