CWE-20
Improper Input Validation
Description
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9
CVEs mapped to this weakness (13,352)
page 125 of 668| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-24274 | Hig | 0.51 | 7.8 | 0.00 | May 12, 2025 | An input validation issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. A malicious app may be able to gain root privileges. | ||
| CVE-2025-21460 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while processing a message, when the buffer is controlled by a Guest VM, the value can be changed continuously. | ||
| CVE-2024-49845 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption during the FRS UDS generation process. | ||
| CVE-2024-49844 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while triggering commands in the PlayReady Trusted application. | ||
| CVE-2024-45579 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption may occur when invoking IOCTL calls from userspace to the camera kernel driver to dump request information, due to a missing memory requirement check. | ||
| CVE-2024-45577 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2025 | Memory corruption while invoking IOCTL calls from userspace to camera kernel driver to dump request information. | ||
| CVE-2024-13943 | Hig | 0.51 | 7.8 | 0.00 | Apr 30, 2025 | Tesla Model S Iris Modem QCMAP_ConnectionManager Improper Input Validation Sandbox Escape Vulnerability. This vulnerability allows local attackers to escape the sandbox on affected affected Tesla Model S vehicles. An attacker must first obtain the ability to execute… | ||
| CVE-2023-42977 | Hig | 0.51 | 7.8 | 0.00 | Apr 11, 2025 | A path handling issue was addressed with improved validation. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to break out of its sandbox. | ||
| CVE-2025-2223 | Hig | 0.51 | 7.8 | 0.00 | Apr 9, 2025 | CWE-20: Improper Input Validation vulnerability exists that could cause a loss of Confidentiality, Integrity and Availability of engineering workstation when a malicious project file is loaded by a user from the local system. | ||
| CVE-2025-29811 | Hig | 0.51 | 7.8 | 0.01 | Apr 8, 2025 | Improper input validation in Windows Mobile Broadband allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-27731 | Hig | 0.51 | 7.8 | 0.01 | Apr 8, 2025 | Improper input validation in OpenSSH for Windows allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-27489 | Hig | 0.51 | 7.8 | 0.01 | Apr 8, 2025 | Improper input validation in Azure Local allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-24074 | Hig | 0.51 | 7.8 | 0.01 | Apr 8, 2025 | Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-24073 | Hig | 0.51 | 7.8 | 0.01 | Apr 8, 2025 | Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-24062 | Hig | 0.51 | 7.8 | 0.01 | Apr 8, 2025 | Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-24060 | Hig | 0.51 | 7.8 | 0.01 | Apr 8, 2025 | Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-24058 | Hig | 0.51 | 7.8 | 0.01 | Apr 8, 2025 | Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-1080 | Hig | 0.51 | 7.8 | 0.00 | Mar 4, 2025 | LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice a link in a browser using that scheme could… | ||
| CVE-2024-53031 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption while reading a type value from a buffer controlled by the Guest Virtual Machine. | ||
| CVE-2024-53030 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption while processing input message passed from FE driver. |
- risk 0.51cvss 7.8epss 0.00
An input validation issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. A malicious app may be able to gain root privileges.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing a message, when the buffer is controlled by a Guest VM, the value can be changed continuously.
- risk 0.51cvss 7.8epss 0.00
Memory corruption during the FRS UDS generation process.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while triggering commands in the PlayReady Trusted application.
- risk 0.51cvss 7.8epss 0.00
Memory corruption may occur when invoking IOCTL calls from userspace to the camera kernel driver to dump request information, due to a missing memory requirement check.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while invoking IOCTL calls from userspace to camera kernel driver to dump request information.
- risk 0.51cvss 7.8epss 0.00
Tesla Model S Iris Modem QCMAP_ConnectionManager Improper Input Validation Sandbox Escape Vulnerability. This vulnerability allows local attackers to escape the sandbox on affected affected Tesla Model S vehicles. An attacker must first obtain the ability to execute…
- risk 0.51cvss 7.8epss 0.00
A path handling issue was addressed with improved validation. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to break out of its sandbox.
- risk 0.51cvss 7.8epss 0.00
CWE-20: Improper Input Validation vulnerability exists that could cause a loss of Confidentiality, Integrity and Availability of engineering workstation when a malicious project file is loaded by a user from the local system.
- risk 0.51cvss 7.8epss 0.01
Improper input validation in Windows Mobile Broadband allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.01
Improper input validation in OpenSSH for Windows allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.01
Improper input validation in Azure Local allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.01
Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.01
Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.01
Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.01
Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.01
Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice a link in a browser using that scheme could…
- risk 0.51cvss 7.8epss 0.00
Memory corruption while reading a type value from a buffer controlled by the Guest Virtual Machine.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing input message passed from FE driver.