Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2005-05-02 CVE-2005-0904 Improper Input Validation vulnerability in Microsoft Windows XP
Remote Desktop in Windows XP SP1 does not verify the "Force shutdown from a remote system" setting, which allows remote attackers to shut down the system by executing TSShutdn.exe.
local
low complexity
microsoft CWE-20
2.1
2005-05-02 CVE-2005-0850 Improper Input Validation vulnerability in Filezilla-Project Filezilla Server
FileZilla FTP server before 0.9.6 allows remote attackers to cause a denial of service via a request for a filename containing an MS-DOS device name such as CON, NUL, COM1, LPT1, and others.
network
low complexity
filezilla-project CWE-20
5.0
2005-05-02 CVE-2005-0492 Improper Input Validation vulnerability in Adobe Acrobat Reader 6.0.3/7.0
Adobe Acrobat Reader 6.0.3 and 7.0.0 allows remote attackers to cause a denial of service (application crash) via a PDF file that contains a negative Count value in the root page node.
network
high complexity
adobe CWE-20
2.6
2005-05-02 CVE-2005-0449 Improper Input Validation vulnerability in Linux Kernel
The netfilter/iptables module in Linux before 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) or bypass firewall rules via crafted packets, which are not properly handled by the skb_checksum_help function.
network
linux CWE-20
7.1
2005-05-02 CVE-2005-0209 Improper Input Validation vulnerability in Linux Kernel 2.6.8.1
Netfilter in Linux kernel 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) via crafted IP packet fragments.
network
low complexity
linux CWE-20
7.8
2005-05-02 CVE-2005-0200 Improper Input Validation vulnerability in Tiki Tikiwiki Cms/Groupware 1.6.1
TikiWiki before 1.8.5 does not properly validate files that have been uploaded to the temp directory, which could allow remote attackers to upload and execute arbitrary PHP scripts, a different vulnerability than CVE-2004-1386.
network
low complexity
tiki CWE-20
7.5
2005-05-02 CVE-2005-0050 Improper Input Validation vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows NT
The License Logging service for Windows NT Server, Windows 2000 Server, and Windows Server 2003 does not properly validate the length of messages, which leads to an "unchecked buffer" and allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, aka the "License Logging Service Vulnerability."
network
low complexity
microsoft CWE-20
critical
10.0
2005-01-18 CVE-2005-0116 Improper Input Validation vulnerability in Awstats
AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacters in the configdir parameter to aswtats.pl.
network
low complexity
awstats CWE-20
7.5
2005-01-10 CVE-2004-1125 Improper Input Validation vulnerability in multiple products
Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3.2.3 and 3.3.x to 3.3.2, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PDF file that causes the boundaries of a maskColors array to be exceeded.
9.3
2005-01-10 CVE-2004-1019 Improper Input Validation vulnerability in multiple products
The deserialization code in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to cause a denial of service and execute arbitrary code via untrusted data to the unserialize function that may trigger "information disclosure, double-free and negative reference index array underflow" results.
network
low complexity
openpkg php trustix ubuntu CWE-20
critical
10.0