Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2016-10-14 CVE-2016-7182 Improper Input Validation vulnerability in Microsoft products
The Graphics component in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; and Live Meeting 2007 Console allows attackers to execute arbitrary code via a crafted True Type font, aka "True Type Font Parsing Elevation of Privilege Vulnerability."
network
low complexity
microsoft CWE-20
critical
9.8
2016-10-13 CVE-2016-7796 Improper Input Validation vulnerability in multiple products
The manager_dispatch_notify_fd function in systemd allows local users to cause a denial of service (system hang) via a zero-length message received over a notify socket, which causes an error to be returned and the notification handler to be disabled.
local
low complexity
systemd-project novell redhat CWE-20
5.5
2016-10-13 CVE-2016-7795 Improper Input Validation vulnerability in multiple products
The manager_invoke_notify_message function in systemd 231 and earlier allows local users to cause a denial of service (assertion failure and PID 1 hang) via a zero-length message received over a notify socket.
local
low complexity
canonical systemd-project CWE-20
5.5
2016-10-13 CVE-2016-8563 Improper Input Validation vulnerability in Siemens Automation License Manager 5.3
Siemens Automation License Manager (ALM) before 5.3 SP3 Update 1 allows remote attackers to cause a denial of service (ALM service outage) via crafted packets to TCP port 4410.
network
low complexity
siemens CWE-20
7.5
2016-10-10 CVE-2016-6696 Improper Input Validation vulnerability in Google Android
sound/soc/msm/qdsp6v2/msm-ds2-dap-config.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 allows attackers to cause a denial of service or possibly have unspecified other impact via a large negative value for the data length, aka Qualcomm internal bug CR 1041130.
network
low complexity
google CWE-20
critical
9.8
2016-10-10 CVE-2016-6694 Improper Input Validation vulnerability in Google Android
sound/soc/msm/qdsp6v2/msm-ds2-dap-config.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 allows attackers to cause a denial of service or possibly have unspecified other impact via crafted parameter data, aka Qualcomm internal bug CR 1033525.
network
low complexity
google CWE-20
critical
9.8
2016-10-10 CVE-2016-6693 Improper Input Validation vulnerability in Google Android
sound/soc/msm/qdsp6v2/msm-ds2-dap-config.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 allows attackers to cause a denial of service or possibly have unspecified other impact via an invalid data length, aka Qualcomm internal bug CR 1027585.
network
low complexity
google CWE-20
critical
9.8
2016-10-10 CVE-2016-6674 Improper Input Validation vulnerability in Google Android
system_server in Android before 2016-10-05 on Nexus devices allows attackers to gain privileges via a crafted application, aka internal bug 30445380.
local
low complexity
google CWE-20
7.8
2016-10-10 CVE-2016-3937 Improper Input Validation vulnerability in Google Android
The MediaTek video driver in Android before 2016-10-05 allows attackers to gain privileges via a crafted application, aka Android internal bug 30030994 and MediaTek internal bug ALPS02834874.
local
low complexity
google CWE-20
7.8
2016-10-10 CVE-2016-3936 Improper Input Validation vulnerability in Google Android
The MediaTek video driver in Android before 2016-10-05 allows attackers to gain privileges via a crafted application, aka Android internal bug 30019037 and MediaTek internal bug ALPS02829568.
local
low complexity
google CWE-20
7.8