VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,429)

page 210 of 672
  • CVE-2013-1816HigNov 20, 2019
    risk 0.49cvss 7.5epss 0.03

    MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to cause a denial of service (application crash) by sending a specially crafted request.

  • CVE-2011-0529HigNov 20, 2019
    risk 0.49cvss 7.5epss 0.01

    Weborf before 0.12.5 is affected by a Denial of Service (DOS) due to malformed fields in HTTP.

  • CVE-2019-11289HigNov 19, 2019
    risk 0.49cvss 8.6epss 0.02

    Cloud Foundry Routing, all versions before 0.193.0, does not properly validate nonce input. A remote unauthenticated malicious user could forge an HTTP route service request using an invalid nonce that will cause the Gorouter to crash.

  • CVE-2012-6070HigNov 19, 2019
    risk 0.49cvss 7.5epss 0.02

    Falconpl before 0.9.6.9-git20120606 misuses the libcurl API which may allow remote attackers to interfere with security checks.

  • CVE-2011-4967HigNov 19, 2019
    risk 0.49cvss 7.5epss 0.03

    tog-Pegasus has a package hash collision DoS vulnerability

  • CVE-2019-11180HigNov 14, 2019
    risk 0.49cvss 7.5epss 0.01

    Insufficient input validation in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable denial of service via network access.

  • CVE-2019-11175HigNov 14, 2019
    risk 0.49cvss 7.5epss 0.01

    Insufficient input validation in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable denial of service via network access.

  • CVE-2009-5050HigNov 6, 2019
    risk 0.49cvss 7.5epss 0.02

    konversation before 1.2.3 allows attackers to cause a denial of service.

  • CVE-2019-1789HigNov 5, 2019
    risk 0.49cvss 7.5epss 0.01

    ClamAV versions prior to 0.101.2 are susceptible to a denial of service (DoS) vulnerability. An out-of-bounds heap read condition may occur when scanning PE files. An example is Windows EXE and DLL files that have been packed using Aspack as a result of inadequate bound-checking.

  • CVE-2019-17210HigNov 4, 2019
    risk 0.49cvss 7.5epss 0.01

    A denial-of-service issue was discovered in the MQTT library in Arm Mbed OS 2017-11-02. The function readMQTTLenString() is called by the function MQTTDeserialize_publish() to get the length and content of the MQTT topic name. In the function readMQTTLenString(),…

  • CVE-2013-4100HigNov 4, 2019
    risk 0.49cvss 7.5epss 0.02

    Cryptocat before 2.0.22 has Remote Denial of Service via username

  • CVE-2019-18228HigOct 31, 2019
    risk 0.49cvss 7.5epss 0.02

    Honeywell equIP series IP cameras Multiple equIP Series Cameras, A vulnerability exists in the affected products where a specially crafted HTTP packet request could result in a denial of service.

  • CVE-2010-1678HigOct 29, 2019
    risk 0.49cvss 7.5epss 0.02

    Mapserver 5.2, 5.4 and 5.6 before 5.6.5-2 improperly validates symbol index values during Mapfile parsing.

  • CVE-2019-18608HigOct 29, 2019
    risk 0.49cvss 7.5epss 0.01

    Cezerin v0.33.0 allows unauthorized order-information modification because certain internal attributes can be overwritten via a conflicting name when processing order requests. Hence, a malicious customer can manipulate an order (e.g., its payment status or shipping fee) by…

  • CVE-2014-2304HigOct 23, 2019
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in version 0.90 of the Open Floodlight SDN controller software could result in a denial of service attack and crashing of the controller service. This effect is the result of a flaw in OpenFlow protocol processing, where specific malformed and mistimed…

  • CVE-2013-7333HigOct 23, 2019
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in version 0.90 of the Open Floodlight SDN controller software could allow an attacker with access to the OpenFlow control network to selectively disconnect individual switches from the SDN controller, causing degradation and eventually denial of network access…

  • CVE-2019-12290HigOct 22, 2019
    risk 0.49cvss 7.5epss 0.03

    GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490 Section 4.2 when converting A-labels to U-labels. This makes it possible in some circumstances for one domain to impersonate another. By creating a malicious domain that matches a target domain…

  • CVE-2019-15262HigOct 16, 2019
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the Secure Shell (SSH) session management for Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists because the SSH process is…

  • CVE-2019-17507HigOct 11, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered on D-Link DIR-816 A1 1.06 devices. An attacker could access management pages of the router via a client that ignores the 'top.location.href = "/dir_login.asp"' line in a .asp file. This provides access to d_status.asp, version.asp, d_dhcptbl.asp, and…

  • CVE-2019-12706HigOct 2, 2019
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the Sender Policy Framework (SPF) functionality of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the configured user filters on an affected device. The vulnerability exists because the…