Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2022-01-03 CVE-2021-30278 Improper Input Validation vulnerability in Qualcomm products
Improper input validation in TrustZone memory transfer interface can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking
local
low complexity
qualcomm CWE-20
5.5
2021-12-28 CVE-2021-44832 Improper Input Validation vulnerability in multiple products
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server.
network
high complexity
apache oracle cisco fedoraproject debian CWE-20
6.6
2021-12-27 CVE-2021-45687 Improper Input Validation vulnerability in Raw-Cpuid Project Raw-Cpuid
An issue was discovered in the raw-cpuid crate before 9.1.1 for Rust.
network
low complexity
raw-cpuid-project CWE-20
critical
9.8
2021-12-27 CVE-2021-45711 Improper Input Validation vulnerability in Simple Asn1 Project Simple Asn1 0.6.0
An issue was discovered in the simple_asn1 crate 0.6.0 before 0.6.1 for Rust.
network
low complexity
simple-asn1-project CWE-20
7.5
2021-12-26 CVE-2021-41788 Improper Input Validation vulnerability in Mediatek products
MediaTek microchips, as used in NETGEAR devices through 2021-12-13 and other devices, mishandle attempts at Wi-Fi authentication flooding.
network
low complexity
mediatek CWE-20
7.5
2021-12-23 CVE-2021-38015 Improper Input Validation vulnerability in multiple products
Inappropriate implementation in input in Google Chrome prior to 96.0.4664.45 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.
network
low complexity
google fedoraproject debian CWE-20
8.8
2021-12-23 CVE-2021-4059 Improper Input Validation vulnerability in multiple products
Insufficient data validation in loader in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
network
low complexity
google fedoraproject debian CWE-20
6.5
2021-12-20 CVE-2021-41561 Improper Input Validation vulnerability in Apache Parquet-Mr
Improper Input Validation vulnerability in Parquet-MR of Apache Parquet allows an attacker to DoS by malicious Parquet files.
network
low complexity
apache CWE-20
7.5
2021-12-17 CVE-2021-37863 Improper Input Validation vulnerability in Mattermost Server
Mattermost 6.0 and earlier fails to sufficiently validate parameters during post creation, which allows authenticated attackers to cause a client-side crash of the web application via a maliciously crafted post.
network
low complexity
mattermost CWE-20
5.7
2021-12-15 CVE-2021-0921 Improper Input Validation vulnerability in Google Android 11.0
In ParsingPackageImpl of ParsingPackageImpl.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation.
local
low complexity
google CWE-20
7.8