CWE-20
Improper Input Validation
Description
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9
CVEs mapped to this weakness (13,352)
page 126 of 668| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-53029 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption while reading a value from a buffer controlled by the Guest Virtual Machine. | ||
| CVE-2024-53022 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption may occur during communication between primary and guest VM. | ||
| CVE-2024-53012 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption may occur due to improper input validation in clock device. | ||
| CVE-2025-0514 | Hig | 0.51 | 7.8 | 0.00 | Feb 25, 2025 | Improper Input Validation vulnerability in The Document Foundation LibreOffice allows Windows Executable hyperlink targets to be executed unconditionally on activation.This issue affects LibreOffice: from 24.8 before < 24.8.5. | ||
| CVE-2025-21375 | Hig | 0.51 | 7.8 | 0.01 | Feb 11, 2025 | Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | ||
| CVE-2025-21370 | Hig | 0.51 | 7.8 | 0.00 | Jan 14, 2025 | Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability | ||
| CVE-2025-21344 | Hig | 0.51 | 7.8 | 0.01 | Jan 14, 2025 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2025-21235 | Hig | 0.51 | 7.8 | 0.01 | Jan 14, 2025 | Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | ||
| CVE-2025-21234 | Hig | 0.51 | 7.8 | 0.01 | Jan 14, 2025 | Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | ||
| CVE-2024-52982 | Hig | 0.51 | 7.8 | 0.00 | Dec 10, 2024 | Animate versions 23.0.8, 24.0.5 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious… | ||
| CVE-2024-43052 | Hig | 0.51 | 7.8 | 0.00 | Dec 2, 2024 | Memory corruption while processing API calls to NPU with invalid input. | ||
| CVE-2024-0127 | Hig | 0.51 | 7.8 | 0.00 | Oct 26, 2024 | NVIDIA vGPU software contains a vulnerability in the GPU kernel driver of the vGPU Manager for all supported hypervisors, where a user of the guest OS can cause an improper input validation by compromising the guest OS kernel. A successful exploit of this vulnerability might… | ||
| CVE-2024-38261 | Hig | 0.51 | 7.8 | 0.01 | Oct 8, 2024 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | ||
| CVE-2024-44094 | Hig | 0.51 | 7.8 | 0.00 | Sep 13, 2024 | In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2024-38245 | Hig | 0.51 | 7.8 | 0.01 | Sep 10, 2024 | Kernel Streaming Service Driver Elevation of Privilege Vulnerability | ||
| CVE-2024-38244 | Hig | 0.51 | 7.8 | 0.06 | Sep 10, 2024 | Kernel Streaming Service Driver Elevation of Privilege Vulnerability | ||
| CVE-2024-38243 | Hig | 0.51 | 7.8 | 0.01 | Sep 10, 2024 | Kernel Streaming Service Driver Elevation of Privilege Vulnerability | ||
| CVE-2024-38241 | Hig | 0.51 | 7.8 | 0.06 | Sep 10, 2024 | Kernel Streaming Service Driver Elevation of Privilege Vulnerability | ||
| CVE-2024-38046 | Hig | 0.51 | 7.8 | 0.01 | Sep 10, 2024 | PowerShell Elevation of Privilege Vulnerability | ||
| CVE-2024-7980 | Hig | 0.51 | 7.8 | 0.00 | Aug 21, 2024 | Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation via a crafted symbolic link. (Chromium security severity: Medium) |
- risk 0.51cvss 7.8epss 0.00
Memory corruption while reading a value from a buffer controlled by the Guest Virtual Machine.
- risk 0.51cvss 7.8epss 0.00
Memory corruption may occur during communication between primary and guest VM.
- risk 0.51cvss 7.8epss 0.00
Memory corruption may occur due to improper input validation in clock device.
- risk 0.51cvss 7.8epss 0.00
Improper Input Validation vulnerability in The Document Foundation LibreOffice allows Windows Executable hyperlink targets to be executed unconditionally on activation.This issue affects LibreOffice: from 24.8 before < 24.8.5.
- risk 0.51cvss 7.8epss 0.01
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Animate versions 23.0.8, 24.0.5 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing API calls to NPU with invalid input.
- risk 0.51cvss 7.8epss 0.00
NVIDIA vGPU software contains a vulnerability in the GPU kernel driver of the vGPU Manager for all supported hypervisors, where a user of the guest OS can cause an improper input validation by compromising the guest OS kernel. A successful exploit of this vulnerability might…
- risk 0.51cvss 7.8epss 0.01
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.00
In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.51cvss 7.8epss 0.01
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.06
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.06
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
PowerShell Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation via a crafted symbolic link. (Chromium security severity: Medium)