VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,430)

page 197 of 672
  • CVE-2021-22286HigFeb 4, 2022
    risk 0.49cvss 7.5epss 0.01

    Improper Input Validation vulnerability in the ABB SPIET800 and PNI800 module allows an attacker to cause the denial of service or make the module unresponsive.

  • CVE-2021-40423HigJan 28, 2022
    risk 0.49cvss 7.5epss 0.01

    A denial of service vulnerability exists in the cgiserver.cgi API command parser functionality of Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted series of HTTP requests can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2022-23019HigJan 25, 2022
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x and 12.1.x, when a message routing type virtual server is configured with both Diameter Session and Router Profiles, undisclosed traffic can cause an increase in…

  • CVE-2021-36343HigJan 24, 2022
    risk 0.49cvss 7.5epss 0.00

    Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

  • CVE-2021-36342HigJan 24, 2022
    risk 0.49cvss 7.5epss 0.00

    Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

  • CVE-2021-42555HigJan 15, 2022
    risk 0.49cvss 7.5epss 0.01

    Pexip Infinity before 26.2 allows temporary remote Denial of Service (abort) because of missing call-setup input validation.

  • CVE-2021-35969HigJan 15, 2022
    risk 0.49cvss 7.5epss 0.01

    Pexip Infinity before 26 allows temporary remote Denial of Service (abort) because of missing call-setup input validation.

  • CVE-2021-33499HigJan 15, 2022
    risk 0.49cvss 7.5epss 0.01

    Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation (issue 2 of 2).

  • CVE-2021-33498HigJan 15, 2022
    risk 0.49cvss 7.5epss 0.01

    Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation (issue 1 of 2).

  • CVE-2021-32545HigJan 15, 2022
    risk 0.49cvss 7.5epss 0.01

    Pexip Infinity before 26 allows remote denial of service because of missing RTMP input validation.

  • CVE-2022-20698HigJan 14, 2022
    risk 0.49cvss 7.5epss 0.03

    A vulnerability in the OOXML parsing module in Clam AntiVirus (ClamAV) Software version 0.104.1 and LTS version 0.103.4 and prior versions could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to…

  • CVE-2021-41769HigJan 11, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SIPROTEC 5 6MD85 devices (CPU variant CP300) (All versions < V8.83), SIPROTEC 5 6MD86 devices (CPU variant CP300) (All versions < V8.83), SIPROTEC 5 6MD89 devices (CPU variant CP300) (All versions < V8.83), SIPROTEC 5 6MU85 devices (CPU…

  • CVE-2021-38957HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could disclose sensitive information due to hazardous input validation during QR code generation. IBM X-Force ID: 212040.

  • CVE-2020-5956HigJan 5, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in SdLegacySmm in Insyde InsydeH2O with kernel 5.1 before 05.15.11, 5.2 before 05.25.11, 5.3 before 05.34.11, and 5.4 before 05.42.11. The software SMI handler allows untrusted external input because it does not verify CommBuffer.

  • CVE-2021-24893HigJan 3, 2022
    risk 0.49cvss 7.5epss 0.02

    The Stars Rating WordPress plugin before 3.5.1 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the comments section, or pending comment dashboard depending if the user sent it as unauthenticated or authenticated.

  • CVE-2021-41561HigDec 20, 2021
    risk 0.49cvss 7.5epss 0.03

    Improper Input Validation vulnerability in Parquet-MR of Apache Parquet allows an attacker to DoS by malicious Parquet files. This issue affects Apache Parquet-MR version 1.9.0 and later versions.

  • CVE-2021-37096HigDec 7, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to user privacy disclosed.

  • CVE-2021-37094HigDec 7, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to system denial of service.

  • CVE-2021-37081HigDec 7, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to nearby crash.

  • CVE-2021-37060HigDec 7, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to SAMGR Heap Address Leakage.