Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2007-01-29 CVE-2006-6955 Improper Input Validation vulnerability in Opera Browser
Opera allows remote attackers to cause a denial of service (application crash) via a web page that contains a large number of nested marquee tags, a related issue to CVE-2006-2723.
network
opera CWE-20
4.3
2007-01-29 CVE-2006-6954 Improper Input Validation vulnerability in Flock 1.0.7
Flock beta 1 0.7 allows remote attackers to cause a denial of service (application crash) via a web page that contains a large number of nested marquee tags, a related issue to CVE-2006-2723.
network
flock CWE-20
4.3
2007-01-26 CVE-2007-0524 Improper Input Validation vulnerability in LG Electronics Chocolate Kg800
The LG Chocolate KG800 phone allows remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a file over Bluetooth, as demonstrated by ussp-push.
2.9
2007-01-26 CVE-2007-0523 Improper Input Validation vulnerability in Nokia N70
The Nokia N70 phone allows remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a file over Bluetooth, as demonstrated by ussp-push.
low complexity
nokia CWE-20
3.3
2007-01-26 CVE-2007-0522 Improper Input Validation vulnerability in Motorola Motorazr V3
The Motorola MOTORAZR V3 phone allows remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a file over Bluetooth, as demonstrated by ussp-push.
low complexity
motorola CWE-20
3.3
2007-01-26 CVE-2007-0521 Improper Input Validation vulnerability in Sony Ericsson K700I and W810I
The Sony Ericsson K700i and W810i phones allow remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a file over Bluetooth, as demonstrated by ussp-push.
low complexity
sony-ericsson CWE-20
3.3
2007-01-19 CVE-2006-6943 Improper Input Validation vulnerability in PHPmyadmin
PhpMyAdmin before 2.9.1.1 allows remote attackers to obtain the full server path via direct requests to (a) scripts/check_lang.php and (b) themes/darkblue_orange/layout.inc.php; and via the (1) lang[], (2) target[], (3) db[], (4) goto[], (5) table[], and (6) tbl_group[] array arguments to (c) index.php, and the (7) back[] argument to (d) sql.php; and an invalid (8) sort_by parameter to (e) server_databases.php and (9) db parameter to (f) db_printview.php.
network
low complexity
phpmyadmin CWE-20
5.0
2007-01-11 CVE-2007-0197 Improper Input Validation vulnerability in Apple mac OS X 10.4.6/10.4.8
Finder 10.4.6 on Apple Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a long volume name in a DMG disk image, which results in memory corruption.
network
apple CWE-20
6.8
2007-01-09 CVE-2007-0028 Improper Input Validation vulnerability in Microsoft products
Microsoft Excel 2000, 2002, 2003, Viewer 2003, Office 2004 for Mac, and Office v.X for Mac does not properly handle certain opcodes, which allows user-assisted remote attackers to execute arbitrary code via a crafted XLS file, which results in an "Improper Memory Access Vulnerability." NOTE: an early disclosure of this issue used CVE-2006-3432, but only CVE-2007-0028 should be used.
network
microsoft CWE-20
critical
9.3
2007-01-09 CVE-2007-0104 Improper Input Validation vulnerability in multiple products
The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and other products, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node.
network
xpdf kde CWE-20
6.8