VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,352)

page 127 of 668
  • CVE-2024-7977HigAug 21, 2024
    risk 0.51cvss 7.8epss 0.00

    Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Medium)

  • CVE-2024-33657HigAug 21, 2024
    risk 0.51cvss 7.8epss 0.00

    This SMM vulnerability affects certain modules, allowing privileged attackers to execute arbitrary code, manipulate stack memory, and leak information from SMRAM to kernel space, potentially leading to denial-of-service attacks.

  • CVE-2024-41856HigAug 14, 2024
    risk 0.51cvss 7.8epss 0.00

    Illustrator versions 28.5, 27.9.4, 28.6, 27.9.5 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must…

  • CVE-2024-38196HigAug 13, 2024
    risk 0.51cvss 7.8epss 0.06

    Windows Common Log File System Driver Elevation of Privilege Vulnerability

  • CVE-2023-1577HigJul 31, 2024
    risk 0.51cvss 7.8epss 0.00

    A path hijacking vulnerability was reported in Lenovo Driver Manager prior to version 3.1.1307.1308 that could allow a local user to execute code with elevated privileges.

  • CVE-2024-7340HigJul 31, 2024
    risk 0.51cvss 8.8epss 0.05

    The Weave server API allows remote users to fetch files from a specific directory, but due to a lack of input validation, it is possible to traverse and leak arbitrary files remotely. In various common scenarios, this allows a low-privileged user to assume the role of the server…

  • CVE-2024-5681HigJul 11, 2024
    risk 0.51cvss 7.8epss 0.00

    CWE-20: Improper Input Validation vulnerability exists that could cause local denial-of-service, privilege escalation, and potentially kernel execution when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver.

  • CVE-2024-31310HigJul 9, 2024
    risk 0.51cvss 7.8epss 0.00

    In newServiceInfoLocked of AutofillManagerServiceImpl.java, there is a possible way to hide an enabled Autofill service app in the Autofill service settings due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges…

  • CVE-2024-38052HigJul 9, 2024
    risk 0.51cvss 7.8epss 0.07

    Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability

  • CVE-2024-38047HigJul 9, 2024
    risk 0.51cvss 7.8epss 0.01

    PowerShell Elevation of Privilege Vulnerability

  • CVE-2024-38043HigJul 9, 2024
    risk 0.51cvss 7.8epss 0.01

    PowerShell Elevation of Privilege Vulnerability

  • CVE-2024-32907HigJun 13, 2024
    risk 0.51cvss 7.8epss 0.00

    In memcall_add of memlog.c, there is a possible buffer overflow due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-32903HigJun 13, 2024
    risk 0.51cvss 7.8epss 0.00

    In prepare_response_locked of lwis_transaction.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-30087HigJun 11, 2024
    risk 0.51cvss 7.8epss 0.10

    Win32k Elevation of Privilege Vulnerability

  • CVE-2022-1242HigJun 3, 2024
    risk 0.51cvss 7.8epss 0.00

    Apport can be tricked into connecting to arbitrary sockets as the root user

  • CVE-2023-45745HigMay 16, 2024
    risk 0.51cvss 7.9epss 0.00

    Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2024-3968HigMay 15, 2024
    risk 0.51cvss 7.8epss 0.01

    Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger remote code execution using custom file upload task.

  • CVE-2024-34098HigMay 15, 2024
    risk 0.51cvss 7.8epss 0.00

    Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must…

  • CVE-2024-23707HigMay 7, 2024
    risk 0.51cvss 7.8epss 0.00

    In multiple locations, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2024-23706HigMay 7, 2024
    risk 0.51cvss 7.8epss 0.00

    In multiple locations, there is a possible bypass of health data permissions due to an improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.