Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2017-04-06 CVE-2016-9219 Improper Input Validation vulnerability in Cisco products
A vulnerability with IPv6 UDP ingress packet processing in Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause an unexpected reload of the device.
network
low complexity
cisco CWE-20
7.5
2017-04-05 CVE-2017-0888 Improper Input Validation vulnerability in Nextcloud
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Content-Spoofing vulnerability in the "files" app.
network
low complexity
nextcloud CWE-20
4.3
2017-04-05 CVE-2017-0887 Improper Input Validation vulnerability in Nextcloud Server
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a bypass in the quota limitation.
network
low complexity
nextcloud CWE-20
4.3
2017-04-04 CVE-2015-1612 Improper Input Validation vulnerability in Opendaylight Openflow
OpenFlow plugin for OpenDaylight before Helium SR3 allows remote attackers to spoof the SDN topology and affect the flow of data, related to the reuse of LLDP packets, aka "LLDP Relay."
network
low complexity
opendaylight CWE-20
7.5
2017-04-04 CVE-2015-1611 Improper Input Validation vulnerability in Opendaylight Openflow
OpenFlow plugin for OpenDaylight before Helium SR3 allows remote attackers to spoof the SDN topology and affect the flow of data, related to "fake LLDP injection."
network
low complexity
opendaylight CWE-20
7.5
2017-04-03 CVE-2017-6181 Improper Input Validation vulnerability in Ruby-Lang Ruby 2.4.0
The parse_char_class function in regparse.c in the Onigmo (aka Oniguruma-mod) regular expression library, as used in Ruby 2.4.0, allows remote attackers to cause a denial of service (deep recursion and application crash) via a crafted regular expression.
network
low complexity
ruby-lang CWE-20
7.5
2017-04-03 CVE-2016-10222 Improper Input Validation vulnerability in Apple Safari 18
runtime/JSONObject.cpp in JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 18, allows remote attackers to cause a denial of service (segmentation violation and application crash) via crafted JavaScript code that triggers a "type confusion" in the JSON.stringify function.
network
low complexity
apple CWE-20
7.5
2017-04-02 CVE-2016-8796 Improper Input Validation vulnerability in Huawei products
Huawei USG9520 V300R001C01, USG9560 V300R001C01, and USG9580 V300R001C01 allow unauthenticated attackers to send abnormal DHCP request packets to the affected products to trigger a DoS condition.
network
low complexity
huawei CWE-20
7.5
2017-04-02 CVE-2016-8773 Improper Input Validation vulnerability in Huawei products
Huawei S5300 with software V200R003C00, V200R007C00, V200R008C00, V200R009C00; S5700 with software V200R001C00, V200R002C00, V200R003C00, V200R005C00, V200R005C03, V200R007C00, V200R008C00, V200R009C00; S6300 with software V200R003C00, V200R005C00, V200R008C00, V200R009C00; S6700 with software V200R001C00, V200R001C01, V200R002C00, V200R003C00, V200R005C00, V200R008C00, V200R009C00; S7700 with software V200R007C00, V200R008C00, V200R009C00; S9300 with software V200R007C00, V200R008C00, V200R009C00; S9700 with software V200R007C00, V200R008C00, V200R009C00; and S12700 with software V200R007C00, V200R007C01, V200R008C00, V200R009C00 allow the attacker to cause a denial of service condition by sending malformed MPLS packets.
network
low complexity
huawei CWE-20
7.5
2017-04-02 CVE-2016-8764 Improper Input Validation vulnerability in Huawei P8 Lite Firmware, P9 Firmware and P9 Lite Firmware
The TrustZone driver in Huawei P9 phones with software Versions earlier than EVA-AL10C00B352 and P9 Lite with software VNS-L21C185B130 and earlier versions and P8 Lite with software ALE-L02C636B150 and earlier versions has an input validation vulnerability, which allows attackers to read and write user-mode memory data anywhere in the TrustZone driver.
local
high complexity
huawei CWE-20
6.4