Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2016-06-13 CVE-2016-2477 Improper Input Validation vulnerability in Google Android
mm-video-v4l2/vidc/vdec/src/omx_vdec_msm8974.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 mishandles pointers, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 27251096.
local
low complexity
google CWE-20
7.8
2016-06-13 CVE-2016-2475 Improper Input Validation vulnerability in Google Android
The Broadcom Wi-Fi driver in Android before 2016-06-01 on Nexus 5, Nexus 6, Nexus 6P, Nexus 7 (2013), Nexus 9, Nexus Player, and Pixel C devices allows attackers to gain privileges for certain system calls via a crafted application, aka internal bug 26425765.
local
low complexity
google CWE-20
7.8
2016-06-13 CVE-2016-2464 Improper Input Validation vulnerability in Google Android
libvpx in libwebm in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted mkv file, aka internal bug 23167726.
local
low complexity
google CWE-20
7.8
2016-06-10 CVE-2016-3706 Improper Input Validation vulnerability in multiple products
Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in the GNU C Library (aka glibc or libc6) allows remote attackers to cause a denial of service (crash) via vectors involving hostent conversion.
network
low complexity
opensuse gnu CWE-20
7.5
2016-06-10 CVE-2016-2786 Improper Input Validation vulnerability in Puppet Agent and Puppet Enterprise
The pxp-agent component in Puppet Enterprise 2015.3.x before 2015.3.3 and Puppet Agent 1.3.x before 1.3.6 does not properly validate server certificates, which might allow remote attackers to spoof brokers and execute arbitrary commands via a crafted certificate.
network
low complexity
puppet CWE-20
critical
9.8
2016-06-10 CVE-2016-1419 Improper Input Validation vulnerability in Cisco Aironet Access Point Software 8.2(102.43)
Cisco Access Point devices with software 8.2(102.43) allow remote attackers to cause a denial of service (device reload) via crafted ARP packets, aka Bug ID CSCuy55803.
low complexity
cisco CWE-20
8.1
2016-06-09 CVE-2016-4449 Improper Input Validation vulnerability in multiple products
XML external entity (XXE) vulnerability in the xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.4, when not in validating mode, allows context-dependent attackers to read arbitrary files or cause a denial of service (resource consumption) via unspecified vectors.
local
low complexity
debian canonical xmlsoft CWE-20
7.1
2016-06-08 CVE-2016-4368 Improper Input Validation vulnerability in HP products
HPE Universal CMDB 10.0 through 10.21, Universal CMDB Configuration Manager 10.0 through 10.21, and Universal Discovery 10.0 through 10.21 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
network
low complexity
hp CWE-20
critical
9.8
2016-06-08 CVE-2016-1418 Improper Input Validation vulnerability in Cisco Aironet Access Point Software 8.2(100.0)
Cisco Aironet Access Point Software 8.2(100.0) on 1830e, 1830i, 1850e, 1850i, 2800, and 3800 access points allows local users to obtain Linux root access via crafted CLI command parameters, aka Bug ID CSCuy64037.
local
low complexity
cisco CWE-20
7.8
2016-06-07 CVE-2016-4545 Improper Input Validation vulnerability in F5 products
Virtual servers in F5 BIG-IP 11.5.4, when SSL profiles are enabled, allow remote attackers to cause a denial of service (resource consumption and Traffic Management Microkernel restart) via an SSL alert during the handshake.
network
low complexity
f5 CWE-20
7.5