Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2005-05-02 CVE-2005-0050 Improper Input Validation vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows NT
The License Logging service for Windows NT Server, Windows 2000 Server, and Windows Server 2003 does not properly validate the length of messages, which leads to an "unchecked buffer" and allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, aka the "License Logging Service Vulnerability."
network
low complexity
microsoft CWE-20
critical
10.0
2005-01-18 CVE-2005-0116 Improper Input Validation vulnerability in Awstats
AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacters in the configdir parameter to aswtats.pl.
network
low complexity
awstats CWE-20
7.5
2005-01-10 CVE-2004-1125 Improper Input Validation vulnerability in multiple products
Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3.2.3 and 3.3.x to 3.3.2, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PDF file that causes the boundaries of a maskColors array to be exceeded.
9.3
2005-01-10 CVE-2004-1019 Improper Input Validation vulnerability in multiple products
The deserialization code in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to cause a denial of service and execute arbitrary code via untrusted data to the unserialize function that may trigger "information disclosure, double-free and negative reference index array underflow" results.
network
low complexity
openpkg php trustix ubuntu CWE-20
critical
10.0
2004-12-31 CVE-2004-2706 Improper Input Validation vulnerability in Phrozensmoke Gyach Enhanced
Unspecified vulnerability in Gyach Enhanced (Gyach-E) before 1.0.4 allows remote attackers to cause a denial of service (crash) via conference packets with error messages.
network
low complexity
phrozensmoke CWE-20
5.0
2004-12-31 CVE-2004-2649 Improper Input Validation vulnerability in Eudora 6.1.0.6
Eudora 6.1.0.6 allows remote attackers to obfuscate URLs displayed in the status bar by inserting a large number of characters (e.g.
network
eudora CWE-20
5.8
2004-12-31 CVE-2004-2596 Improper Input Validation vulnerability in ID Software Quake II Server 3.20/3.21
Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (exhaustion of connection slots) via a large number of connections from the same IP address.
network
low complexity
id-software CWE-20
5.0
2004-12-31 CVE-2004-2592 Improper Input Validation vulnerability in ID Software Quake II Server 3.20/3.21
Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (application crash) via a modified client that asks the server to send data stored at a negative array offset, which is not handled when processing Configstrings and Baselines.
network
low complexity
id-software CWE-20
5.0
2004-12-31 CVE-2004-2533 Improper Input Validation vulnerability in Solarwinds Serv-U File Server 4.1.0.0
Serv-U FTP Server 4.1 (possibly 4.0) allows remote attackers to cause a denial of service (application crash) via a SITE CHMOD command with a "\\...\" followed by a short string, causing partial memory corruption, a different vulnerability than CVE-2004-2111.
network
low complexity
solarwinds CWE-20
5.0
2004-12-31 CVE-2004-1777 Improper Input Validation vulnerability in Skype Technologies Skype 0.98.0.04
A "range check error" in Skype for Windows before 0.98.0.28 allows local and remote attackers to cause a denial of service (application crash) via long command line arguments or a long callto:// URL, a different vulnerability than CVE-2004-1114.
network
low complexity
skype-technologies CWE-20
5.0