Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2016-02-10 CVE-2016-0037 Improper Input Validation vulnerability in Microsoft Windows Server 2012 R2
The forms-based authentication implementation in Active Directory Federation Services (ADFS) 3.0 in Microsoft Windows Server 2012 R2 allows remote attackers to cause a denial of service (daemon outage) via crafted data, aka "Microsoft Active Directory Federation Services Denial of Service Vulnerability."
network
low complexity
microsoft CWE-20
7.5
2016-02-08 CVE-2016-2089 Improper Input Validation vulnerability in Jasper Project Jasper 1.900.1
The jas_matrix_clip function in jas_seq.c in JasPer 1.900.1 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted JPEG 2000 image.
network
low complexity
jasper-project CWE-20
6.5
2016-02-08 CVE-2015-8360 Improper Input Validation vulnerability in Atlassian Bamboo
An unspecified resource in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 allows remote attackers to execute arbitrary Java code via serialized data to the JMS port.
network
low complexity
atlassian CWE-20
critical
9.8
2016-02-08 CVE-2014-9757 Improper Input Validation vulnerability in Atlassian Bamboo
The Ignite Realtime Smack XMPP API, as used in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0, allows remote configured XMPP servers to execute arbitrary Java code via serialized data in an XMPP message.
network
low complexity
atlassian CWE-20
critical
9.8
2016-02-08 CVE-2016-2201 Improper Input Validation vulnerability in Siemens Simatic S7-1500 CPU Firmware 1.8.2
Siemens SIMATIC S7-1500 CPU devices before 1.8.3 allow remote attackers to bypass a replay protection mechanism via packets on TCP port 102.
network
low complexity
siemens CWE-20
5.3
2016-02-08 CVE-2016-2200 Improper Input Validation vulnerability in Siemens Simatic S7-1500 CPU Firmware 1.5.1/1.6/1.8.2
Siemens SIMATIC S7-1500 CPU devices before 1.8.3 allow remote attackers to cause a denial of service (STOP mode transition) via crafted packets on TCP port 102.
network
low complexity
siemens CWE-20
7.5
2016-02-07 CVE-2016-0802 Improper Input Validation vulnerability in multiple products
The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted wireless control message packets, aka internal bug 25306181.
low complexity
google apple CWE-20
8.8
2016-02-07 CVE-2016-0801 Improper Input Validation vulnerability in multiple products
The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted wireless control message packets, aka internal bug 25662029.
network
low complexity
apple google CWE-20
critical
9.8
2016-02-04 CVE-2016-1284 Improper Input Validation vulnerability in ISC Bind 9.9.8
rdataset.c in ISC BIND 9 Supported Preview Edition 9.9.8-S before 9.9.8-S5, when nxdomain-redirect is enabled, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via crafted flag values in a query.
network
high complexity
isc CWE-20
5.9
2016-02-03 CVE-2015-8747 Improper Input Validation vulnerability in Radicale 1.0/1.0.1
The multifilesystem storage backend in Radicale before 1.1 allows remote attackers to read or write to arbitrary files via a crafted component name.
network
low complexity
radicale CWE-20
critical
10.0