VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,428)

page 257 of 672
  • CVE-2022-38385HigNov 15, 2022
    risk 0.46cvss 7.1epss 0.01

    IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.2.0 could allow an authenticated user to obtain highly sensitive information or perform unauthorized actions due to improper input validation. IBM X-Force ID: 233777.

  • CVE-2022-39880HigNov 9, 2022
    risk 0.46cvss 7.1epss 0.00

    Improper input validation vulnerability in DualOutFocusViewer prior to SMR Nov-2022 Release 1 allows local attacker to perform an arbitrary code execution.

  • CVE-2022-20822HigOct 26, 2022
    risk 0.46cvss 7.1epss 0.01

    A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read and delete files on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker…

  • CVE-2022-32797HigSep 23, 2022
    risk 0.46cvss 7.1epss 0.01

    This issue was addressed with improved checks. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. Processing a maliciously crafted AppleScript binary may result in unexpected termination or disclosure of process memory.

  • CVE-2021-4204HigAug 24, 2022
    risk 0.46cvss 7.1epss 0.01

    An out-of-bounds (OOB) memory access flaw was found in the Linux kernel's eBPF due to an Improper Input Validation. This flaw allows a local attacker with a special privilege to crash the system or leak internal information.

  • CVE-2022-2385HigJul 12, 2022
    risk 0.46cvss 8.1epss 0.01

    A security issue was discovered in aws-iam-authenticator where an allow-listed IAM identity may be able to modify their username and escalate privileges.

  • CVE-2021-30338HigJun 14, 2022
    risk 0.46cvss 7.1epss 0.00

    Improper input validation in TrustZone memory transfer interface can lead to information disclosure in Snapdragon Compute

  • CVE-2021-26370HigMay 10, 2022
    risk 0.46cvss 7.1epss 0.00

    Improper validation of destination address in SVC_LOAD_FW_IMAGE_BY_INSTANCE and SVC_LOAD_BINARY_BY_ATTRIB in a malicious UApp or ABL may allow an attacker to overwrite arbitrary bootloader memory with SPI ROM contents resulting in a loss of integrity and availability.

  • CVE-2021-26618HigFeb 18, 2022
    risk 0.46cvss 7.1epss 0.01

    An improper input validation leading to arbitrary file creation was discovered in ToWord of ToOffice. Remote attackers use this vulnerability to execute arbitrary file included malicious code.

  • CVE-2022-23624HigFeb 7, 2022
    risk 0.46cvss 8.1epss 0.01

    Frourio-express is a minimal full stack framework, for TypeScript. Frourio-express users who uses frourio-express version prior to v0.26.0 and integration with class-validator through `validators/` folder are subject to a input validation vulnerability. Validators do not work…

  • CVE-2022-23623HigFeb 7, 2022
    risk 0.46cvss 8.1epss 0.01

    Frourio is a full stack framework, for TypeScript. Frourio users who uses frourio version prior to v0.26.0 and integration with class-validator through `validators/` folder are subject to a input validation vulnerability. Validators do not work properly for request bodies and…

  • CVE-2022-21646HigJan 11, 2022
    risk 0.46cvss 8.1epss 0.01

    SpiceDB is a database system for managing security-critical application permissions. Any user making use of a wildcard relationship under the right hand branch of an `exclusion` or within an `intersection` operation will see `Lookup`/`LookupResources` return a resource as…

  • CVE-2021-30278HigJan 3, 2022
    risk 0.46cvss 7.1epss 0.00

    Improper input validation in TrustZone memory transfer interface can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and…

  • CVE-2020-12946HigNov 16, 2021
    risk 0.46cvss 7.1epss 0.00

    Insufficient input validation in ASP firmware for discrete TPM commands could allow a potential loss of integrity and denial of service.

  • CVE-2021-31360HigOct 19, 2021
    risk 0.46cvss 7.1epss 0.00

    An improper privilege management vulnerability in the Juniper Networks Junos OS and Junos OS Evolved command-line interpreter (CLI) allows a low-privileged user to overwrite local files as root, possibly leading to a system integrity issue or Denial of Service (DoS). Depending…

  • CVE-2021-42257HigOct 11, 2021
    risk 0.46cvss 7.1epss 0.00

    check_smart before 6.9.1 allows unintended drive access by an unprivileged user because it only checks for a substring match of a device path (the /dev/bus substring and a number), aka an unanchored regular expression.

  • CVE-2021-1110HigAug 11, 2021
    risk 0.46cvss 7.1epss 0.00

    NVIDIA Linux kernel distributions on Jetson Xavier contain a vulnerability in camera firmware where a user can change input data after validation, which may lead to complete denial of service and serious data corruption of all kernel components.

  • CVE-2020-7862HigJun 24, 2021
    risk 0.46cvss 7.0epss 0.01

    A vulnerability in agent program of HelpU remote control solution could allow an authenticated remote attacker to execute arbitrary commands This vulnerability is due to insufficient input santization when communicating customer process.

  • CVE-2021-25410HigJun 11, 2021
    risk 0.46cvss 7.1epss 0.00

    Improper access control of a component in CallBGProvider prior to SMR JUN-2021 Release 1 allows local attackers to access arbitrary files with an escalated privilege.

  • CVE-2021-32642HigMay 28, 2021
    risk 0.46cvss 7.0epss 0.01

    radsecproxy is a generic RADIUS proxy that supports both UDP and TLS (RadSec) RADIUS transports. Missing input validation in radsecproxy's `naptr-eduroam.sh` and `radsec-dynsrv.sh` scripts can lead to configuration injection via crafted radsec peer discovery DNS records. Users…