Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2021-06-11 CVE-2021-22765 Improper Input Validation vulnerability in Schneider-Electric products
A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that could cause denial of service or remote code execution via a specially crafted HTTP packet
network
low complexity
schneider-electric CWE-20
critical
9.8
2021-06-11 CVE-2021-25411 Improper Input Validation vulnerability in Google Android 10.0/11.0
Improper address validation vulnerability in RKP api prior to SMR JUN-2021 Release 1 allows root privileged local attackers to write read-only kernel memory.
local
low complexity
google CWE-20
4.4
2021-06-11 CVE-2021-25415 Improper Input Validation vulnerability in Google Android 10.0/11.0
Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to remap EL2 memory as writable.
local
low complexity
google CWE-20
5.5
2021-06-11 CVE-2021-25416 Improper Input Validation vulnerability in Google Android 10.0/11.0
Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to create executable kernel page outside code area.
local
low complexity
google CWE-20
6.5
2021-06-11 CVE-2021-25683 Improper Input Validation vulnerability in Canonical Apport
It was discovered that the get_starttime() function in data/apport did not properly parse the /proc/pid/stat file from the kernel.
local
low complexity
canonical CWE-20
7.8
2021-06-11 CVE-2021-25684 Improper Input Validation vulnerability in Canonical Apport
It was discovered that apport in data/apport did not properly open a report file to prevent hanging reads on a FIFO.
local
low complexity
canonical CWE-20
7.8
2021-06-10 CVE-2021-20329 Improper Input Validation vulnerability in Mongodb GO Driver
Specific cstrings input may not be properly validated in the MongoDB Go Driver when marshalling Go objects into BSON.
network
low complexity
mongodb CWE-20
6.5
2021-06-09 CVE-2021-0051 Improper Input Validation vulnerability in Intel Server Platform Services
Improper input validation in the Intel(R) SPS versions before SPS_E5_04.04.04.023.0, SPS_E5_04.04.03.228.0 or SPS_SoC-A_05.00.03.098.0 may allow a privileged user to potentially enable denial of service via local access.
local
low complexity
intel CWE-20
4.4
2021-06-09 CVE-2021-0134 Improper Input Validation vulnerability in Intel Secl-Dc
Improper input validation in an API for the Intel(R) Security Library before version 3.3 may allow a privileged user to potentially enable denial of service via network access.
network
low complexity
intel CWE-20
4.9
2021-06-09 CVE-2020-12295 Improper Input Validation vulnerability in Intel products
Improper input validation in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access.
local
low complexity
intel CWE-20
5.5