Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2008-05-16 CVE-2008-1741 Improper Input Validation vulnerability in Cisco Unified Presence 6.01
The SIP Proxy (SIPD) service in Cisco Unified Presence before 6.0(3) allows remote attackers to cause a denial of service (core dump and service interruption) via a TCP port scan, aka Bug ID CSCsj64533.
network
low complexity
cisco CWE-20
7.8
2008-05-16 CVE-2008-1740 Improper Input Validation vulnerability in Cisco Unified Presence 6.01
The Presence Engine (PE) service in Cisco Unified Presence before 6.0(1) allows remote attackers to cause a denial of service (core dump and service interruption) via an unspecified "stress test," aka Bug ID CSCsh20972.
network
low complexity
cisco CWE-20
7.8
2008-05-16 CVE-2008-1419 Improper Input Validation vulnerability in Xiph.Org Libvorbis
Xiph.org libvorbis 1.2.0 and earlier does not properly handle a zero value for codebook.dim, which allows remote attackers to cause a denial of service (crash or infinite loop) or trigger an integer overflow.
4.3
2008-05-16 CVE-2008-1158 Improper Input Validation vulnerability in Cisco Unified Presence and Unified Presence Server
The Presence Engine (PE) service in Cisco Unified Presence before 6.0(1) allows remote attackers to cause a denial of service (core dump and service interruption) via malformed packets, aka Bug ID CSCsh50164.
network
low complexity
cisco CWE-20
7.8
2008-05-13 CVE-2008-2173 Improper Input Validation vulnerability in Yamaha Router
Unspecified vulnerability in Yamaha routers allows remote attackers to cause a denial of service (dropped session) via crafted BGP UPDATE messages, leading to route flapping, possibly a related issue to CVE-2007-6372.
network
yamaha CWE-20
7.1
2008-05-13 CVE-2008-2172 Improper Input Validation vulnerability in Hitachi Gr2000, Gr3000 and Gr4000
Unspecified vulnerability in Hitachi GR routers allows remote attackers to cause a denial of service (dropped session) via crafted BGP UPDATE messages, leading to route flapping, possibly a related issue to CVE-2007-6372.
network
hitachi CWE-20
7.1
2008-05-13 CVE-2008-2171 Improper Input Validation vulnerability in Alaxala AX Router
Unspecified vulnerability in AlaxalA AX routers allows remote attackers to cause a denial of service (dropped session) via crafted BGP UPDATE messages, leading to route flapping, possibly a related issue to CVE-2007-6372.
network
alaxala CWE-20
7.1
2008-05-13 CVE-2008-2170 Improper Input Validation vulnerability in Century Software Router
Unspecified vulnerability in Century routers allows remote attackers to cause a denial of service (dropped session) via crafted BGP UPDATE messages, leading to route flapping, possibly a related issue to CVE-2007-6372.
7.1
2008-05-13 CVE-2008-2169 Improper Input Validation vulnerability in multiple products
Unspecified vulnerability in Avici routers allows remote attackers to cause a denial of service (dropped session) via crafted BGP UPDATE messages, leading to route flapping, possibly a related issue to CVE-2007-6372.
network
avici hitachi CWE-20
7.1
2008-05-09 CVE-2008-2134 Improper Input Validation vulnerability in Tru-Zone Nukeet
The Journal module in Tru-Zone Nuke ET 3.x allows remote attackers to obtain access to arbitrary user accounts, and alter or delete data, via a modified username in an unspecified cookie.
network
tru-zone CWE-20
6.8