Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2021-11-12 CVE-2021-38972 Improper Input Validation vulnerability in IBM products
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
network
low complexity
ibm CWE-20
4.3
2021-11-12 CVE-2021-38973 Improper Input Validation vulnerability in IBM products
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
network
low complexity
ibm CWE-20
2.7
2021-11-12 CVE-2021-38985 Improper Input Validation vulnerability in IBM products
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
network
low complexity
ibm CWE-20
4.3
2021-11-11 CVE-2021-34417 Improper Input Validation vulnerability in Zoom products
The network proxy page on the web portal for the Zoom On-Premise Meeting Connector Controller before version 4.6.365.20210703, Zoom On-Premise Meeting Connector MMR before version 4.6.365.20210703, Zoom On-Premise Recording Connector before version 3.8.45.20210703, Zoom On-Premise Virtual Room Connector before version 4.4.6868.20210703, and Zoom On-Premise Virtual Room Connector Load Balancer before version 2.5.5496.20210703 fails to validate input sent in requests to set the network proxy password.
network
low complexity
zoom CWE-20
7.2
2021-11-11 CVE-2021-3910 Improper Input Validation vulnerability in multiple products
OctoRPKI crashes when encountering a repository that returns an invalid ROA (just an encoded NUL (\0) character).
network
low complexity
cloudflare debian CWE-20
7.5
2021-11-08 CVE-2021-41772 Improper Input Validation vulnerability in multiple products
Go before 1.16.10 and 1.17.x before 1.17.3 allows an archive/zip Reader.Open panic via a crafted ZIP archive containing an invalid name or an empty filename field.
network
low complexity
golang fedoraproject oracle CWE-20
7.5
2021-11-05 CVE-2021-43406 Improper Input Validation vulnerability in Fusionpbx
An issue was discovered in FusionPBX before 4.5.30.
network
low complexity
fusionpbx CWE-20
8.8
2021-11-05 CVE-2021-25503 Improper Input Validation vulnerability in Google Android
Improper input validation vulnerability in HDCP prior to SMR Nov-2021 Release 1 allows attackers to arbitrary code execution.
local
low complexity
google CWE-20
6.7
2021-11-05 CVE-2021-25509 Improper Input Validation vulnerability in Samsung Flow
A missing input validation in Samsung Flow Windows application prior to Version 4.8.5.0 allows attackers to overwrite abtraty file in the Windows known folders.
local
low complexity
samsung CWE-20
7.1
2021-11-04 CVE-2021-40127 Improper Input Validation vulnerability in Cisco products
A vulnerability in the web-based management interface of Cisco Small Business 200 Series Smart Switches, Cisco Small Business 300 Series Managed Switches, and Cisco Small Business 500 Series Stackable Managed Switches could allow an unauthenticated, remote attacker to render the web-based management interface unusable, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
5.3