CWE-20
Improper Input Validation
Description
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9
CVEs mapped to this weakness (13,352)
page 129 of 668| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-37336 | Hig | 0.51 | 7.9 | 0.00 | Aug 11, 2023 | Improper input validation in BIOS firmware for some Intel(R) NUC may allow a privileged user to potentially enable escalation of privilege via local access. | ||
| CVE-2023-21192 | Hig | 0.51 | 7.8 | 0.00 | Jun 28, 2023 | In setInputMethodWithSubtypeIdLocked of InputMethodManagerService.java, there is a possible way to setup input methods that are not enabled due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User… | ||
| CVE-2023-21138 | Hig | 0.51 | 7.8 | 0.00 | Jun 15, 2023 | In onNullBinding of CallRedirectionProcessor.java, there is a possible long lived connection due to improper input validation. This could lead to local escalation of privilege and background activity launches with User execution privileges needed. User interaction is not needed… | ||
| CVE-2023-21135 | Hig | 0.51 | 7.8 | 0.00 | Jun 15, 2023 | In onCreate of NotificationAccessSettings.java, there is a possible failure to persist notifications settings due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2023-21121 | Hig | 0.51 | 7.8 | 0.00 | Jun 15, 2023 | In onResume of AppManagementFragment.java, there is a possible way to prevent users from forgetting a previously connected VPN due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is… | ||
| CVE-2023-34448 | Hig | 0.51 | 8.8 | 0.05 | Jun 14, 2023 | Grav is a flat-file content management system. Prior to version 1.7.42, the patch for CVE-2022-2073, a server-side template injection vulnerability in Grav leveraging the default `filter()` function, did not block other built-in functions exposed by Twig's Core Extension that… | ||
| CVE-2023-29371 | Hig | 0.51 | 7.8 | 0.05 | Jun 14, 2023 | Windows GDI Elevation of Privilege Vulnerability | ||
| CVE-2023-29359 | Hig | 0.51 | 7.8 | 0.01 | Jun 14, 2023 | GDI Elevation of Privilege Vulnerability | ||
| CVE-2023-21657 | Hig | 0.51 | 7.8 | 0.00 | Jun 6, 2023 | Memoru corruption in Audio when ADSP sends input during record use case. | ||
| CVE-2023-21656 | Hig | 0.51 | 7.8 | 0.00 | Jun 6, 2023 | Memory corruption in WLAN HOST while receiving an WMI event from firmware. | ||
| CVE-2023-21092 | Hig | 0.51 | 7.8 | 0.00 | Apr 19, 2023 | In retrieveServiceLocked of ActiveServices.java, there is a possible way to dynamically register a BroadcastReceiver using permissions of System App due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed.… | ||
| CVE-2023-26388 | Hig | 0.51 | 7.8 | 0.00 | Apr 12, 2023 | Adobe Substance 3D Stager version 2.0.1 (and earlier) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a… | ||
| CVE-2023-26407 | Hig | 0.51 | 7.8 | 0.04 | Apr 12, 2023 | Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user… | ||
| CVE-2023-26405 | Hig | 0.51 | 7.8 | 0.04 | Apr 12, 2023 | Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user… | ||
| CVE-2023-28304 | Hig | 0.51 | 7.8 | 0.01 | Apr 11, 2023 | Microsoft ODBC and OLE DB Remote Code Execution Vulnerability | ||
| CVE-2023-28274 | Hig | 0.51 | 7.8 | 0.07 | Apr 11, 2023 | Windows Win32k Elevation of Privilege Vulnerability | ||
| CVE-2023-24893 | Hig | 0.51 | 7.8 | 0.01 | Apr 11, 2023 | Visual Studio Code Remote Code Execution Vulnerability | ||
| CVE-2023-23375 | Hig | 0.51 | 7.8 | 0.01 | Apr 11, 2023 | Microsoft ODBC and OLE DB Remote Code Execution Vulnerability | ||
| CVE-2023-24304 | Hig | 0.51 | 7.8 | 0.00 | Mar 28, 2023 | Improper input validation in the PDF.dll plugin of IrfanView v4.60 allows attackers to execute arbitrary code via opening a crafted PDF file. | ||
| CVE-2023-25901 | Hig | 0.51 | 7.8 | 0.00 | Mar 28, 2023 | Adobe Dimension versions 3.4.7 (and earlier) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious… |
- risk 0.51cvss 7.9epss 0.00
Improper input validation in BIOS firmware for some Intel(R) NUC may allow a privileged user to potentially enable escalation of privilege via local access.
- risk 0.51cvss 7.8epss 0.00
In setInputMethodWithSubtypeIdLocked of InputMethodManagerService.java, there is a possible way to setup input methods that are not enabled due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User…
- risk 0.51cvss 7.8epss 0.00
In onNullBinding of CallRedirectionProcessor.java, there is a possible long lived connection due to improper input validation. This could lead to local escalation of privilege and background activity launches with User execution privileges needed. User interaction is not needed…
- risk 0.51cvss 7.8epss 0.00
In onCreate of NotificationAccessSettings.java, there is a possible failure to persist notifications settings due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…
- risk 0.51cvss 7.8epss 0.00
In onResume of AppManagementFragment.java, there is a possible way to prevent users from forgetting a previously connected VPN due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is…
- risk 0.51cvss 8.8epss 0.05
Grav is a flat-file content management system. Prior to version 1.7.42, the patch for CVE-2022-2073, a server-side template injection vulnerability in Grav leveraging the default `filter()` function, did not block other built-in functions exposed by Twig's Core Extension that…
- risk 0.51cvss 7.8epss 0.05
Windows GDI Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
GDI Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Memoru corruption in Audio when ADSP sends input during record use case.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN HOST while receiving an WMI event from firmware.
- risk 0.51cvss 7.8epss 0.00
In retrieveServiceLocked of ActiveServices.java, there is a possible way to dynamically register a BroadcastReceiver using permissions of System App due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed.…
- risk 0.51cvss 7.8epss 0.00
Adobe Substance 3D Stager version 2.0.1 (and earlier) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…
- risk 0.51cvss 7.8epss 0.04
Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user…
- risk 0.51cvss 7.8epss 0.04
Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user…
- risk 0.51cvss 7.8epss 0.01
Microsoft ODBC and OLE DB Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.07
Windows Win32k Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Visual Studio Code Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft ODBC and OLE DB Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.00
Improper input validation in the PDF.dll plugin of IrfanView v4.60 allows attackers to execute arbitrary code via opening a crafted PDF file.
- risk 0.51cvss 7.8epss 0.00
Adobe Dimension versions 3.4.7 (and earlier) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…