VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,429)

page 209 of 672
  • CVE-2019-15915HigDec 20, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, RTCGQ01LM devices. Attackers can utilize the "discover ZigBee network procedure" to perform a denial of service attack.

  • CVE-2019-15914HigDec 20, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Attackers can use the ZigBee trust center rejoin procedure to perform mutiple denial of service attacks.

  • CVE-2019-15912HigDec 20, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Attackers can use the ZigBee trust center rejoin procedure to perform mutiple denial of service attacks.

  • CVE-2019-15910HigDec 20, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Attackers can utilize the "discover ZigBee network procedure" to perform a denial of service attack.

  • CVE-2012-6111HigDec 20, 2019
    risk 0.49cvss 7.5epss 0.02

    gnome-keyring does not discard stored secrets when using gnome_keyring_lock_all_sync function

  • CVE-2019-0166HigDec 18, 2019
    risk 0.49cvss 7.5epss 0.01

    Insufficient input validation in the subsystem for Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable information disclosure via network access.

  • CVE-2019-8788HigDec 18, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1. Improper URL processing may lead to data exfiltration.

  • CVE-2019-8665HigDec 18, 2019
    risk 0.49cvss 7.5epss 0.02

    A denial of service issue was addressed with improved validation. This issue is fixed in iOS 12.4, watchOS 5.3. A remote attacker may cause an unexpected application termination.

  • CVE-2019-8516HigDec 18, 2019
    risk 0.49cvss 7.5epss 0.02

    A validation issue was addressed with improved logic. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. Processing a maliciously crafted string may lead to a denial of service.

  • CVE-2014-8179HigDec 17, 2019
    risk 0.49cvss 7.5epss 0.03

    Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 does not properly validate and extract the manifest object from its JSON representation during a pull, which allows attackers to inject new attributes in a JSON object and bypass pull-by-digest validation.

  • CVE-2019-19729HigDec 11, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the BSON ObjectID (aka bson-objectid) package 1.3.0 for Node.js. ObjectID() allows an attacker to generate a malformed objectid by inserting an additional property to the user-input, because bson-objectid will return early if it detects…

  • CVE-2019-2232HigDec 6, 2019
    risk 0.49cvss 7.5epss 0.01

    In handleRun of TextLine.java, there is a possible application crash due to improper input validation. This could lead to remote denial of service when processing Unicode with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2019-19396HigNov 29, 2019
    risk 0.49cvss 7.5epss 0.01

    illumos, as used in OmniOS Community Edition before r151030y, allows a kernel crash via an application with multiple threads calling sendmsg concurrently over a single socket, because uts/common/inet/ip/ip_attr.c mishandles conn_ixa dereferences.

  • CVE-2019-18247HigNov 27, 2019
    risk 0.49cvss 7.5epss 0.02

    An attacker may use a specially crafted message to force Relion 650 series (versions 1.3.0.5 and prior) or Relion 670 series (versions 1.2.3.18, 2.0.0.11, 2.1.0.1 and prior) to reboot, which could cause a denial of service.

  • CVE-2019-15705HigNov 27, 2019
    risk 0.49cvss 7.5epss 0.02

    An Improper Input Validation vulnerability in the SSL VPN portal of FortiOS versions 6.2.1 and below, and 6.0.6 and below may allow an unauthenticated remote attacker to crash the SSL VPN service by sending a crafted POST request.

  • CVE-2011-4310HigNov 26, 2019
    risk 0.49cvss 7.5epss 0.01

    The news module in CMSMS before 1.9.4.3 allows remote attackers to corrupt new articles.

  • CVE-2019-15276MedNov 26, 2019
    risk 0.49cvss 6.5epss 0.46

    A vulnerability in the web interface of Cisco Wireless LAN Controller Software could allow a low-privileged, authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists due to a failure of the HTTP parsing engine to…

  • CVE-2014-1937HigNov 21, 2019
    risk 0.49cvss 7.5epss 0.01

    Gamera before 3.4.1 insecurely creates temporary files.

  • CVE-2014-1936HigNov 21, 2019
    risk 0.49cvss 7.5epss 0.01

    rc before 1.7.1-5 insecurely creates temporary files.

  • CVE-2012-4524HigNov 21, 2019
    risk 0.49cvss 7.5epss 0.03

    xlockmore before 5.43 'dclock' security bypass vulnerability