VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,545)

page 16 of 678
  • CVE-2023-45163CriNov 6, 2023
    risk 0.64cvss 9.9epss 0.01

    The 1E-Exchange-CommandLinePing instruction that is part of the Network product pack available on the 1E Exchange does not properly validate the input parameter, which allows for a specially crafted input to perform arbitrary code execution with SYSTEM permissions. This…

  • CVE-2023-45161CriNov 6, 2023
    risk 0.64cvss 9.9epss 0.01

    The 1E-Exchange-URLResponseTime instruction that is part of the Network product pack available on the 1E Exchange does not properly validate the URL parameter, which allows for a specially crafted input to perform arbitrary code execution with SYSTEM permissions. This…

  • CVE-2023-41355CriNov 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Chunghwa Telecom NOKIA G-040W-Q Firewall function has a vulnerability of input validation for ICMP redirect messages. An unauthenticated remote attacker can exploit this vulnerability by sending a crafted package to modify the network routing table, resulting in a denial of…

  • CVE-2023-35349CriOct 10, 2023
    risk 0.64cvss 9.8epss 0.03

    Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

  • CVE-2023-32485CriOct 5, 2023
    risk 0.64cvss 9.8epss 0.01

    Dell SmartFabric Storage Software version 1.3 and lower contain an improper input validation vulnerability. A remote unauthenticated attacker may exploit this vulnerability and escalate privileges up to the highest administration level. This is a critical severity vulnerability…

  • CVE-2023-36619CriOct 4, 2023
    risk 0.64cvss 9.8epss 0.04

    Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of administrative scripts by unauthenticated users.

  • CVE-2022-48605CriSep 25, 2023
    risk 0.64cvss 9.8epss 0.00

    Input verification vulnerability in the fingerprint module. Successful exploitation of this vulnerability will affect confidentiality, integrity, and availability.

  • CVE-2023-41748CriAug 31, 2023
    risk 0.64cvss 9.8epss 0.01

    Remote command execution due to improper input validation. The following products are affected: Acronis Cloud Manager (Windows) before build 6.2.23089.203.

  • CVE-2023-41746CriAug 31, 2023
    risk 0.64cvss 9.8epss 0.01

    Remote command execution due to improper input validation. The following products are affected: Acronis Cloud Manager (Windows) before build 6.2.23089.203.

  • CVE-2023-25915CriAug 21, 2023
    risk 0.64cvss 9.9epss 0.01

    Due to improper input validation, an authenticated remote attacker could execute arbitrary commands on the target system.

  • CVE-2023-39405CriAug 13, 2023
    risk 0.64cvss 9.8epss 0.00

    Vulnerability of out-of-bounds parameter read/write in the Wi-Fi module. Successful exploitation of this vulnerability may cause other apps to be executed with escalated privileges.

  • CVE-2023-35367CriJul 11, 2023
    risk 0.64cvss 9.8epss 0.02

    Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

  • CVE-2023-35366CriJul 11, 2023
    risk 0.64cvss 9.8epss 0.02

    Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

  • CVE-2023-35365CriJul 11, 2023
    risk 0.64cvss 9.8epss 0.02

    Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

  • CVE-2023-32057CriJul 11, 2023
    risk 0.64cvss 9.8epss 0.02

    Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

  • CVE-2023-32015CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.02

    Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability

  • CVE-2023-34152CriMay 30, 2023
    risk 0.64cvss 9.8epss 0.08

    A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.

  • CVE-2023-32321CriMay 26, 2023
    risk 0.64cvss 9.8epss 0.02

    CKAN is an open-source data management system for powering data hubs and data portals. Multiple vulnerabilities have been discovered in Ckan which may lead to remote code execution. An arbitrary file write in `resource_create` and `package_update` actions, using the…

  • CVE-2022-47937CriMay 15, 2023
    risk 0.64cvss 9.8epss 0.02

    Improper input validation in the Apache Sling Commons JSON bundle allows an attacker to trigger unexpected errors by supplying specially-crafted input. The org.apache.sling.commons.json bundle has been deprecated as of March 2017 and should not be used anymore. Consumers are…

  • CVE-2023-31039CriMay 8, 2023
    risk 0.64cvss 9.8epss 0.02

    Security vulnerability in Apache bRPC <1.5.0 on all platforms allows attackers to execute arbitrary code via ServerOptions::pid_file. An attacker that can influence the ServerOptions pid_file parameter with which the bRPC server is started can execute arbitrary code with the…