VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,352)

page 129 of 668
  • CVE-2022-37336HigAug 11, 2023
    risk 0.51cvss 7.9epss 0.00

    Improper input validation in BIOS firmware for some Intel(R) NUC may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2023-21192HigJun 28, 2023
    risk 0.51cvss 7.8epss 0.00

    In setInputMethodWithSubtypeIdLocked of InputMethodManagerService.java, there is a possible way to setup input methods that are not enabled due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User…

  • CVE-2023-21138HigJun 15, 2023
    risk 0.51cvss 7.8epss 0.00

    In onNullBinding of CallRedirectionProcessor.java, there is a possible long lived connection due to improper input validation. This could lead to local escalation of privilege and background activity launches with User execution privileges needed. User interaction is not needed…

  • CVE-2023-21135HigJun 15, 2023
    risk 0.51cvss 7.8epss 0.00

    In onCreate of NotificationAccessSettings.java, there is a possible failure to persist notifications settings due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2023-21121HigJun 15, 2023
    risk 0.51cvss 7.8epss 0.00

    In onResume of AppManagementFragment.java, there is a possible way to prevent users from forgetting a previously connected VPN due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is…

  • CVE-2023-34448HigJun 14, 2023
    risk 0.51cvss 8.8epss 0.05

    Grav is a flat-file content management system. Prior to version 1.7.42, the patch for CVE-2022-2073, a server-side template injection vulnerability in Grav leveraging the default `filter()` function, did not block other built-in functions exposed by Twig's Core Extension that…

  • CVE-2023-29371HigJun 14, 2023
    risk 0.51cvss 7.8epss 0.05

    Windows GDI Elevation of Privilege Vulnerability

  • CVE-2023-29359HigJun 14, 2023
    risk 0.51cvss 7.8epss 0.01

    GDI Elevation of Privilege Vulnerability

  • CVE-2023-21657HigJun 6, 2023
    risk 0.51cvss 7.8epss 0.00

    Memoru corruption in Audio when ADSP sends input during record use case.

  • CVE-2023-21656HigJun 6, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in WLAN HOST while receiving an WMI event from firmware.

  • CVE-2023-21092HigApr 19, 2023
    risk 0.51cvss 7.8epss 0.00

    In retrieveServiceLocked of ActiveServices.java, there is a possible way to dynamically register a BroadcastReceiver using permissions of System App due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed.…

  • CVE-2023-26388HigApr 12, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Substance 3D Stager version 2.0.1 (and earlier) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2023-26407HigApr 12, 2023
    risk 0.51cvss 7.8epss 0.04

    Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user…

  • CVE-2023-26405HigApr 12, 2023
    risk 0.51cvss 7.8epss 0.04

    Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user…

  • CVE-2023-28304HigApr 11, 2023
    risk 0.51cvss 7.8epss 0.01

    Microsoft ODBC and OLE DB Remote Code Execution Vulnerability

  • CVE-2023-28274HigApr 11, 2023
    risk 0.51cvss 7.8epss 0.07

    Windows Win32k Elevation of Privilege Vulnerability

  • CVE-2023-24893HigApr 11, 2023
    risk 0.51cvss 7.8epss 0.01

    Visual Studio Code Remote Code Execution Vulnerability

  • CVE-2023-23375HigApr 11, 2023
    risk 0.51cvss 7.8epss 0.01

    Microsoft ODBC and OLE DB Remote Code Execution Vulnerability

  • CVE-2023-24304HigMar 28, 2023
    risk 0.51cvss 7.8epss 0.00

    Improper input validation in the PDF.dll plugin of IrfanView v4.60 allows attackers to execute arbitrary code via opening a crafted PDF file.

  • CVE-2023-25901HigMar 28, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Dimension versions 3.4.7 (and earlier) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…