A vulnerability in the SNORT detection engine of Cisco Firepower System Software could allow an unauthenticated, remote
A vulnerability in the H.264 decoder function of Cisco Meeting Server could allow an unauthenticated, remote attacker to
A vulnerability in Session Initiation Protocol (SIP) call handling in Cisco IP Phone 8800 Series devices could allow an
Denial of Service was found in Horde_Image 2.x before 2.5.0 via a crafted URL to the "Null" image driver.
IBM InfoSphere Master Data Management Server 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 could allow a remote attacker to hij
An issue was discovered in Xen through 4.9.x allowing PV guest OS users to cause a denial of service (host OS crash) if
A local denial of service vulnerability exists in window broadcast message handling functionality of Kaspersky Anti-Viru
Installing a zero-permission Android application on certain Samsung Android devices with KK(4.4), L(5.0/5.1), and M(6.0)
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have a security by
The Samsung Exynos fimg2d driver for Android with Exynos 5433, 54xx, or 7420 chipsets allows local users to cause a deni
The gdImageCreate function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial
The process_file function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of servi
include/linux/init_task.h in the Linux kernel before 2.6.35 does not prevent signals with a process group ID of zero fro
Buffer overflow in the readgifimage function in gif2tiff.c in the gif2tiff tool in LibTIFF 4.0.6 allows remote attackers
Samsung devices with Android KK(4.4) or L(5.0/5.1) allow local users to cause a denial of service (IAndroidShm service c
IBM AIX 7.1 and 7.2 allows a local user to open a file with a specially crafted argument that would crash the system. IB
All versions of NVIDIA Linux GPU Display Driver contain a vulnerability in the kernel mode layer handler where improper
An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "ntfs" compo
An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "Graphics Driver"
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. The issue involves the "Contacts" comp
FastStone MaxView 3.0 and 3.1 allows user-assisted attackers to cause a denial of service (application crash) via a malf
Munin before 2.999.6 has a local file write vulnerability when CGI graphs are enabled. Setting multiple upper_limit GET
The DrawDashPolygon function in magick/render.c in GraphicsMagick before 1.3.24 and the SVG renderer in ImageMagick allo
The MagickRealloc function in memory.c in Graphicsmagick 1.3.25 allows remote attackers to cause a denial of service (cr
The MSL interpreter in ImageMagick before 6.9.6-4 allows remote attackers to cause a denial of service (segmentation fau
coders/mat.c in ImageMagick before 6.9.4-5 allows remote attackers to cause a denial of service (application crash) via
An issue was discovered in ImageMagick 6.9.7. Incorrect TGA files could trigger assertion failures, thus leading to DoS.
The mmap extension __MAP_NOFAULT in OpenBSD 5.8 and 5.9 allows attackers to cause a denial of service (kernel panic and
thrsleep in kern/kern_synch.c in OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (kernel panic) via
OpenBSD 5.8 and 5.9 allows certain local users to cause a denial of service (kernel panic) by unmounting a filesystem wi
A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a dev
A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a dev
A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a dev
A denial of service vulnerability in Audioserver could enable a local malicious application to cause a device hang or re
The add_probe function in modutils/modprobe.c in BusyBox before 1.23.0 allows local users to bypass intended restriction
The gdImageCreateFromGd2Ctx function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attac
Device Guard in Microsoft Windows 10 Gold, 1511, 1607, and Windows Server 2016 allows remote attackers to modify PowerSh
An issue was discovered in apng2gif 1.7. There is improper sanitization of user input causing huge memory allocations, r
WAVE.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via ve
The jas_seq2d_create function in jas_seq.c in JasPer before 1.900.14 allows remote attackers to cause a denial of servic
The jas_seq2d_create function in jas_seq.c in JasPer before 1.900.17 allows remote attackers to cause a denial of servic
The jas_seq2d_create function in jas_seq.c in JasPer before 1.900.25 allows remote attackers to cause a denial of servic
The ION driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230,
The vmw_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.10.5 does
The AMD Ryzen processor with AGESA microcode through 2017-01-27 allows local users to cause a denial of service (system
ImageMagick allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafte
ImageMagick allows remote attackers to cause a denial of service (file descriptor consumption) via a crafted file.
ImageMagick allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafte
ImageMagick allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafte
The dpx file handler in ImageMagick allows remote attackers to cause a denial of service (segmentation fault and applica
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started