VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,429)

page 212 of 672
  • CVE-2019-12633HigSep 5, 2019
    risk 0.49cvss 7.5epss 0.02

    A vulnerability in Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to bypass access controls and conduct a server-side request forgery (SSRF) attack on a targeted system. The vulnerability is due to improper validation of…

  • CVE-2019-12632HigSep 5, 2019
    risk 0.49cvss 7.5epss 0.02

    A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to bypass access controls and conduct a server-side request forgery (SSRF) attack on an affected system. The vulnerability exists because the affected system does not properly validate user-supplied…

  • CVE-2019-5611HigAug 30, 2019
    risk 0.49cvss 7.5epss 0.04

    In FreeBSD 12.0-STABLE before r350828, 12.0-RELEASE before 12.0-RELEASE-p10, 11.3-STABLE before r350829, 11.3-RELEASE before 11.3-RELEASE-p3, and 11.2-RELEASE before 11.2-RELEASE-p14, a missing check in the function to arrange data in a chain of mbufs could cause data returned…

  • CVE-2019-1968HigAug 30, 2019
    risk 0.49cvss 7.5epss 0.02

    A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an NX-API system process to unexpectedly restart. The vulnerability is due to incorrect validation of the HTTP header of a request that is sent to the NX-API.…

  • CVE-2019-10054HigAug 28, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Suricata 4.1.3. The function process_reply_record_v3 lacks a check for the length of reply.data. It causes an invalid memory access and the program crashes within the nfs/nfs3.rs file.

  • CVE-2015-9348HigAug 27, 2019
    risk 0.49cvss 7.5epss 0.02

    The sell-downloads plugin before 1.0.8 for WordPress has insufficient restrictions on brute-force guessing of purchase IDs.

  • CVE-2015-9345HigAug 27, 2019
    risk 0.49cvss 7.5epss 0.01

    The link-log plugin before 2.0 for WordPress has HTTP Response Splitting.

  • CVE-2018-20980HigAug 22, 2019
    risk 0.49cvss 7.5epss 0.01

    The ninja-forms plugin before 3.2.15 for WordPress has parameter tampering.

  • CVE-2017-18545HigAug 16, 2019
    risk 0.49cvss 7.5epss 0.01

    The invite-anyone plugin before 1.3.16 for WordPress has incorrect escaping of untrusted Dashboard and front-end input.

  • CVE-2019-1955HigAug 8, 2019
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the Sender Policy Framework (SPF) functionality of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to bypass configured user filters on the device. The vulnerability is due to incomplete input…

  • CVE-2019-14474HigAug 7, 2019
    risk 0.49cvss 7.5epss 0.02

    eQ-3 Homematic CCU3 3.47.15 and prior has Improper Input Validation in function 'Call()' of ReGa core logic process, resulting in the ability to start a Denial of Service. Due to Improper Authorization an attacker can obtain a session ID from CVE-2019-9583 or a valid…

  • CVE-2017-18431HigAug 2, 2019
    risk 0.49cvss 7.5epss 0.01

    cPanel before 66.0.1 does not reliably perform suspend/unsuspend operations on accounts (CPANEL-13941).

  • CVE-2019-13097HigJul 22, 2019
    risk 0.49cvss 7.5epss 0.01

    The application API of Cat Runner Decorate Home version 2.8.0 for Android does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable. Attackers can manipulate users' score parameters exchanged between client and server.

  • CVE-2019-14211HigJul 21, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Foxit PhantomPDF before 8.3.11. The application could crash due to the lack of proper validation of the existence of an object prior to performing operations on that object when executing JavaScript.

  • CVE-2019-7843HigJul 18, 2019
    risk 0.49cvss 7.5epss 0.03

    Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Insufficient input validation vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user.

  • CVE-2019-10191HigJul 16, 2019
    risk 0.49cvss 7.5epss 0.02

    A vulnerability was discovered in DNS resolver of knot resolver before version 4.1.0 which allows remote attackers to downgrade DNSSEC-secure domains to DNSSEC-insecure state, opening possibility of domain hijack using attacks against insecure DNS protocol.

  • CVE-2019-10190HigJul 16, 2019
    risk 0.49cvss 7.5epss 0.02

    A vulnerability was discovered in DNS resolver component of knot resolver through version 3.2.0 before 4.1.0 which allows remote attackers to bypass DNSSEC validation for non-existence answer. NXDOMAIN answer would get passed through to the client even if its DNSSEC validation…

  • CVE-2018-19629HigJul 16, 2019
    risk 0.49cvss 7.5epss 0.01

    A Denial of Service vulnerability in the ImageNow Server service in Hyland Perceptive Content Server before 7.1.5 allows an attacker to crash the service via a TCP connection.

  • CVE-2019-13612HigJul 16, 2019
    risk 0.49cvss 7.5epss 0.01

    MDaemon Email Server 19 through 20.0.1 skips SpamAssassin checks by default for e-mail messages larger than 2 MB (and limits checks to 10 MB even with special configuration), which is arguably inconsistent with currently popular message sizes. This might interfere with risk…

  • CVE-2018-10531HigJul 10, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the America's Army Proving Grounds platform for the Unreal Engine. With a false packet sent via UDP, the application server responds with several bytes, giving the possibility of DoS amplification, even being able to be used in DDoS attacks.