VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,314)

page 16 of 666
  • CVE-2022-47937CriMay 15, 2023
    risk 0.64cvss 9.8epss 0.02

    Improper input validation in the Apache Sling Commons JSON bundle allows an attacker to trigger unexpected errors by supplying specially-crafted input. The org.apache.sling.commons.json bundle has been deprecated as of March 2017 and should not be used anymore. Consumers are…

  • CVE-2023-31039CriMay 8, 2023
    risk 0.64cvss 9.8epss 0.02

    Security vulnerability in Apache bRPC <1.5.0 on all platforms allows attackers to execute arbitrary code via ServerOptions::pid_file. An attacker that can influence the ServerOptions pid_file parameter with which the bRPC server is started can execute arbitrary code with the…

  • CVE-2023-22581CriApr 24, 2023
    risk 0.64cvss 9.8epss 0.01

    White Rabbit Switch contains a vulnerability which makes it possible for an attacker to perform system commands under the context of the web application (the default installation makes the webserver run as the root user).

  • CVE-2022-29606CriApr 20, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in ONOS 2.5.1. An intent with a large port number shows the CORRUPT state, which is misleading to a network operator. Improper handling of such port numbers causes inconsistency between intent and flow rules in the network.

  • CVE-2022-33211CriApr 13, 2023
    risk 0.64cvss 9.8epss 0.00

    memory corruption in modem due to improper check while calculating size of serialized CoAP message

  • CVE-2023-26070CriApr 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 4 of 4).

  • CVE-2023-26069CriApr 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 3 of 4).

  • CVE-2023-28731CriMar 30, 2023
    risk 0.64cvss 9.8epss 0.02

    AnyMailing Joomla Plugin is vulnerable to unauthenticated remote code execution, when being granted access to the campaign's creation on front-office due to unrestricted file upload allowing PHP code to be injected. This issue affects AnyMailing Joomla Plugin Enterprise…

  • CVE-2021-35370CriFeb 24, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue found in Peacexie Imcat v5.4 allows attackers to execute arbitrary code via the incomplete filtering function.

  • CVE-2022-45088CriFeb 12, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Input Validation vulnerability in Group Arge Energy and Control Systems Smartpower Web allows PHP Local File Inclusion. This issue affects Smartpower Web: before 23.01.01.

  • CVE-2022-25729CriFeb 12, 2023
    risk 0.64cvss 9.8epss 0.00

    Memory corruption in modem due to improper length check while copying into memory

  • CVE-2022-39060CriJan 31, 2023
    risk 0.64cvss 9.8epss 0.01

    ChangingTech MegaServiSignAdapter component has a vulnerability of improper input validation. An unauthenticated remote attacker can exploit this vulnerability to access and modify HKEY_CURRENT_USER subkey (ex: AutoRUN) in Registry where malicious scripts can be executed to take…

  • CVE-2022-45875CriJan 4, 2023
    risk 0.64cvss 9.8epss 0.03

    Improper validation of script alert plugin parameters in Apache DolphinScheduler to avoid remote command execution vulnerability. This issue affects Apache DolphinScheduler version 3.0.1 and prior versions; version 3.1.0 and prior versions. This attack can be performed only by…

  • CVE-2022-34476CriDec 22, 2022
    risk 0.64cvss 9.8epss 0.01

    ASN.1 parsing of an indefinite SEQUENCE inside an indefinite GROUP could have resulted in the parser accepting malformed ASN.1. This vulnerability affects Firefox < 102.

  • CVE-2022-42837CriDec 15, 2022
    risk 0.64cvss 9.8epss 0.02

    An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, watchOS 9.2. A remote user may be able to cause unexpected app termination or…

  • CVE-2022-45872CriNov 23, 2022
    risk 0.64cvss 9.8epss 0.01

    iTerm2 before 3.4.18 mishandles a DECRQSS response.

  • CVE-2022-36784CriNov 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Elsight – Elsight Halo  Remote Code Execution (RCE) Elsight Halo web panel allows us to perform connection validation. through the POST request : /api/v1/nics/wifi/wlan0/ping we can abuse DESTINATION parameter and leverage it to remote code execution.

  • CVE-2022-43546CriNov 8, 2022
    risk 0.64cvss 9.9epss 0.02

    A vulnerability has been identified in POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), SICAM P850 (All versions < V3.10), SICAM P850 (All…

  • CVE-2022-43545CriNov 8, 2022
    risk 0.64cvss 9.9epss 0.01

    A vulnerability has been identified in POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), SICAM P850 (All versions < V3.10), SICAM P850 (All…

  • CVE-2022-43439CriNov 8, 2022
    risk 0.64cvss 9.9epss 0.02

    A vulnerability has been identified in POWER METER SICAM Q100 (7KG9501-0AA01-0AA1) (All versions < V2.50), POWER METER SICAM Q100 (7KG9501-0AA01-2AA1) (All versions < V2.50), POWER METER SICAM Q100 (7KG9501-0AA31-0AA1) (All versions < V2.50), POWER METER SICAM Q100…