CWE-20
Improper Input Validation
Description
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9
CVEs mapped to this weakness (13,314)
page 24 of 666| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2012-6125 | Cri | 0.64 | 9.8 | 0.02 | Oct 31, 2019 | Chicken before 4.8.0 is susceptible to algorithmic complexity attacks related to hash table collisions. | ||
| CVE-2013-1910 | Cri | 0.64 | 9.8 | 0.03 | Oct 31, 2019 | yum does not properly handle bad metadata, which allows an attacker to cause a denial of service and possibly have other unspecified impact via a Trojan horse file in the metadata of a remote repository. | ||
| CVE-2010-0748 | Cri | 0.64 | 9.8 | 0.02 | Oct 30, 2019 | Transmission before 1.92 allows an attacker to cause a denial of service (crash) or possibly have other unspecified impact via a large number of tr arguments in a magnet link. | ||
| CVE-2010-3375 | Cri | 0.64 | 9.8 | 0.02 | Oct 29, 2019 | qtparted has insecure library loading which may allow arbitrary code execution | ||
| CVE-2019-16699 | Cri | 0.64 | 9.8 | 0.02 | Oct 16, 2019 | The sr_freecap (aka freeCap CAPTCHA) extension 2.4.5 and below and 2.5.2 and below for TYPO3 fails to sanitize user input, which allows execution of arbitrary Extbase actions, resulting in Remote Code Execution. | ||
| CVE-2019-15019 | Cri | 0.64 | 9.8 | 0.01 | Oct 9, 2019 | A security vulnerability exists in the Zingbox Inspector versions 1.294 and earlier, that could allow an attacker to supply an invalid software update image to the Zingbox Inspector. | ||
| CVE-2018-10105 | Cri | 0.64 | 9.8 | 0.04 | Oct 3, 2019 | tcpdump before 4.9.3 mishandles the printing of SMB data (issue 2 of 2). | ||
| CVE-2018-10103 | Cri | 0.64 | 9.8 | 0.04 | Oct 3, 2019 | tcpdump before 4.9.3 mishandles the printing of SMB data (issue 1 of 2). | ||
| CVE-2019-12157 | Cri | 0.64 | 9.8 | 0.02 | Oct 2, 2019 | In JetBrains UpSource versions before 2018.2 build 1293, there is credential disclosure via RPC commands. | ||
| CVE-2019-10538 | Cri | 0.64 | 9.8 | 0.01 | Sep 30, 2019 | Lack of check of address range received from firmware response allows modem to respond arbitrary pages into its address range which can compromise HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice… | ||
| CVE-2019-3416 | Cri | 0.64 | 9.8 | 0.01 | Sep 23, 2019 | All versions up to V81511329.1008 of ZTE ZXV10 B860A products are impacted by input validation vulnerability. Due to input validation, unauthorized users can take advantage of this vulnerability to control the user terminal system. | ||
| CVE-2018-7081 | Cri | 0.64 | 9.8 | 0.06 | Sep 13, 2019 | A remote code execution vulnerability is present in network-listening components in some versions of ArubaOS. An attacker with the ability to transmit specially-crafted IP traffic to a mobility controller could exploit this vulnerability and cause a process crash or to execute… | ||
| CVE-2015-9351 | Cri | 0.64 | 9.8 | 0.03 | Aug 27, 2019 | The feed-them-social plugin before 1.7.0 for WordPress has possible shortcode execution in the Facebook Feeds load more button. | ||
| CVE-2019-1581 | Cri | 0.64 | 9.8 | 0.03 | Aug 23, 2019 | A remote code execution vulnerability in the PAN-OS SSH device management interface that can lead to unauthenticated remote users with network access to the SSH management interface gaining root access to PAN-OS. This issue affects PAN-OS 7.1 versions prior to 7.1.24-h1, 7.1.25;… | ||
| CVE-2013-7483 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The slidedeck2 plugin before 2.3.5 for WordPress has file inclusion. | ||
| CVE-2016-10930 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via a ticket number. | ||
| CVE-2018-20985 | Cri | 0.64 | 9.8 | 0.08 | Aug 22, 2019 | The wp-payeezy-pay plugin before 2.98 for WordPress has local file inclusion in pay.php, donate.php, donate-rec, and pay-rec. | ||
| CVE-2014-10384 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The memphis-documents-library plugin before 3.0 for WordPress has Local File Inclusion. | ||
| CVE-2014-10383 | Cri | 0.64 | 9.8 | 0.03 | Aug 22, 2019 | The memphis-documents-library plugin before 3.0 for WordPress has Remote File Inclusion. | ||
| CVE-2018-20973 | Cri | 0.64 | 9.8 | 0.02 | Aug 16, 2019 | The companion-auto-update plugin before 3.2.1 for WordPress has local file inclusion. |
- risk 0.64cvss 9.8epss 0.02
Chicken before 4.8.0 is susceptible to algorithmic complexity attacks related to hash table collisions.
- risk 0.64cvss 9.8epss 0.03
yum does not properly handle bad metadata, which allows an attacker to cause a denial of service and possibly have other unspecified impact via a Trojan horse file in the metadata of a remote repository.
- risk 0.64cvss 9.8epss 0.02
Transmission before 1.92 allows an attacker to cause a denial of service (crash) or possibly have other unspecified impact via a large number of tr arguments in a magnet link.
- risk 0.64cvss 9.8epss 0.02
qtparted has insecure library loading which may allow arbitrary code execution
- risk 0.64cvss 9.8epss 0.02
The sr_freecap (aka freeCap CAPTCHA) extension 2.4.5 and below and 2.5.2 and below for TYPO3 fails to sanitize user input, which allows execution of arbitrary Extbase actions, resulting in Remote Code Execution.
- risk 0.64cvss 9.8epss 0.01
A security vulnerability exists in the Zingbox Inspector versions 1.294 and earlier, that could allow an attacker to supply an invalid software update image to the Zingbox Inspector.
- risk 0.64cvss 9.8epss 0.04
tcpdump before 4.9.3 mishandles the printing of SMB data (issue 2 of 2).
- risk 0.64cvss 9.8epss 0.04
tcpdump before 4.9.3 mishandles the printing of SMB data (issue 1 of 2).
- risk 0.64cvss 9.8epss 0.02
In JetBrains UpSource versions before 2018.2 build 1293, there is credential disclosure via RPC commands.
- risk 0.64cvss 9.8epss 0.01
Lack of check of address range received from firmware response allows modem to respond arbitrary pages into its address range which can compromise HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice…
- risk 0.64cvss 9.8epss 0.01
All versions up to V81511329.1008 of ZTE ZXV10 B860A products are impacted by input validation vulnerability. Due to input validation, unauthorized users can take advantage of this vulnerability to control the user terminal system.
- risk 0.64cvss 9.8epss 0.06
A remote code execution vulnerability is present in network-listening components in some versions of ArubaOS. An attacker with the ability to transmit specially-crafted IP traffic to a mobility controller could exploit this vulnerability and cause a process crash or to execute…
- risk 0.64cvss 9.8epss 0.03
The feed-them-social plugin before 1.7.0 for WordPress has possible shortcode execution in the Facebook Feeds load more button.
- risk 0.64cvss 9.8epss 0.03
A remote code execution vulnerability in the PAN-OS SSH device management interface that can lead to unauthenticated remote users with network access to the SSH management interface gaining root access to PAN-OS. This issue affects PAN-OS 7.1 versions prior to 7.1.24-h1, 7.1.25;…
- risk 0.64cvss 9.8epss 0.02
The slidedeck2 plugin before 2.3.5 for WordPress has file inclusion.
- risk 0.64cvss 9.8epss 0.02
The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via a ticket number.
- risk 0.64cvss 9.8epss 0.08
The wp-payeezy-pay plugin before 2.98 for WordPress has local file inclusion in pay.php, donate.php, donate-rec, and pay-rec.
- risk 0.64cvss 9.8epss 0.02
The memphis-documents-library plugin before 3.0 for WordPress has Local File Inclusion.
- risk 0.64cvss 9.8epss 0.03
The memphis-documents-library plugin before 3.0 for WordPress has Remote File Inclusion.
- risk 0.64cvss 9.8epss 0.02
The companion-auto-update plugin before 3.2.1 for WordPress has local file inclusion.