VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,352)

page 128 of 668
  • CVE-2024-23705HigMay 7, 2024
    risk 0.51cvss 7.8epss 0.00

    In multiple locations, there is a possible failure to persist or enforce user restrictions due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2024-21476HigMay 6, 2024
    risk 0.51cvss 7.8epss 0.00

    Memory corruption when the channel ID passed by user is not validated and further used.

  • CVE-2024-20064HigMay 6, 2024
    risk 0.51cvss 7.8epss 0.00

    In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08572601; Issue ID: MSV-1229.

  • CVE-2024-26173HigMar 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2024-26170HigMar 12, 2024
    risk 0.51cvss 7.8epss 0.07

    Windows Composite Image File System (CimFS) Elevation of Privilege Vulnerability

  • CVE-2024-26002HigMar 12, 2024
    risk 0.51cvss 7.8epss 0.00

    An improper input validation in the Qualcom plctool allows a local attacker with low privileges to gain root access by changing the ownership of specific files.

  • CVE-2024-23294HigMar 8, 2024
    risk 0.51cvss 7.8epss 0.00

    This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.4. Processing malicious input may lead to code execution.

  • CVE-2024-0021HigFeb 16, 2024
    risk 0.51cvss 7.8epss 0.00

    In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way for an app in the work profile to enable notification listener services due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges…

  • CVE-2024-21315HigFeb 13, 2024
    risk 0.51cvss 7.8epss 0.01

    Microsoft Defender for Endpoint Protection Elevation of Privilege Vulnerability

  • CVE-2023-42826HigJan 10, 2024
    risk 0.51cvss 7.8epss 0.00

    The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing a file may lead to arbitrary code execution.

  • CVE-2023-48634HigDec 13, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe After Effects versions 24.0.3 (and earlier) and 23.6.0 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a…

  • CVE-2023-5058HigDec 7, 2023
    risk 0.51cvss 7.8epss 0.00

    Improper Input Validation in the processing of user-supplied splash screen during system boot in Phoenix SecureCore™ Technology™ 4 potentially allows denial-of-service attacks or arbitrary code execution.

  • CVE-2023-40097HigDec 4, 2023
    risk 0.51cvss 7.8epss 0.00

    In hasPermissionForActivity of PackageManagerHelper.java, there is a possible URI grant due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2023-36719HigNov 14, 2023
    risk 0.51cvss 7.8epss 0.01

    Microsoft Speech Application Programming Interface (SAPI) Elevation of Privilege Vulnerability

  • CVE-2023-36407HigNov 14, 2023
    risk 0.51cvss 7.8epss 0.02

    Windows Hyper-V Elevation of Privilege Vulnerability

  • CVE-2023-3676HigOct 31, 2023
    risk 0.51cvss 8.8epss 0.13

    A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes.

  • CVE-2023-36731HigOct 10, 2023
    risk 0.51cvss 7.8epss 0.08

    Win32k Elevation of Privilege Vulnerability

  • CVE-2023-2914HigAug 17, 2023
    risk 0.51cvss 7.5epss 0.40

    The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, an integer overflow condition exists in the affected products. When the ThinManager processes incoming messages, a read access violation occurs and terminates the process. A…

  • CVE-2023-21272HigAug 14, 2023
    risk 0.51cvss 7.8epss 0.00

    In readFrom of Uri.java, there is a possible bad URI permission grant due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-26587HigAug 11, 2023
    risk 0.51cvss 7.8epss 0.00

    Improper input validation for the Intel(R) Easy Streaming Wizard software may allow an authenticated user to potentially enable escalation of privilege via local access.