VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,352)

page 125 of 668
  • CVE-2025-24274HigMay 12, 2025
    risk 0.51cvss 7.8epss 0.00

    An input validation issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. A malicious app may be able to gain root privileges.

  • CVE-2025-21460HigMay 6, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while processing a message, when the buffer is controlled by a Guest VM, the value can be changed continuously.

  • CVE-2024-49845HigMay 6, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption during the FRS UDS generation process.

  • CVE-2024-49844HigMay 6, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while triggering commands in the PlayReady Trusted application.

  • CVE-2024-45579HigMay 6, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption may occur when invoking IOCTL calls from userspace to the camera kernel driver to dump request information, due to a missing memory requirement check.

  • CVE-2024-45577HigMay 6, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while invoking IOCTL calls from userspace to camera kernel driver to dump request information.

  • CVE-2024-13943HigApr 30, 2025
    risk 0.51cvss 7.8epss 0.00

    Tesla Model S Iris Modem QCMAP_ConnectionManager Improper Input Validation Sandbox Escape Vulnerability. This vulnerability allows local attackers to escape the sandbox on affected affected Tesla Model S vehicles. An attacker must first obtain the ability to execute…

  • CVE-2023-42977HigApr 11, 2025
    risk 0.51cvss 7.8epss 0.00

    A path handling issue was addressed with improved validation. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to break out of its sandbox.

  • CVE-2025-2223HigApr 9, 2025
    risk 0.51cvss 7.8epss 0.00

    CWE-20: Improper Input Validation vulnerability exists that could cause a loss of Confidentiality, Integrity and Availability of engineering workstation when a malicious project file is loaded by a user from the local system.

  • CVE-2025-29811HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper input validation in Windows Mobile Broadband allows an authorized attacker to elevate privileges locally.

  • CVE-2025-27731HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper input validation in OpenSSH for Windows allows an authorized attacker to elevate privileges locally.

  • CVE-2025-27489HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper input validation in Azure Local allows an authorized attacker to elevate privileges locally.

  • CVE-2025-24074HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

  • CVE-2025-24073HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

  • CVE-2025-24062HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

  • CVE-2025-24060HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

  • CVE-2025-24058HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

  • CVE-2025-1080HigMar 4, 2025
    risk 0.51cvss 7.8epss 0.00

    LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice a link in a browser using that scheme could…

  • CVE-2024-53031HigMar 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while reading a type value from a buffer controlled by the Guest Virtual Machine.

  • CVE-2024-53030HigMar 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while processing input message passed from FE driver.