VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,352)

page 113 of 668
  • CVE-2012-1168HigNov 14, 2019
    risk 0.53cvss 8.2epss 0.02

    Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified.

  • CVE-2013-2227HigNov 1, 2019
    risk 0.53cvss 7.5epss 0.13

    GLPI 0.83.7 has Local File Inclusion in common.tabs.php.

  • CVE-2013-4751HigNov 1, 2019
    risk 0.53cvss 8.1epss 0.01

    php-symfony2-Validator has loss of information during serialization

  • CVE-2016-10948HigSep 13, 2019
    risk 0.53cvss 8.1epss 0.02

    The Post Indexer plugin before 3.0.6.2 for WordPress has incorrect handling of data passed to the unserialize function.

  • CVE-2019-1936HigAug 21, 2019
    risk 0.53cvss 7.2epss 0.39

    A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an authenticated, remote attacker to execute arbitrary commands on the underlying Linux…

  • CVE-2016-10804HigAug 7, 2019
    risk 0.53cvss 8.1epss 0.01

    The SQLite journal feature in cPanel before 57.9999.54 allows arbitrary file-overwrite operations during Horde Restore (SEC-58).

  • CVE-2016-10787HigAug 6, 2019
    risk 0.53cvss 8.1epss 0.01

    The Host Access Control feature in cPanel before 60.0.25 mishandles actionless host.deny entries (SEC-187).

  • CVE-2016-10771HigAug 5, 2019
    risk 0.53cvss 8.1epss 0.01

    cPanel before 60.0.25 allows file-create and file-chmod operations during ModSecurity Audit logfile processing (SEC-165).

  • CVE-2018-10899HigAug 1, 2019
    risk 0.53cvss 8.1epss 0.03

    A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. This holds true for properly configured instances with strict checking for origin and referrer headers. This could result in a Remote Code Execution attack.

  • CVE-2018-6138HigJun 27, 2019
    risk 0.53cvss 8.1epss 0.01

    Insufficient policy enforcement in Extensions API in Google Chrome prior to 67.0.3396.62 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.

  • CVE-2017-6261HigJun 5, 2019
    risk 0.53cvss 8.2epss 0.00

    NVIDIA Vibrante Linux version 1.1, 2.0, and 2.2 contains a vulnerability in the user space driver in which protection mechanisms are insufficient, may lead to denial of service or information disclosure.

  • CVE-2019-0163HigApr 17, 2019
    risk 0.53cvss 8.2epss 0.00

    Insufficient input validation in system firmware for Intel(R) Broadwell U i5 vPro before version MYBDWi5v.86A may allow an authenticated user to potentially enable escalation of privilege, denial of service, and/or information disclosure via local access.

  • CVE-2018-12216HigMar 14, 2019
    risk 0.53cvss 8.2epss 0.00

    Insufficient input validation in Kernel Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373 potentially enables a…

  • CVE-2019-0255HigFeb 15, 2019
    risk 0.53cvss 8.1epss 0.02

    SAP NetWeaver AS ABAP Platform, Krnl64nuc 7.74, krnl64UC 7.73, 7.74, Kernel 7.73, 7.74, 7.75, fails to validate type of installation for an ABAP Server system correctly. That behavior may lead to situation, where business user achieves access to the full SAP Menu, that is 'Easy…

  • CVE-2018-20519HigDec 27, 2018
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in 74cms v4.2.111. It allows remote authenticated users to read or modify arbitrary resumes by changing a job-search intention, as demonstrated by the index.php?c=Personal&a=ajax_save_basic pid parameter.

  • CVE-2018-16874HigDec 14, 2018
    risk 0.53cvss 8.1epss 0.05

    In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to directory traversal when executed with the import path of a malicious Go package which contains curly braces (both '{' and '}' characters). Specifically, it is only vulnerable in GOPATH mode, but…

  • CVE-2018-16528HigDec 6, 2018
    risk 0.53cvss 8.1epss 0.03

    Amazon Web Services (AWS) FreeRTOS through 1.3.1 allows remote attackers to execute arbitrary code because of mbedTLS context object corruption in prvSetupConnection and GGD_SecureConnect_Connect in AWS TLS connectivity modules.

  • CVE-2018-12176HigSep 12, 2018
    risk 0.53cvss 8.2epss 0.00

    Improper input validation in firmware for Intel NUC Kits may allow a privileged user to potentially execute arbitrary code resulting in information disclosure, escalation of privilege and/or denial of service via local access.

  • CVE-2018-10927HigSep 4, 2018
    risk 0.53cvss 8.1epss 0.03

    A flaw was found in RPC request using gfs3_lookup_req in glusterfs server. An authenticated attacker could use this flaw to leak information and execute remote denial of service by crashing gluster brick process.

  • CVE-2018-10923HigSep 4, 2018
    risk 0.53cvss 8.1epss 0.02

    It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node. An authenticated attacker could use this to create an arbitrary device and read data from any device attached to the glusterfs server node.