CWE-20
Improper Input Validation
Description
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9
CVEs mapped to this weakness (13,429)
page 209 of 672| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-15915 | Hig | 0.49 | 7.5 | 0.01 | Dec 20, 2019 | An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, RTCGQ01LM devices. Attackers can utilize the "discover ZigBee network procedure" to perform a denial of service attack. | ||
| CVE-2019-15914 | Hig | 0.49 | 7.5 | 0.01 | Dec 20, 2019 | An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Attackers can use the ZigBee trust center rejoin procedure to perform mutiple denial of service attacks. | ||
| CVE-2019-15912 | Hig | 0.49 | 7.5 | 0.01 | Dec 20, 2019 | An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Attackers can use the ZigBee trust center rejoin procedure to perform mutiple denial of service attacks. | ||
| CVE-2019-15910 | Hig | 0.49 | 7.5 | 0.01 | Dec 20, 2019 | An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Attackers can utilize the "discover ZigBee network procedure" to perform a denial of service attack. | ||
| CVE-2012-6111 | Hig | 0.49 | 7.5 | 0.02 | Dec 20, 2019 | gnome-keyring does not discard stored secrets when using gnome_keyring_lock_all_sync function | ||
| CVE-2019-0166 | Hig | 0.49 | 7.5 | 0.01 | Dec 18, 2019 | Insufficient input validation in the subsystem for Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable information disclosure via network access. | ||
| CVE-2019-8788 | Hig | 0.49 | 7.5 | 0.01 | Dec 18, 2019 | An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1. Improper URL processing may lead to data exfiltration. | ||
| CVE-2019-8665 | Hig | 0.49 | 7.5 | 0.02 | Dec 18, 2019 | A denial of service issue was addressed with improved validation. This issue is fixed in iOS 12.4, watchOS 5.3. A remote attacker may cause an unexpected application termination. | ||
| CVE-2019-8516 | Hig | 0.49 | 7.5 | 0.02 | Dec 18, 2019 | A validation issue was addressed with improved logic. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. Processing a maliciously crafted string may lead to a denial of service. | ||
| CVE-2014-8179 | Hig | 0.49 | 7.5 | 0.03 | Dec 17, 2019 | Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 does not properly validate and extract the manifest object from its JSON representation during a pull, which allows attackers to inject new attributes in a JSON object and bypass pull-by-digest validation. | ||
| CVE-2019-19729 | Hig | 0.49 | 7.5 | 0.01 | Dec 11, 2019 | An issue was discovered in the BSON ObjectID (aka bson-objectid) package 1.3.0 for Node.js. ObjectID() allows an attacker to generate a malformed objectid by inserting an additional property to the user-input, because bson-objectid will return early if it detects… | ||
| CVE-2019-2232 | Hig | 0.49 | 7.5 | 0.01 | Dec 6, 2019 | In handleRun of TextLine.java, there is a possible application crash due to improper input validation. This could lead to remote denial of service when processing Unicode with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2019-19396 | Hig | 0.49 | 7.5 | 0.01 | Nov 29, 2019 | illumos, as used in OmniOS Community Edition before r151030y, allows a kernel crash via an application with multiple threads calling sendmsg concurrently over a single socket, because uts/common/inet/ip/ip_attr.c mishandles conn_ixa dereferences. | ||
| CVE-2019-18247 | Hig | 0.49 | 7.5 | 0.02 | Nov 27, 2019 | An attacker may use a specially crafted message to force Relion 650 series (versions 1.3.0.5 and prior) or Relion 670 series (versions 1.2.3.18, 2.0.0.11, 2.1.0.1 and prior) to reboot, which could cause a denial of service. | ||
| CVE-2019-15705 | Hig | 0.49 | 7.5 | 0.02 | Nov 27, 2019 | An Improper Input Validation vulnerability in the SSL VPN portal of FortiOS versions 6.2.1 and below, and 6.0.6 and below may allow an unauthenticated remote attacker to crash the SSL VPN service by sending a crafted POST request. | ||
| CVE-2011-4310 | Hig | 0.49 | 7.5 | 0.01 | Nov 26, 2019 | The news module in CMSMS before 1.9.4.3 allows remote attackers to corrupt new articles. | ||
| CVE-2019-15276 | Med | 0.49 | 6.5 | 0.46 | Nov 26, 2019 | A vulnerability in the web interface of Cisco Wireless LAN Controller Software could allow a low-privileged, authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists due to a failure of the HTTP parsing engine to… | ||
| CVE-2014-1937 | Hig | 0.49 | 7.5 | 0.01 | Nov 21, 2019 | Gamera before 3.4.1 insecurely creates temporary files. | ||
| CVE-2014-1936 | Hig | 0.49 | 7.5 | 0.01 | Nov 21, 2019 | rc before 1.7.1-5 insecurely creates temporary files. | ||
| CVE-2012-4524 | Hig | 0.49 | 7.5 | 0.03 | Nov 21, 2019 | xlockmore before 5.43 'dclock' security bypass vulnerability |
- risk 0.49cvss 7.5epss 0.01
An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, RTCGQ01LM devices. Attackers can utilize the "discover ZigBee network procedure" to perform a denial of service attack.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Attackers can use the ZigBee trust center rejoin procedure to perform mutiple denial of service attacks.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Attackers can use the ZigBee trust center rejoin procedure to perform mutiple denial of service attacks.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Attackers can utilize the "discover ZigBee network procedure" to perform a denial of service attack.
- risk 0.49cvss 7.5epss 0.02
gnome-keyring does not discard stored secrets when using gnome_keyring_lock_all_sync function
- risk 0.49cvss 7.5epss 0.01
Insufficient input validation in the subsystem for Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable information disclosure via network access.
- risk 0.49cvss 7.5epss 0.01
An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1. Improper URL processing may lead to data exfiltration.
- risk 0.49cvss 7.5epss 0.02
A denial of service issue was addressed with improved validation. This issue is fixed in iOS 12.4, watchOS 5.3. A remote attacker may cause an unexpected application termination.
- risk 0.49cvss 7.5epss 0.02
A validation issue was addressed with improved logic. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. Processing a maliciously crafted string may lead to a denial of service.
- risk 0.49cvss 7.5epss 0.03
Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 does not properly validate and extract the manifest object from its JSON representation during a pull, which allows attackers to inject new attributes in a JSON object and bypass pull-by-digest validation.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in the BSON ObjectID (aka bson-objectid) package 1.3.0 for Node.js. ObjectID() allows an attacker to generate a malformed objectid by inserting an additional property to the user-input, because bson-objectid will return early if it detects…
- risk 0.49cvss 7.5epss 0.01
In handleRun of TextLine.java, there is a possible application crash due to improper input validation. This could lead to remote denial of service when processing Unicode with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.49cvss 7.5epss 0.01
illumos, as used in OmniOS Community Edition before r151030y, allows a kernel crash via an application with multiple threads calling sendmsg concurrently over a single socket, because uts/common/inet/ip/ip_attr.c mishandles conn_ixa dereferences.
- risk 0.49cvss 7.5epss 0.02
An attacker may use a specially crafted message to force Relion 650 series (versions 1.3.0.5 and prior) or Relion 670 series (versions 1.2.3.18, 2.0.0.11, 2.1.0.1 and prior) to reboot, which could cause a denial of service.
- risk 0.49cvss 7.5epss 0.02
An Improper Input Validation vulnerability in the SSL VPN portal of FortiOS versions 6.2.1 and below, and 6.0.6 and below may allow an unauthenticated remote attacker to crash the SSL VPN service by sending a crafted POST request.
- risk 0.49cvss 7.5epss 0.01
The news module in CMSMS before 1.9.4.3 allows remote attackers to corrupt new articles.
- risk 0.49cvss 6.5epss 0.46
A vulnerability in the web interface of Cisco Wireless LAN Controller Software could allow a low-privileged, authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists due to a failure of the HTTP parsing engine to…
- risk 0.49cvss 7.5epss 0.01
Gamera before 3.4.1 insecurely creates temporary files.
- risk 0.49cvss 7.5epss 0.01
rc before 1.7.1-5 insecurely creates temporary files.
- risk 0.49cvss 7.5epss 0.03
xlockmore before 5.43 'dclock' security bypass vulnerability