CWE-20
Improper Input Validation
Description
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9
CVEs mapped to this weakness (13,430)
page 197 of 672| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-22286 | Hig | 0.49 | 7.5 | 0.01 | Feb 4, 2022 | Improper Input Validation vulnerability in the ABB SPIET800 and PNI800 module allows an attacker to cause the denial of service or make the module unresponsive. | ||
| CVE-2021-40423 | Hig | 0.49 | 7.5 | 0.01 | Jan 28, 2022 | A denial of service vulnerability exists in the cgiserver.cgi API command parser functionality of Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted series of HTTP requests can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability. | ||
| CVE-2022-23019 | Hig | 0.49 | 7.5 | 0.01 | Jan 25, 2022 | On BIG-IP version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x and 12.1.x, when a message routing type virtual server is configured with both Diameter Session and Router Profiles, undisclosed traffic can cause an increase in… | ||
| CVE-2021-36343 | Hig | 0.49 | 7.5 | 0.00 | Jan 24, 2022 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM. | ||
| CVE-2021-36342 | Hig | 0.49 | 7.5 | 0.00 | Jan 24, 2022 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM. | ||
| CVE-2021-42555 | Hig | 0.49 | 7.5 | 0.01 | Jan 15, 2022 | Pexip Infinity before 26.2 allows temporary remote Denial of Service (abort) because of missing call-setup input validation. | ||
| CVE-2021-35969 | Hig | 0.49 | 7.5 | 0.01 | Jan 15, 2022 | Pexip Infinity before 26 allows temporary remote Denial of Service (abort) because of missing call-setup input validation. | ||
| CVE-2021-33499 | Hig | 0.49 | 7.5 | 0.01 | Jan 15, 2022 | Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation (issue 2 of 2). | ||
| CVE-2021-33498 | Hig | 0.49 | 7.5 | 0.01 | Jan 15, 2022 | Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation (issue 1 of 2). | ||
| CVE-2021-32545 | Hig | 0.49 | 7.5 | 0.01 | Jan 15, 2022 | Pexip Infinity before 26 allows remote denial of service because of missing RTMP input validation. | ||
| CVE-2022-20698 | Hig | 0.49 | 7.5 | 0.03 | Jan 14, 2022 | A vulnerability in the OOXML parsing module in Clam AntiVirus (ClamAV) Software version 0.104.1 and LTS version 0.103.4 and prior versions could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to… | ||
| CVE-2021-41769 | Hig | 0.49 | 7.5 | 0.01 | Jan 11, 2022 | A vulnerability has been identified in SIPROTEC 5 6MD85 devices (CPU variant CP300) (All versions < V8.83), SIPROTEC 5 6MD86 devices (CPU variant CP300) (All versions < V8.83), SIPROTEC 5 6MD89 devices (CPU variant CP300) (All versions < V8.83), SIPROTEC 5 6MU85 devices (CPU… | ||
| CVE-2021-38957 | Hig | 0.49 | 7.5 | 0.01 | Jan 10, 2022 | IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could disclose sensitive information due to hazardous input validation during QR code generation. IBM X-Force ID: 212040. | ||
| CVE-2020-5956 | Hig | 0.49 | 7.5 | 0.01 | Jan 5, 2022 | An issue was discovered in SdLegacySmm in Insyde InsydeH2O with kernel 5.1 before 05.15.11, 5.2 before 05.25.11, 5.3 before 05.34.11, and 5.4 before 05.42.11. The software SMI handler allows untrusted external input because it does not verify CommBuffer. | ||
| CVE-2021-24893 | Hig | 0.49 | 7.5 | 0.02 | Jan 3, 2022 | The Stars Rating WordPress plugin before 3.5.1 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the comments section, or pending comment dashboard depending if the user sent it as unauthenticated or authenticated. | ||
| CVE-2021-41561 | Hig | 0.49 | 7.5 | 0.03 | Dec 20, 2021 | Improper Input Validation vulnerability in Parquet-MR of Apache Parquet allows an attacker to DoS by malicious Parquet files. This issue affects Apache Parquet-MR version 1.9.0 and later versions. | ||
| CVE-2021-37096 | Hig | 0.49 | 7.5 | 0.01 | Dec 7, 2021 | There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to user privacy disclosed. | ||
| CVE-2021-37094 | Hig | 0.49 | 7.5 | 0.01 | Dec 7, 2021 | There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to system denial of service. | ||
| CVE-2021-37081 | Hig | 0.49 | 7.5 | 0.01 | Dec 7, 2021 | There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to nearby crash. | ||
| CVE-2021-37060 | Hig | 0.49 | 7.5 | 0.01 | Dec 7, 2021 | There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to SAMGR Heap Address Leakage. |
- risk 0.49cvss 7.5epss 0.01
Improper Input Validation vulnerability in the ABB SPIET800 and PNI800 module allows an attacker to cause the denial of service or make the module unresponsive.
- risk 0.49cvss 7.5epss 0.01
A denial of service vulnerability exists in the cgiserver.cgi API command parser functionality of Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted series of HTTP requests can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.
- risk 0.49cvss 7.5epss 0.01
On BIG-IP version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x and 12.1.x, when a message routing type virtual server is configured with both Diameter Session and Router Profiles, undisclosed traffic can cause an increase in…
- risk 0.49cvss 7.5epss 0.00
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
- risk 0.49cvss 7.5epss 0.00
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
- risk 0.49cvss 7.5epss 0.01
Pexip Infinity before 26.2 allows temporary remote Denial of Service (abort) because of missing call-setup input validation.
- risk 0.49cvss 7.5epss 0.01
Pexip Infinity before 26 allows temporary remote Denial of Service (abort) because of missing call-setup input validation.
- risk 0.49cvss 7.5epss 0.01
Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation (issue 2 of 2).
- risk 0.49cvss 7.5epss 0.01
Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation (issue 1 of 2).
- risk 0.49cvss 7.5epss 0.01
Pexip Infinity before 26 allows remote denial of service because of missing RTMP input validation.
- risk 0.49cvss 7.5epss 0.03
A vulnerability in the OOXML parsing module in Clam AntiVirus (ClamAV) Software version 0.104.1 and LTS version 0.103.4 and prior versions could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to…
- risk 0.49cvss 7.5epss 0.01
A vulnerability has been identified in SIPROTEC 5 6MD85 devices (CPU variant CP300) (All versions < V8.83), SIPROTEC 5 6MD86 devices (CPU variant CP300) (All versions < V8.83), SIPROTEC 5 6MD89 devices (CPU variant CP300) (All versions < V8.83), SIPROTEC 5 6MU85 devices (CPU…
- risk 0.49cvss 7.5epss 0.01
IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could disclose sensitive information due to hazardous input validation during QR code generation. IBM X-Force ID: 212040.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in SdLegacySmm in Insyde InsydeH2O with kernel 5.1 before 05.15.11, 5.2 before 05.25.11, 5.3 before 05.34.11, and 5.4 before 05.42.11. The software SMI handler allows untrusted external input because it does not verify CommBuffer.
- risk 0.49cvss 7.5epss 0.02
The Stars Rating WordPress plugin before 3.5.1 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the comments section, or pending comment dashboard depending if the user sent it as unauthenticated or authenticated.
- risk 0.49cvss 7.5epss 0.03
Improper Input Validation vulnerability in Parquet-MR of Apache Parquet allows an attacker to DoS by malicious Parquet files. This issue affects Apache Parquet-MR version 1.9.0 and later versions.
- risk 0.49cvss 7.5epss 0.01
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to user privacy disclosed.
- risk 0.49cvss 7.5epss 0.01
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to system denial of service.
- risk 0.49cvss 7.5epss 0.01
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to nearby crash.
- risk 0.49cvss 7.5epss 0.01
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to SAMGR Heap Address Leakage.