VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,428)

page 264 of 672
  • CVE-2024-22065MedOct 29, 2024
    risk 0.44cvss 6.8epss 0.01

    There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.

  • CVE-2024-43526MedOct 8, 2024
    risk 0.44cvss 6.8epss 0.01

    Windows Mobile Broadband Driver Remote Code Execution Vulnerability

  • CVE-2024-43525MedOct 8, 2024
    risk 0.44cvss 6.8epss 0.01

    Windows Mobile Broadband Driver Remote Code Execution Vulnerability

  • CVE-2024-43523MedOct 8, 2024
    risk 0.44cvss 6.8epss 0.01

    Windows Mobile Broadband Driver Remote Code Execution Vulnerability

  • CVE-2024-25008MedAug 16, 2024
    risk 0.44cvss 6.8epss 0.00

    Ericsson RAN Compute and Site Controller 6610 contains a vulnerability in the Control System where Improper Input Validation can lead to arbitrary code execution, for example to obtain a Linux Shell with the same privileges as the attacker. The attacker would require elevated…

  • CVE-2023-24062MedAug 8, 2024
    risk 0.44cvss 6.8epss 0.00

    Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR12, 4.0.0 SR04, 4.1.0 SR02, and 4.2.0 SR01 fails to validate the directory structure of the root file system during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able to…

  • CVE-2024-27386MedJul 9, 2024
    risk 0.44cvss 6.7epss 0.00

    A vulnerability was discovered in the slsi_handle_nan_rx_event_log_ind function in Samsung Mobile Processor Exynos 1380 and Exynos 1480 related to no input validation check on tag_len for tx coming from userspace, which can lead to heap overwrite.

  • CVE-2024-27385MedJul 9, 2024
    risk 0.44cvss 6.7epss 0.00

    A vulnerability was discovered in the slsi_handle_nan_rx_event_log_ind function in Samsung Mobile Processor Exynos 1380 and Exynos 1480 related to no input validation check on tag_len for rx coming from userspace, which can lead to heap overwrite.

  • CVE-2024-34693MedJun 20, 2024
    risk 0.44cvss 6.8epss 0.02

    Improper Input Validation vulnerability in Apache Superset, allows for an authenticated attacker to create a MariaDB connection with local_infile enabled. If both the MariaDB server (off by default) and the local mysql client on the web server are set to allow for local infile,…

  • CVE-2024-30002MedMay 14, 2024
    risk 0.44cvss 6.8epss 0.01

    Windows Mobile Broadband Driver Remote Code Execution Vulnerability

  • CVE-2024-29998MedMay 14, 2024
    risk 0.44cvss 6.8epss 0.01

    Windows Mobile Broadband Driver Remote Code Execution Vulnerability

  • CVE-2024-20056MedMay 6, 2024
    risk 0.44cvss 6.7epss 0.00

    In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08528185; Issue ID: ALPS08528185.

  • CVE-2023-36505MedApr 17, 2024
    risk 0.44cvss 6.8epss 0.01

    Improper Input Validation vulnerability in Saturday Drive Ninja Forms Contact Form.This issue affects Ninja Forms Contact Form : from n/a through 3.6.24.

  • CVE-2024-28897MedApr 9, 2024
    risk 0.44cvss 6.8epss 0.01

    Secure Boot Security Feature Bypass Vulnerability

  • CVE-2024-26253MedApr 9, 2024
    risk 0.44cvss 6.8epss 0.01

    Windows rndismp6.sys Remote Code Execution Vulnerability

  • CVE-2024-31212MedApr 4, 2024
    risk 0.44cvss 6.7epss 0.01

    InstantCMS is a free and open source content management system. A SQL injection vulnerability affects instantcms v2.16.2 in which an attacker with administrative privileges can cause the application to execute unauthorized SQL code. The vulnerability exists in index_chart_data…

  • CVE-2023-32633MedMar 14, 2024
    risk 0.44cvss 6.7epss 0.00

    Improper input validation in the Intel(R) CSME installer software before version 2328.5.5.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-24549HigMar 13, 2024
    risk 0.44cvss 7.5epss 0.23

    Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated HTTP/2 stream was not reset until after all of the headers…

  • CVE-2024-27612MedMar 8, 2024
    risk 0.44cvss 6.2epss 0.11

    Numbas editor before 7.3 mishandles editing of themes and extensions.

  • CVE-2024-24696MedFeb 14, 2024
    risk 0.44cvss 6.8epss 0.01

    Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to conduct a disclosure of information via network access.