VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,428)

page 265 of 672
  • CVE-2024-24695MedFeb 14, 2024
    risk 0.44cvss 6.8epss 0.01

    Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to conduct a disclosure of information via network access.

  • CVE-2024-21319MedJan 9, 2024
    risk 0.44cvss 6.8epss 0.03

    Microsoft Identity Denial of service vulnerability

  • CVE-2023-39251MedDec 22, 2023
    risk 0.44cvss 6.7epss 0.00

    Dell BIOS contains an Improper Input Validation vulnerability. A local malicious user with high privileges could potentially exploit this vulnerability in order to corrupt memory on the system.

  • CVE-2023-32727MedDec 18, 2023
    risk 0.44cvss 6.8epss 0.01

    An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious command inside it to execute arbitrary code on the current Zabbix server.

  • CVE-2023-43570MedNov 8, 2023
    risk 0.44cvss 6.7epss 0.00

    A potential vulnerability was reported in the SMI callback function of the OemSmi driver that may allow a local attacker with elevated permissions to execute arbitrary code.

  • CVE-2023-5763MedNov 3, 2023
    risk 0.44cvss 6.8epss 0.01

    In Eclipse Glassfish 5 or 6, running with old versions of JDK (lower than 6u211, or < 7u201, or < 8u191), allows remote attackers to load malicious code on the server via access to insecure ORB listeners.

  • CVE-2023-4197HigNov 1, 2023
    risk 0.44cvss 7.5epss 0.33

    Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing an attacker to inject and evaluate arbitrary PHP code.

  • CVE-2022-4574MedOct 30, 2023
    risk 0.44cvss 6.7epss 0.00

    An SMI handler input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to execute arbitrary code.  

  • CVE-2022-4573MedOct 30, 2023
    risk 0.44cvss 6.7epss 0.00

    An SMI handler input validation vulnerability in the ThinkPad X1 Fold Gen 1 could allow an attacker with local access and elevated privileges to execute arbitrary code.

  • CVE-2022-48189MedOct 30, 2023
    risk 0.44cvss 6.7epss 0.00

    An SMM driver input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to execute arbitrary code.

  • CVE-2021-26736MedOct 23, 2023
    risk 0.44cvss 6.7epss 0.00

    Multiple vulnerabilities in the Zscaler Client Connector Installer and Uninstaller for Windows prior to 3.6 allowed execution of binaries from a low privileged path. A local adversary may be able to execute code with SYSTEM privileges.

  • CVE-2023-45805HigOct 20, 2023
    risk 0.44cvss 7.8epss 0.01

    pdm is a Python package and dependency manager supporting the latest PEP standards. It's possible to craft a malicious `pdm.lock` file that could allow e.g. an insider or a malicious open source project to appear to depend on a trusted PyPI project, but actually install another…

  • CVE-2023-36697MedOct 10, 2023
    risk 0.44cvss 6.8epss 0.02

    Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

  • CVE-2023-32827MedOct 2, 2023
    risk 0.44cvss 6.7epss 0.00

    In camera middleware, there is a possible out of bounds write due to a missing input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07993539; Issue ID:…

  • CVE-2023-32826MedOct 2, 2023
    risk 0.44cvss 6.7epss 0.00

    In camera middleware, there is a possible out of bounds write due to a missing input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07993539; Issue ID:…

  • CVE-2023-31010MedSep 20, 2023
    risk 0.44cvss 6.8epss 0.01

    NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause improper input validation. A successful exploit of this vulnerability may lead to escalation of privileges, information disclosure, and denial of service.

  • CVE-2023-4680MedSep 15, 2023
    risk 0.44cvss 6.8epss 0.00

    HashiCorp Vault and Vault Enterprise transit secrets engine allowed authorized users to specify arbitrary nonces, even with convergent encryption disabled. The encrypt endpoint, in combination with an offline attack, could be used to decrypt arbitrary ciphertext and potentially…

  • CVE-2023-30712MedSep 6, 2023
    risk 0.44cvss 6.8epss 0.00

    Improper input validation in Settings Suggestions prior to SMR Sep-2023 Release 1 allows attackers to launch arbitrary activity.

  • CVE-2023-32811MedSep 4, 2023
    risk 0.44cvss 6.7epss 0.00

    In connectivity system driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07929848; Issue ID:…

  • CVE-2023-39137HigAug 30, 2023
    risk 0.44cvss 7.8epss 0.00

    An issue in Archive v3.3.7 allows attackers to spoof zip filenames which can lead to inconsistent filename parsing.