Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2017-03-29 CVE-2015-4556 Improper Input Validation vulnerability in Call-Cc Chicken 4.8.0/4.9.0
The string-translate* procedure in the data-structures unit in CHICKEN before 4.10.0 allows remote attackers to cause a denial of service (crash).
network
low complexity
call-cc CWE-20
7.5
2017-03-29 CVE-2009-5147 Improper Input Validation vulnerability in Ruby-Lang Ruby
DL::dlopen in Ruby 1.8, 1.9.0, 1.9.2, 1.9.3, 2.0.0 before patchlevel 648, and 2.1 before 2.1.8 opens libraries with tainted names.
network
low complexity
ruby-lang CWE-20
7.3
2017-03-27 CVE-2017-7183 Improper Input Validation vulnerability in Extraputty 0.29
The TFTP server in ExtraPuTTY 0.30 and earlier allows remote attackers to cause a denial of service (crash) via a large (1) read or (2) write TFTP protocol message.
network
low complexity
extraputty CWE-20
7.5
2017-03-27 CVE-2017-6464 Improper Input Validation vulnerability in NTP
NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote attackers to cause a denial of service (ntpd crash) via a malformed mode configuration directive.
network
low complexity
ntp CWE-20
6.5
2017-03-27 CVE-2017-6463 Improper Input Validation vulnerability in NTP
NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote authenticated users to cause a denial of service (daemon crash) via an invalid setting in a :config directive, related to the unpeer option.
network
low complexity
ntp CWE-20
6.5
2017-03-27 CVE-2017-5932 Improper Input Validation vulnerability in GNU Bash 4.4
The path autocompletion feature in Bash 4.4 allows local users to gain privileges via a crafted filename starting with a " (double quote) character and a command substitution metacharacter.
local
low complexity
gnu CWE-20
7.8
2017-03-25 CVE-2017-7262 Improper Input Validation vulnerability in AMD Ryzen 20170127
The AMD Ryzen processor with AGESA microcode through 2017-01-27 allows local users to cause a denial of service (system hang) via an application that makes a long series of FMA3 instructions, as demonstrated by the Flops test suite.
local
low complexity
amd CWE-20
5.5
2017-03-24 CVE-2017-7261 Improper Input Validation vulnerability in Linux Kernel
The vmw_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.10.5 does not check for a zero value of certain levels data, which allows local users to cause a denial of service (ZERO_SIZE_PTR dereference, and GPF and possibly panic) via a crafted ioctl call for a /dev/dri/renderD* device.
local
low complexity
linux CWE-20
5.5
2017-03-24 CVE-2016-6206 Improper Input Validation vulnerability in Huawei Ar3200 Firmware
Huawei AR3200 routers with software before V200R007C00SPC600 allow remote attackers to cause a denial of service or execute arbitrary code via a crafted packet.
network
low complexity
huawei CWE-20
critical
9.8
2017-03-24 CVE-2015-8678 Improper Input Validation vulnerability in Huawei Mate S Firmware and P8 Firmware
The ION driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230 and Mate S smartphones with software CRR-TL00 before CRR-TL00C01B160SP01, CRR-UL00 before CRR-UL00C00B160, and CRR-CL00 before CRR-CL00C92B161 allows remote attackers to cause a denial of service (crash) via a crafted application.
local
low complexity
huawei CWE-20
5.5