VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,314)

page 22 of 666
  • CVE-2020-3847CriApr 1, 2020
    risk 0.64cvss 9.8epss 0.02

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A remote attacker may be able to leak memory.

  • CVE-2020-10374CriMar 30, 2020
    risk 0.64cvss 9.8epss 0.05

    A webserver component in Paessler PRTG Network Monitor 19.2.50 to PRTG 20.1.56 allows unauthenticated remote command execution via a crafted POST request or the what parameter of the screenshot function in the Contact Support form.

  • CVE-2020-10885CriMar 25, 2020
    risk 0.64cvss 9.8epss 0.07

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of DNS responses.…

  • CVE-2020-10837CriMar 24, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (with TEEGRIS) software. The Esecomm Trustlet allows a stack overflow and arbitrary code execution. The Samsung ID is SVE-2019-15984 (February 2020).

  • CVE-2019-7589CriMar 10, 2020
    risk 0.64cvss 9.8epss 0.02

    A vulnerability with the SmartService API Service option exists whereby an unauthorized user could potentially exploit this to upload malicious code to the server that could be executed at system level privileges. This affects Johnson Controls' Kantech EntraPass Corporate…

  • CVE-2020-8132CriFeb 28, 2020
    risk 0.64cvss 9.8epss 0.02

    Lack of input validation in pdf-image npm package version <= 2.0.0 may allow an attacker to run arbitrary code if PDF file path is constructed based on untrusted user input.

  • CVE-2014-4651CriFeb 18, 2020
    risk 0.64cvss 9.8epss 0.02

    It was found that the jclouds scriptbuilder Statements class wrote a temporary file to a predictable location. An attacker could use this flaw to access sensitive data, cause a denial of service, or perform other attacks.

  • CVE-2015-1425CriFeb 18, 2020
    risk 0.64cvss 9.8epss 0.02

    JAKWEB Gecko CMS has Multiple Input Validation Vulnerabilities

  • CVE-2013-3738CriFeb 17, 2020
    risk 0.64cvss 9.8epss 0.03

    A File Inclusion vulnerability exists in Zabbix 2.0.6 due to inadequate sanitization of request strings in CGI scripts, which could let a remote malicious user execute arbitrary code.

  • CVE-2020-8614CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered on Askey AP4000W TDC_V1.01.003 devices. An attacker can perform Remote Code Execution (RCE) by sending a specially crafted network packer to the bd_svr service listening on TCP port 54188.

  • CVE-2013-1607CriFeb 11, 2020
    risk 0.64cvss 9.8epss 0.03

    Ruby PDFKit gem prior to 0.5.3 has a Code Execution Vulnerability

  • CVE-2014-5468HigFeb 7, 2020
    risk 0.64cvss 8.8epss 0.53

    A File Inclusion vulnerability exists in Railo 4.2.1 and earlier via a specially-crafted URL request to the thumbnail.cfm to specify a malicious PNG file, which could let a remote malicious user obtain sensitive information or execute arbitrary code.

  • CVE-2010-4815CriFeb 5, 2020
    risk 0.64cvss 9.8epss 0.02

    Coppermine gallery before 1.4.26 has an input validation vulnerability that allows for code execution.

  • CVE-2019-10786CriFeb 4, 2020
    risk 0.64cvss 9.8epss 0.02

    network-manager through 1.0.2 allows remote attackers to execute arbitrary commands via the "execSync()" argument.

  • CVE-2016-2031CriJan 31, 2020
    risk 0.64cvss 9.8epss 0.05

    Multiple vulnerabilities exists in Aruba Instate before 4.1.3.0 and 4.2.3.1 due to insufficient validation of user-supplied input and insufficient checking of parameters, which could allow a malicious user to bypass security restrictions, obtain sensitive information, perform…

  • CVE-2020-8445CriJan 30, 2020
    risk 0.64cvss 9.8epss 0.02

    In OSSEC-HIDS 2.7 through 3.5.0, the OS_CleanMSG function in ossec-analysisd doesn't remove or encode terminal control characters or newlines from processed log messages. In many cases, those characters are later logged. Because newlines (\n) are permitted in messages processed…

  • CVE-2014-2914CriJan 28, 2020
    risk 0.64cvss 9.8epss 0.03

    fish (aka fish-shell) 2.0.0 before 2.1.1 does not restrict access to the configuration service (aka fish_config), which allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by set_prompt.

  • CVE-2019-5464CriJan 28, 2020
    risk 0.64cvss 9.8epss 0.03

    A flawed DNS rebinding protection issue was discovered in GitLab CE/EE 10.2 and later in the `url_blocker.rb` which could result in SSRF where the library is utilized.

  • CVE-2020-8087CriJan 27, 2020
    risk 0.64cvss 9.8epss 0.06

    SMC Networks D3G0804W D3GNV5M-3.5.1.6.10_GA devices allow remote command execution by leveraging access to the Network Diagnostic Tools screen, as demonstrated by an admin login. The attacker must use a Parameter Pollution approach against goform/formSetDiagnosticToolsFmPing by…

  • CVE-2020-6965CriJan 24, 2020
    risk 0.64cvss 9.9epss 0.01

    In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, B450 Version 2.X, B650 Version 1.X, B650 Version 2.X, B850 Version 1.X, B850…