Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2017-03-07 CVE-2016-9726 Improper Input Validation vulnerability in IBM products
IBM QRadar Incident Forensics 7.2 could allow a remote authenticated attacker to execute arbitrary commands on the system.
network
low complexity
ibm CWE-20
8.8
2017-03-07 CVE-2016-9693 Improper Input Validation vulnerability in IBM Business Process Manager
IBM Business Process Manager 7.5, 8.0, and 8.5 has a file download capability that is vulnerable to a set of attacks.
local
low complexity
ibm CWE-20
6.1
2017-03-07 CVE-2016-6247 Improper Input Validation vulnerability in Openbsd 5.8/5.9
OpenBSD 5.8 and 5.9 allows certain local users to cause a denial of service (kernel panic) by unmounting a filesystem with an open vnode on the mnt_vnodelist.
local
low complexity
openbsd CWE-20
5.5
2017-03-07 CVE-2016-6246 Improper Input Validation vulnerability in Openbsd 5.8/5.9
OpenBSD 5.8 and 5.9 allows certain local users with kern.usermount privileges to cause a denial of service (kernel panic) by mounting a tmpfs with a VNOVAL in the (1) username, (2) groupname, or (3) device name of the root node.
local
low complexity
openbsd CWE-20
4.4
2017-03-07 CVE-2016-6243 Improper Input Validation vulnerability in Openbsd 5.8/5.9
thrsleep in kern/kern_synch.c in OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (kernel panic) via a crafted value in the tsp parameter of the __thrsleep system call.
local
low complexity
openbsd CWE-20
5.5
2017-03-07 CVE-2016-6239 Improper Input Validation vulnerability in Openbsd 5.8/5.9
The mmap extension __MAP_NOFAULT in OpenBSD 5.8 and 5.9 allows attackers to cause a denial of service (kernel panic and crash) via a large size value.
local
low complexity
openbsd CWE-20
5.5
2017-03-07 CVE-2016-6244 Improper Input Validation vulnerability in Openbsd 5.9
The sys_thrsigdivert function in kern/kern_sig.c in the OpenBSD kernel 5.9 allows remote attackers to cause a denial of service (panic) via a negative "ts.tv_sec" value.
network
low complexity
openbsd CWE-20
7.5
2017-03-06 CVE-2017-6504 Improper Input Validation vulnerability in Qbittorrent
WebUI in qBittorrent before 3.3.11 did not set the X-Frame-Options header, which could potentially lead to clickjacking.
network
low complexity
qbittorrent CWE-20
6.1
2017-03-06 CVE-2017-6498 Improper Input Validation vulnerability in multiple products
An issue was discovered in ImageMagick 6.9.7.
local
low complexity
imagemagick debian CWE-20
5.5
2017-03-04 CVE-2017-6473 Improper Input Validation vulnerability in multiple products
In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a K12 file parser crash, triggered by a malformed capture file.
network
low complexity
wireshark debian CWE-20
7.5