Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2017-01-09 CVE-2016-8106 Improper Input Validation vulnerability in multiple products
A Denial of Service in Intel Ethernet Controller's X710/XL710 with Non-Volatile Memory Images before version 5.05 allows a remote attacker to stop the controller from processing network traffic working under certain network use conditions.
network
high complexity
intel hp lenovo CWE-20
5.9
2017-01-09 CVE-2017-5217 Improper Input Validation vulnerability in Samsung Mobile
Installing a zero-permission Android application on certain Samsung Android devices with KK(4.4), L(5.0/5.1), and M(6.0) software can continually crash the system_server process in the Android OS.
local
low complexity
samsung CWE-20
5.5
2017-01-06 CVE-2016-4329 Improper Input Validation vulnerability in Kaspersky Anti-Virus, Internet Security and Total Security
A local denial of service vulnerability exists in window broadcast message handling functionality of Kaspersky Anti-Virus software.
local
low complexity
kaspersky CWE-20
5.5
2017-01-06 CVE-2016-1547 Improper Input Validation vulnerability in NTP
An off-path attacker can cause a preemptible client association to be demobilized in NTP 4.2.8p4 and earlier and NTPSec a5fb34b9cc89b92a8fef2f459004865c93bb7f92 by sending a crypto NAK packet to a victim client with a spoofed source address of an existing associated peer.
network
low complexity
ntp CWE-20
5.3
2017-01-03 CVE-2016-5024 Improper Input Validation vulnerability in F5 products
Virtual servers in F5 BIG-IP systems 11.6.1 before 11.6.1 HF1 and 12.1.x before 12.1.2, when configured to parse RADIUS messages via an iRule, allow remote attackers to cause a denial of service (Traffic Management Microkernel restart) via crafted network traffic.
network
high complexity
f5 CWE-20
5.9
2017-01-02 CVE-2016-10100 Improper Input Validation vulnerability in Borg
Borg (aka BorgBackup) before 1.0.9 has a flaw in the way duplicate archive names were processed during manifest recovery, potentially allowing an attacker to overwrite an archive.
network
low complexity
borg CWE-20
5.3
2016-12-29 CVE-2015-8744 Improper Input Validation vulnerability in multiple products
QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue.
local
low complexity
qemu debian CWE-20
5.5
2016-12-26 CVE-2016-9224 Improper Input Validation vulnerability in Cisco Jabber Guest
A vulnerability in the Cisco Jabber Guest Server could allow an unauthenticated, remote attacker to initiate connections to arbitrary hosts.
network
low complexity
cisco CWE-20
6.5
2016-12-23 CVE-2016-8595 Improper Input Validation vulnerability in Ffmpeg
The gsm_parse function in libavcodec/gsm_parser.c in FFmpeg before 3.1.5 allows remote attackers to cause a denial of service (assert fault) via a crafted AVI file.
local
low complexity
ffmpeg CWE-20
5.5
2016-12-23 CVE-2016-7785 Improper Input Validation vulnerability in Ffmpeg
The avi_read_seek function in libavformat/avidec.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (assert fault) via a crafted AVI file.
local
low complexity
ffmpeg CWE-20
5.5