CWE-20
Improper Input Validation
Description
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9
CVEs mapped to this weakness (13,352)
page 128 of 668| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-23705 | Hig | 0.51 | 7.8 | 0.00 | May 7, 2024 | In multiple locations, there is a possible failure to persist or enforce user restrictions due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. | ||
| CVE-2024-21476 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2024 | Memory corruption when the channel ID passed by user is not validated and further used. | ||
| CVE-2024-20064 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2024 | In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08572601; Issue ID: MSV-1229. | ||
| CVE-2024-26173 | Hig | 0.51 | 7.8 | 0.01 | Mar 12, 2024 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2024-26170 | Hig | 0.51 | 7.8 | 0.07 | Mar 12, 2024 | Windows Composite Image File System (CimFS) Elevation of Privilege Vulnerability | ||
| CVE-2024-26002 | Hig | 0.51 | 7.8 | 0.00 | Mar 12, 2024 | An improper input validation in the Qualcom plctool allows a local attacker with low privileges to gain root access by changing the ownership of specific files. | ||
| CVE-2024-23294 | Hig | 0.51 | 7.8 | 0.00 | Mar 8, 2024 | This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.4. Processing malicious input may lead to code execution. | ||
| CVE-2024-0021 | Hig | 0.51 | 7.8 | 0.00 | Feb 16, 2024 | In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way for an app in the work profile to enable notification listener services due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges… | ||
| CVE-2024-21315 | Hig | 0.51 | 7.8 | 0.01 | Feb 13, 2024 | Microsoft Defender for Endpoint Protection Elevation of Privilege Vulnerability | ||
| CVE-2023-42826 | Hig | 0.51 | 7.8 | 0.00 | Jan 10, 2024 | The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing a file may lead to arbitrary code execution. | ||
| CVE-2023-48634 | Hig | 0.51 | 7.8 | 0.00 | Dec 13, 2023 | Adobe After Effects versions 24.0.3 (and earlier) and 23.6.0 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a… | ||
| CVE-2023-5058 | Hig | 0.51 | 7.8 | 0.00 | Dec 7, 2023 | Improper Input Validation in the processing of user-supplied splash screen during system boot in Phoenix SecureCore™ Technology™ 4 potentially allows denial-of-service attacks or arbitrary code execution. | ||
| CVE-2023-40097 | Hig | 0.51 | 7.8 | 0.00 | Dec 4, 2023 | In hasPermissionForActivity of PackageManagerHelper.java, there is a possible URI grant due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. | ||
| CVE-2023-36719 | Hig | 0.51 | 7.8 | 0.01 | Nov 14, 2023 | Microsoft Speech Application Programming Interface (SAPI) Elevation of Privilege Vulnerability | ||
| CVE-2023-36407 | Hig | 0.51 | 7.8 | 0.02 | Nov 14, 2023 | Windows Hyper-V Elevation of Privilege Vulnerability | ||
| CVE-2023-3676 | Hig | 0.51 | 8.8 | 0.13 | Oct 31, 2023 | A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. | ||
| CVE-2023-36731 | Hig | 0.51 | 7.8 | 0.08 | Oct 10, 2023 | Win32k Elevation of Privilege Vulnerability | ||
| CVE-2023-2914 | Hig | 0.51 | 7.5 | 0.40 | Aug 17, 2023 | The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, an integer overflow condition exists in the affected products. When the ThinManager processes incoming messages, a read access violation occurs and terminates the process. A… | ||
| CVE-2023-21272 | Hig | 0.51 | 7.8 | 0.00 | Aug 14, 2023 | In readFrom of Uri.java, there is a possible bad URI permission grant due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-26587 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2023 | Improper input validation for the Intel(R) Easy Streaming Wizard software may allow an authenticated user to potentially enable escalation of privilege via local access. |
- risk 0.51cvss 7.8epss 0.00
In multiple locations, there is a possible failure to persist or enforce user restrictions due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
- risk 0.51cvss 7.8epss 0.00
Memory corruption when the channel ID passed by user is not validated and further used.
- risk 0.51cvss 7.8epss 0.00
In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08572601; Issue ID: MSV-1229.
- risk 0.51cvss 7.8epss 0.01
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.07
Windows Composite Image File System (CimFS) Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
An improper input validation in the Qualcom plctool allows a local attacker with low privileges to gain root access by changing the ownership of specific files.
- risk 0.51cvss 7.8epss 0.00
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.4. Processing malicious input may lead to code execution.
- risk 0.51cvss 7.8epss 0.00
In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way for an app in the work profile to enable notification listener services due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges…
- risk 0.51cvss 7.8epss 0.01
Microsoft Defender for Endpoint Protection Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing a file may lead to arbitrary code execution.
- risk 0.51cvss 7.8epss 0.00
Adobe After Effects versions 24.0.3 (and earlier) and 23.6.0 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a…
- risk 0.51cvss 7.8epss 0.00
Improper Input Validation in the processing of user-supplied splash screen during system boot in Phoenix SecureCore™ Technology™ 4 potentially allows denial-of-service attacks or arbitrary code execution.
- risk 0.51cvss 7.8epss 0.00
In hasPermissionForActivity of PackageManagerHelper.java, there is a possible URI grant due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
- risk 0.51cvss 7.8epss 0.01
Microsoft Speech Application Programming Interface (SAPI) Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.02
Windows Hyper-V Elevation of Privilege Vulnerability
- risk 0.51cvss 8.8epss 0.13
A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes.
- risk 0.51cvss 7.8epss 0.08
Win32k Elevation of Privilege Vulnerability
- risk 0.51cvss 7.5epss 0.40
The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, an integer overflow condition exists in the affected products. When the ThinManager processes incoming messages, a read access violation occurs and terminates the process. A…
- risk 0.51cvss 7.8epss 0.00
In readFrom of Uri.java, there is a possible bad URI permission grant due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.51cvss 7.8epss 0.00
Improper input validation for the Intel(R) Easy Streaming Wizard software may allow an authenticated user to potentially enable escalation of privilege via local access.