Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2017-01-13 CVE-2016-7431 Improper Input Validation vulnerability in NTP 4.2.8
NTP before 4.2.8p9 allows remote attackers to bypass the origin timestamp protection mechanism via an origin timestamp of zero.
network
low complexity
ntp CWE-20
5.3
2017-01-12 CVE-2016-7791 Improper Input Validation vulnerability in Exponentcms Exponent CMS 2.3.9
Exponent CMS 2.3.9 suffers from a remote code execution vulnerability in /install/index.php.
network
low complexity
exponentcms CWE-20
critical
9.8
2017-01-12 CVE-2016-7790 Improper Input Validation vulnerability in Exponentcms Exponent CMS 2.3.9
Exponent CMS 2.3.9 suffers from a remote code execution vulnerability in /install/index.php.
network
low complexity
exponentcms CWE-20
critical
9.8
2017-01-12 CVE-2017-0389 Improper Input Validation vulnerability in Google Android
A denial of service vulnerability in core networking could enable a remote attacker to use specially crafted network packet to cause a device hang or reboot.
network
low complexity
google CWE-20
7.5
2017-01-12 CVE-2016-8442 Improper Input Validation vulnerability in Linux Kernel 3.18
Possible unauthorized memory access in the hypervisor.
local
low complexity
linux CWE-20
7.8
2017-01-12 CVE-2016-8437 Improper Input Validation vulnerability in Linux Kernel 3.18
Improper input validation in Access Control APIs.
network
low complexity
linux CWE-20
critical
9.8
2017-01-12 CVE-2016-9444 Improper Input Validation vulnerability in ISC Bind
named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted DS resource record in an answer.
network
low complexity
isc CWE-20
7.5
2017-01-12 CVE-2016-9147 Improper Input Validation vulnerability in ISC Bind 9.10.4/9.11.0/9.9.9
named in ISC BIND 9.9.9-P4, 9.9.9-S6, 9.10.4-P4, and 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a response containing an inconsistency among the DNSSEC-related RRsets.
network
low complexity
isc CWE-20
7.5
2017-01-12 CVE-2016-9131 Improper Input Validation vulnerability in multiple products
named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed response to an RTYPE ANY query.
network
low complexity
isc debian redhat netapp CWE-20
7.5
2017-01-11 CVE-2017-2947 Improper Input Validation vulnerability in Adobe products
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have a security bypass vulnerability when manipulating Form Data Format (FDF).
local
low complexity
adobe CWE-20
5.5