Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2016-05-13 CVE-2015-5726 Improper Input Validation vulnerability in multiple products
The BER decoder in Botan 0.10.x before 1.10.10 and 1.11.x before 1.11.19 allows remote attackers to cause a denial of service (application crash) via an empty BIT STRING in ASN.1 data.
network
low complexity
botan-project debian CWE-20
7.5
2016-05-12 CVE-2016-4498 Improper Input Validation vulnerability in Panasonic Fpwin PRO
Panasonic FPWIN Pro 5.x through 7.x before 7.130 accesses an uninitialized pointer, which allows local users to cause a denial of service or possibly have unspecified other impact via unknown vectors.
network
low complexity
panasonic CWE-20
5.5
2016-05-12 CVE-2016-4497 Improper Input Validation vulnerability in Panasonic Fpwin PRO
Panasonic FPWIN Pro 5.x through 7.x before 7.130 allows local users to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion."
local
high complexity
panasonic CWE-20
4.2
2016-05-11 CVE-2016-1115 Improper Input Validation vulnerability in Adobe Coldfusion 10.0/11.0/2016
Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update 1 mishandles wildcards in name fields of X.509 certificates, which might allow man-in-the-middle attackers to spoof servers via a crafted certificate.
network
high complexity
adobe CWE-20
5.9
2016-05-10 CVE-2016-4555 Improper Input Validation vulnerability in multiple products
client_side_request.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via crafted Edge Side Includes (ESI) responses.
network
low complexity
squid-cache canonical oracle CWE-20
7.5
2016-05-09 CVE-2015-5208 Improper Input Validation vulnerability in Apache Cordova
Apache Cordova iOS before 4.0.0 allows remote attackers to execute arbitrary plugins via a link.
local
low complexity
apache CWE-20
4.4
2016-05-09 CVE-2016-4476 Improper Input Validation vulnerability in multiple products
hostapd 0.6.7 through 2.5 and wpa_supplicant 0.6.7 through 2.5 do not reject \n and \r characters in passphrase parameters, which allows remote attackers to cause a denial of service (daemon outage) via a crafted WPS operation.
network
low complexity
w1-fi canonical CWE-20
7.5
2016-05-09 CVE-2016-2454 Improper Input Validation vulnerability in Google Android
The Qualcomm hardware video codec in Android before 2016-05-01 on Nexus 5 devices allows remote attackers to cause a denial of service (reboot) via a crafted file, aka internal bug 26221024.
local
low complexity
google CWE-20
5.5
2016-05-07 CVE-2016-1541 Improper Input Validation vulnerability in Libarchive
Heap-based buffer overflow in the zip_read_mac_metadata function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remote attackers to execute arbitrary code via crafted entry-size values in a ZIP archive.
network
low complexity
libarchive CWE-20
8.8
2016-05-05 CVE-2016-4535 Improper Input Validation vulnerability in Mcafee Livesafe 14.0
Integer signedness error in the AV engine before DAT 8145, as used in McAfee LiveSafe 14.0, allows remote attackers to cause a denial of service (memory corruption and crash) via a crafted packed executable.
network
low complexity
mcafee CWE-20
7.5