VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,314)

page 26 of 666
  • CVE-2019-9845CriApr 16, 2019
    risk 0.64cvss 9.8epss 0.03

    madskristensen Miniblog.Core through 2019-01-16 allows remote attackers to execute arbitrary ASPX code via an IMG element with a data: URL, because SaveFilesToDisk in Controllers/BlogController.cs writes a decoded base64 string to a file without validating the extension.

  • CVE-2019-0786CriApr 9, 2019
    risk 0.64cvss 9.8epss 0.07

    An elevation of privilege vulnerability exists in the Microsoft Server Message Block (SMB) Server when an attacker with valid credentials attempts to open a specially crafted file over the SMB protocol on the same machine, aka 'SMB Server Elevation of Privilege Vulnerability'.

  • CVE-2019-11014CriApr 8, 2019
    risk 0.64cvss 9.8epss 0.02

    The VStarCam vstc.vscam.client library and vstc.vscam shared object, as used in the Eye4 application (for Android, iOS, and Windows), do not prevent spoofing of the camera server. An attacker can create a fake camera server that listens for the client looking for a camera on the…

  • CVE-2014-9186CriApr 8, 2019
    risk 0.64cvss 9.8epss 0.04

    A file inclusion vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x before R430.2, which could lead to accepting an arbitrary file into the function, and potential information disclosure or remote code…

  • CVE-2018-4353CriApr 3, 2019
    risk 0.64cvss 9.8epss 0.01

    A configuration issue was addressed with additional restrictions. This issue affected versions prior to macOS Mojave 10.14.

  • CVE-2018-4295CriApr 3, 2019
    risk 0.64cvss 9.8epss 0.01

    An input validation issue was addressed with improved input validation. This issue affected versions prior to macOS Mojave 10.14.

  • CVE-2017-7342CriMar 25, 2019
    risk 0.64cvss 9.8epss 0.01

    A weak password recovery process vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to execute unauthorized code or commands via a hidden Close button

  • CVE-2018-13904CriFeb 25, 2019
    risk 0.64cvss 9.8epss 0.01

    Improper input validation in SCM handler to access storage in TZ can lead to unauthorized access in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in versions MDM9206,…

  • CVE-2018-12549CriFeb 11, 2019
    risk 0.64cvss 9.8epss 0.02

    In Eclipse OpenJ9 version 0.11.0, the OpenJ9 JIT compiler may incorrectly omit a null check on the receiver object of an Unsafe call when accelerating it.

  • CVE-2018-12547CriFeb 11, 2019
    risk 0.64cvss 9.8epss 0.03

    In Eclipse OpenJ9, prior to the 0.12.0 release, the jio_snprintf() and jio_vsnprintf() native methods ignored the length parameter. This affects existing APIs that called the functions to exceed the allocated buffer. This functions were not directly callable by non-native user…

  • CVE-2018-20771CriFeb 10, 2019
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is unauthenticated Remote Command Execution.

  • CVE-2019-7412CriFeb 5, 2019
    risk 0.64cvss 9.8epss 0.03

    The PS PHPCaptcha WP plugin before v1.2.0 for WordPress mishandles sanitization of input values.

  • CVE-2018-4254CriJan 11, 2019
    risk 0.64cvss 9.8epss 0.01

    In macOS High Sierra before 10.13.5, an input validation issue existed in the kernel. This issue was addressed with improved input validation.

  • CVE-2017-1002157CriJan 10, 2019
    risk 0.64cvss 9.8epss 0.03

    modulemd 1.3.1 and earlier uses an unsafe function for processing externally provided data, leading to remote code execution.

  • CVE-2018-5203CriDec 28, 2018
    risk 0.64cvss 9.8epss 0.02

    DEXTUploadX5 version Between 1.0.0.0 and 2.2.0.0 contains a vulnerability that could allow remote attacker to download and execute remote arbitrary file by setting the arguments to the activex method. this can be leveraged for code execution.

  • CVE-2018-15715CriNov 30, 2018
    risk 0.64cvss 9.8epss 0.03

    Zoom clients on Windows (before version 4.1.34814.1119), Mac OS (before version 4.1.34801.1116), and Linux (2.4.129780.0915 and below) are vulnerable to unauthorized message processing. A remote unauthenticated attacker can spoof UDP messages from a meeting attendee or Zoom…

  • CVE-2017-18318CriNov 28, 2018
    risk 0.64cvss 9.8epss 0.01

    Missing validation check on CRL issuer name in Snapdragon Automobile, Snapdragon Mobile in versions MSM8996AU, SD 410/12, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 810, SD 820, SD 820A.

  • CVE-2018-13315CriNov 26, 2018
    risk 0.64cvss 9.8epss 0.02

    Incorrect access control in formPasswordSetup in TOTOLINK A3002RU version 1.0.8 allows attackers to change the admin user's password via an unauthenticated POST request.

  • CVE-2018-19531CriNov 26, 2018
    risk 0.64cvss 9.8epss 0.05

    HTTL (aka Hyper-Text Template Language) through 1.0.11 allows remote command execution because the decodeXml function uses java.beans.XMLEncoder unsafely when configured without an xml.codec= setting.

  • CVE-2018-19530CriNov 26, 2018
    risk 0.64cvss 9.8epss 0.05

    HTTL (aka Hyper-Text Template Language) through 1.0.11 allows remote command execution because the decodeXml function uses XStream unsafely when configured with an xml.codec=httl.spi.codecs.XstreamCodec setting.