VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,314)

page 23 of 666
  • CVE-2019-19836CriJan 22, 2020
    risk 0.64cvss 9.8epss 0.04

    AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote code execution via a POST request that uses tools/_rcmdstat.jsp to write to a specified filename.

  • CVE-2011-3203CriJan 14, 2020
    risk 0.64cvss 9.8epss 0.02

    A Code Execution vulnerability exists the attachment parameter to index.php in Jcow CMS 4.x to 4.2 and 5.2 to 5.2.

  • CVE-2019-19495CriJan 8, 2020
    risk 0.64cvss 9.8epss 0.04

    The web interface on the Technicolor TC7230 STEB 01.25 is vulnerable to DNS rebinding, which allows a remote attacker to configure the cable modem via JavaScript in a victim's browser. The attacker can then configure the cable modem to port forward the modem's internal TELNET…

  • CVE-2014-0048CriJan 2, 2020
    risk 0.64cvss 9.8epss 0.07

    An issue was found in Docker before 1.6.0. Some programs and scripts in Docker are downloaded via HTTP and then executed or used in unsafe ways.

  • CVE-2019-19398CriDec 26, 2019
    risk 0.64cvss 9.8epss 0.01

    M5 lite 10 with versions of 8.0.0.182(C00) have an insufficient input validation vulnerability. Due to the input validation logic is incorrect, an attacker can exploit this vulnerability to modify the memory of the device by doing a series of operations. Successful exploit may…

  • CVE-2019-11107CriDec 18, 2019
    risk 0.64cvss 9.8epss 0.02

    Insufficient input validation in the subsystem for Intel(R) AMT before version 12.0.45 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

  • CVE-2019-10769CriDec 6, 2019
    risk 0.64cvss 9.8epss 0.03

    safer-eval is a npm package to sandbox the he evaluation of code used within the eval function. Affected versions of this package are vulnerable to Arbitrary Code Execution via generating a RangeError.

  • CVE-2019-15958CriNov 26, 2019
    risk 0.64cvss 9.8epss 0.03

    A vulnerability in the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM) could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on the underlying operating system. The vulnerability is due to…

  • CVE-2012-3460CriNov 21, 2019
    risk 0.64cvss 9.8epss 0.01

    cumin: At installation postgresql database user created without password

  • CVE-2013-7171CriNov 21, 2019
    risk 0.64cvss 9.8epss 0.06

    Slackware 14.0 and 14.1, and Slackware LLVM 3.0-i486-2 and 3.3-i486-2, contain world-writable permissions on the /tmp directory which could allow remote attackers to execute arbitrary code with root privileges.

  • CVE-2010-4660CriNov 20, 2019
    risk 0.64cvss 9.8epss 0.01

    Unspecified vulnerability in statusnet through 2010 due to the way addslashes are used in SQL string escapes..

  • CVE-2011-0703CriNov 15, 2019
    risk 0.64cvss 9.8epss 0.01

    In gksu-polkit before 0.0.3, the source file for xauth may contain arbitrary commands that may allow an attacker to overtake an administrator X11 session.

  • CVE-2011-2897CriNov 12, 2019
    risk 0.64cvss 9.8epss 0.02

    gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flaw

  • CVE-2013-1751CriNov 7, 2019
    risk 0.64cvss 9.8epss 0.05

    TWiki before 5.1.4 allows remote attackers to execute arbitrary shell commands by sending a crafted '%MAKETEXT{}%' parameter value containing Perl backtick characters.

  • CVE-2010-2476CriNov 7, 2019
    risk 0.64cvss 9.8epss 0.02

    syscp 1.4.2.1 allows attackers to add arbitrary paths via the documentroot of a domain by appending a colon to it and setting the open basedir path to use that domain documentroot.

  • CVE-2014-9013HigNov 6, 2019
    risk 0.64cvss 8.8epss 0.47

    The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote authenticated users to create arbitrary users and gain admin privileges via a request to wpmp_pp_ajax_call with an execution target of wp_insert_user.

  • CVE-2010-2446CriNov 6, 2019
    risk 0.64cvss 9.8epss 0.03

    Rbot Reaction plugin allows command execution

  • CVE-2015-8980CriNov 4, 2019
    risk 0.64cvss 9.8epss 0.07

    The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attackers to execute arbitrary code.

  • CVE-2013-4409CriNov 4, 2019
    risk 0.64cvss 9.8epss 0.04

    An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when parsing JSON requests.

  • CVE-2013-2259CriNov 4, 2019
    risk 0.64cvss 9.8epss 0.04

    Cryptocat before 2.0.22 has Arbitrary Code Execution on Firefox Conversation Overview