CWE-20— Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.— MITRE CWE catalog
11,851 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-20page 2 of 238
- CVE-2003-0368MEDIUMCVSS v2 5.0EG 5.02004-02-03
Nokia Gateway GPRS support node (GGSN) allows remote attackers to cause a denial of service (kernel panic) via a malformed IP packet with a 0xFF TCP option.
- CVE-2003-0567HIGHCVSS v2 7.8EG 7.82003-08-18
Cisco IOS 11.x and 12.0 through 12.2 allows remote attackers to cause a denial of service (traffic block) by sending a particular sequence of IPv4 packets to an interface on the device, causing the input queue on that interface to be marke…
- CVE-2003-0795MEDIUMCVSS v2 5.0EG 5.02003-12-15
The vty layer in Quagga before 0.96.4, and Zebra 0.93b and earlier, does not verify that sub-negotiation is taking place when processing the SE marker, which allows remote attackers to cause a denial of service (crash) via a malformed teln…
- CVE-2003-0825HIGHCVSS v2 9.3EG 9.32004-03-03
The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possib…
- CVE-2003-1003HIGHCVSS v2 7.8EG 7.82004-01-05
Cisco PIX firewall 5.x.x, and 6.3.1 and earlier, allows remote attackers to cause a denial of service (crash and reload) via an SNMPv3 message when snmp-server is set.
- CVE-2003-1025MEDIUMCVSS v2 4.3EG 4.32004-01-20
Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the addres…
- CVE-2003-1209MEDIUMCVSS v2 5.0EG 5.02003-12-31
The Post_Method function in Monkey HTTP Daemon before 0.6.2 allows remote attackers to cause a denial of service (crash) via a POST request without a Content-Type header.
- CVE-2003-1350MEDIUMCVSS v2 4.3EG 4.32003-12-31
List Site Pro 2.0 allows remote attackers to hijack user accounts by inserting a "|" (pipe), which is used as a field delimiter, into the bannerurl field.
- CVE-2003-1364HIGHCVSS v2 8.5EG 8.52003-12-31
Aprelium Technologies Abyss Web Server 1.1.2, and possibly other versions before 1.1.4, allows remote attackers to cause a denial of service (crash) via an HTTP GET message with empty (1) Connection or (2) Range fields.
- CVE-2003-1365MEDIUMCVSS v2 5.0EG 5.02003-12-31
The escape_dangerous_chars function in CGI::Lite 2.0 and earlier does not correctly remove special characters including (1) "\" (backslash), (2) "?", (3) "~" (tilde), (4) "^" (carat), (5) newline, or (6) carriage return, which could allow …
- CVE-2003-1402HIGHCVSS v2 7.5EG 7.52003-12-31
PHP remote file inclusion vulnerability in hit.php for Kietu 2.0 and 2.3 allows remote attackers to execute arbitrary PHP code via the url_hit parameter, a different vulnerability than CVE-2006-5015.
- CVE-2003-1403HIGHCVSS v2 7.5EG 7.52003-12-31
foo.php3 in DotBr 0.1 allows remote attackers to obtain sensitive information via a direct request, which calls the phpinfo function.
- CVE-2003-1405HIGHCVSS v2 7.5EG 7.52003-12-31
DotBr 0.1 allows remote attackers to execute arbitrary shell commands via the cmd parameter to (1) exec.php3 or (2) system.php3.
- CVE-2003-1416MEDIUMCVSS v2 4.3EG 4.32003-12-31
BisonFTP Server 4 release 2 allows remote attackers to cause a denial of service (CPU consumption) via a long (1) ls or (2) cwd command.
- CVE-2003-1419MEDIUMCVSS v2 4.3EG 4.32003-12-31
Netscape 7.0 allows remote attackers to cause a denial of service (crash) via a web page with an invalid regular expression argument to the JavaScript reformatDate function.
- CVE-2003-1425HIGHCVSS v2 10.0EG 10.02003-12-31
guestbook.cgi in cPanel 5.0 allows remote attackers to execute arbitrary commands via the template parameter.
- CVE-2003-1440MEDIUMCVSS v2 4.3EG 4.32003-12-31
SpamProbe 0.8a allows remote attackers to cause a denial of service (crash) via HTML e-mail with newline characters within an href tag, which is not properly handled by certain regular expressions.
- CVE-2003-1441MEDIUMCVSS v2 4.3EG 4.32003-12-31
Posadis 0.50.4 through 0.50.8 allows remote attackers to cause a denial of service (crash) via a DNS message without a question section, which triggers null dereference.
- CVE-2003-1443MEDIUMCVSS v2 4.4EG 4.42003-12-31
Kaspersky Antivirus (KAV) 4.0.9.0 does not detect viruses in files with MS-DOS device names in their filenames, which allows local users to bypass virus protection, as demonstrated using aux.vbs and aux.com.
- CVE-2003-1444MEDIUMCVSS v2 4.4EG 4.42003-12-31
Kaspersky Antivirus (KAV) 4.0.9.0 allows local users to cause a denial of service (CPU consumption or crash) and prevent malicious code from being detected via a file with a long pathname.
- CVE-2003-1450MEDIUMCVSS v2 5.0EG 5.02003-12-31
BitchX 75p3 and 1.0c16 through 1.0c20cvs allows remote attackers to cause a denial of service (segmentation fault) via a malformed RPL_NAMREPLY numeric 353 message.
- CVE-2003-1456MEDIUMCVSS v2 5.0EG 5.02003-12-31
Album.pl 6.1 allows remote attackers to execute arbitrary commands, when an alternative configuration file is used, via unknown attack vectors.
- CVE-2003-1463LOWCVSS v2 3.5EG 3.52003-12-31
Absolute path traversal vulnerability in Alt-N Technologies WebAdmin 2.0.0 through 2.0.2 allows remote attackers with administrator privileges to (1) determine the installation path by reading the contents of the Name parameter in a link, …
- CVE-2003-1471MEDIUMCVSS v2 6.3EG 6.32003-12-31
MDaemon POP server 6.0.7 and earlier allows remote authenticated users to cause a denial of service (crash) via a (1) DELE or (2) UIDL with a negative number.
- CVE-2003-1485MEDIUMCVSS v2 5.0EG 5.02003-12-31
Clearswift MAILsweeper 4.0 through 4.3.7 allows remote attackers to bypass filtering via a file attachment that contains "multiple extensions combined with large blocks of white space."
- CVE-2003-1487HIGHCVSS v2 10.0EG 10.02003-12-31
Multiple "command injection" vulnerabilities in Phorum 3.4 through 3.4.2 allow remote attackers to execute arbitrary commands and modify the Phorum configuration files via the (1) UserAdmin program, (2) Edit user profile, or (3) stats prog…
- CVE-2003-1488MEDIUMCVSS v2 6.4EG 6.42003-12-31
The (1) verif_admin.php and (2) check_admin.php scripts in Truegalerie 1.0 allow remote attackers to gain administrator access via a request to admin.php without the connect parameter and with the loggedin parameter set to any value, such …
- CVE-2003-1490HIGHCVSS v2 7.8EG 7.82003-12-31
SonicWall Pro running firmware 6.4.0.1 allows remote attackers to cause a denial of service (device reset) via a long HTTP POST to the internal interface, possibly due to a buffer overflow.
- CVE-2003-1538MEDIUMCVSS v2 6.4EG 6.42003-12-31
susehelp in SuSE Linux 8.1, Enterprise Server 8, Office Server, and Openexchange Server 4 does not properly filter shell metacharacters, which allows remote attackers to execute arbitrary commands via CGI queries.
- CVE-2003-1568MEDIUMCVSS v2 5.0EG 5.02009-02-06
GoAhead WebServer before 2.1.6 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an invalid URL, related to the websSafeUrl function.
- CVE-2003-1569MEDIUMCVSS v2 5.0EG 5.02009-02-06
GoAhead WebServer before 2.1.5 on Windows 95, 98, and ME allows remote attackers to cause a denial of service (daemon crash) via an HTTP request with a (1) con, (2) nul, (3) clock$, or (4) config$ device name in a path component, different…
- CVE-2004-0244MEDIUMCVSS v2 4.7EG 4.72004-11-23
Cisco 6000, 6500, and 7600 series systems with Multilayer Switch Feature Card 2 (MSFC2) and a FlexWAN or OSM module allow local users to cause a denial of service (hang or reset) by sending a layer 2 frame packet that encapsulates a layer …
- CVE-2004-0276MEDIUMCVSS v2 5.0EG 5.02004-11-23
The get_real_string function in Monkey HTTP Daemon (monkeyd) 0.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request with a sequence of "%" characters and a missing Host field.
- CVE-2004-0411HIGHCVSS v2 7.5EG 7.52004-07-07
The URI handlers in Konqueror for KDE 3.2.2 and earlier do not properly filter "-" characters that begin a hostname in a (1) telnet, (2) rlogin, (3) ssh, or (4) mailto URI, which allows remote attackers to manipulate the options that are p…
- CVE-2004-0840HIGHCVSS v2 10.0EG 10.02004-11-03
The SMTP (Simple Mail Transfer Protocol) component of Microsoft Windows XP 64-bit Edition, Windows Server 2003, Windows Server 2003 64-bit Edition, and the Exchange Routing Engine component of Exchange Server 2003, allows remote attackers …
- CVE-2004-1019HIGHCVSS v2 10.0EG 10.02005-01-10
The deserialization code in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to cause a denial of service and execute arbitrary code via untrusted data to the unserialize function that may trigger "information disclosure, …
- CVE-2004-1125HIGHCVSS v2 9.3EG 9.32005-01-10
Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3.2.3 and 3.3.x to 3.3.2, allows remote attackers to cause a denial of service (application…
- CVE-2004-1386HIGHCVSS v2 7.5EG 7.52004-12-31
TikiWiki before 1.8.4.1 does not properly verify uploaded images, which could allow remote attackers to upload and execute arbitrary PHP scripts, a different vulnerability than CVE-2005-0200.
- CVE-2004-1617MEDIUMCVSS v2 5.0EG 5.02004-10-18
Lynx, lynx-ssl, and lynx-cur before 2.8.6dev.8 allow remote attackers to cause a denial of service (infinite loop) via a web page or HTML email that contains invalid HTML including (1) a TEXTAREA tag with a large COLS value and (2) a large…
- CVE-2004-1675MEDIUMCVSS v2 5.0EG 5.02004-09-11
Serv-U FTP server 4.x and 5.x allows remote attackers to cause a denial of service (application crash) via a STORE UNIQUE (STOU) command with an MS-DOS device name argument such as (1) COM1, (2) LPT1, (3) PRN, or (4) AUX.
- CVE-2004-1777MEDIUMCVSS v2 5.0EG 5.02004-12-31
A "range check error" in Skype for Windows before 0.98.0.28 allows local and remote attackers to cause a denial of service (application crash) via long command line arguments or a long callto:// URL, a different vulnerability than CVE-2004…
- CVE-2004-1928HIGHCVSS v2 7.5EG 7.52004-04-12
The image upload feature in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to upload and possibly execute arbitrary files via the img/wiki_up URL.
- CVE-2004-2533MEDIUMCVSS v2 5.0EG 5.02004-12-31
Serv-U FTP Server 4.1 (possibly 4.0) allows remote attackers to cause a denial of service (application crash) via a SITE CHMOD command with a "\\...\" followed by a short string, causing partial memory corruption, a different vulnerability…
- CVE-2004-2592MEDIUMCVSS v2 5.0EG 5.02004-12-31
Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (application crash) via a modified client that asks the server to send data stored at a negative array offset, which is not han…
- CVE-2004-2596MEDIUMCVSS v2 5.0EG 5.02004-12-31
Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (exhaustion of connection slots) via a large number of connections from the same IP address.
- CVE-2004-2649MEDIUMCVSS v2 5.8EG 5.82004-12-31
Eudora 6.1.0.6 allows remote attackers to obfuscate URLs displayed in the status bar by inserting a large number of characters (e.g. spaces coded as " ") in the middle of the URL.
- CVE-2004-2706MEDIUMCVSS v2 5.0EG 5.02004-12-31
Unspecified vulnerability in Gyach Enhanced (Gyach-E) before 1.0.4 allows remote attackers to cause a denial of service (crash) via conference packets with error messages.
- CVE-2004-2771HIGHCVSS v2 7.5EG 7.52014-12-24
The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in an email address.
- CVE-2005-0050HIGHCVSS v2 10.0EG 10.02005-05-02
The License Logging service for Windows NT Server, Windows 2000 Server, and Windows Server 2003 does not properly validate the length of messages, which leads to an "unchecked buffer" and allows remote attackers to cause a denial of servic…
- CVE-2005-0116HIGHCVSS v2 7.5EG 7.52005-01-18
AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacters in the configdir parameter to aswtats.pl.
Map vulnerabilities like CWE-20 to your infrastructure
EchelonGraph correlates every CVE — across CWE-20 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →