CWE-20
Improper Input Validation
Description
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9
CVEs mapped to this weakness (13,387)
page 294 of 670| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-36706 | Med | 0.42 | 6.5 | 0.02 | Oct 10, 2023 | Windows Deployment Services Information Disclosure Vulnerability | ||
| CVE-2023-36566 | Med | 0.42 | 6.5 | 0.03 | Oct 10, 2023 | Microsoft Common Data Model SDK Denial of Service Vulnerability | ||
| CVE-2023-42508 | Med | 0.42 | 6.5 | 0.00 | Oct 3, 2023 | JFrog Artifactory prior to version 7.66.0 is vulnerable to specific endpoint abuse with a specially crafted payload, which can lead to unauthenticated users being able to send emails with manipulated email body. | ||
| CVE-2023-39410 | Hig | 0.42 | 7.5 | 0.02 | Sep 29, 2023 | When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should… | ||
| CVE-2023-42805 | Hig | 0.42 | 7.5 | 0.01 | Sep 21, 2023 | quinn-proto is a state machine for the QUIC transport protocol. Prior to versions 0.9.5 and 0.10.5, receiving unknown QUIC frames in a QUIC packet could result in a panic. The problem has been fixed in 0.9.5 and 0.10.5 maintenance releases. | ||
| CVE-2023-39208 | Med | 0.42 | 6.5 | 0.01 | Sep 12, 2023 | Improper input validation in Zoom Desktop Client for Linux before version 5.15.10 may allow an unauthenticated user to conduct a denial of service via network access. | ||
| CVE-2023-34317 | Med | 0.42 | 6.5 | 0.01 | Sep 5, 2023 | An improper input validation vulnerability exists in the OAS Engine User Creation functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to unexpected data in the configuration. An attacker can send a sequence… | ||
| CVE-2023-4698 | Hig | 0.42 | 7.5 | 0.01 | Sep 1, 2023 | Improper Input Validation in GitHub repository usememos/memos prior to 0.13.2. | ||
| CVE-2023-39553 | Hig | 0.42 | 7.5 | 0.02 | Aug 11, 2023 | Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider. Apache Airflow Drill Provider is affected by a vulnerability that allows an attacker to pass in malicious parameters when establishing a connection with DrillHook giving an… | ||
| CVE-2023-38254 | Med | 0.42 | 6.5 | 0.02 | Aug 8, 2023 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | ||
| CVE-2023-36893 | Med | 0.42 | 6.5 | 0.02 | Aug 8, 2023 | Microsoft Outlook Spoofing Vulnerability | ||
| CVE-2023-35377 | Med | 0.42 | 6.5 | 0.02 | Aug 8, 2023 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | ||
| CVE-2023-35376 | Med | 0.42 | 6.5 | 0.02 | Aug 8, 2023 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | ||
| CVE-2023-21647 | Med | 0.42 | 6.5 | 0.00 | Aug 8, 2023 | Information disclosure in Bluetooth when an GATT packet is received due to improper input validation. | ||
| CVE-2023-37559 | Med | 0.42 | 6.5 | 0.01 | Aug 3, 2023 | After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, potentially leading to a… | ||
| CVE-2023-37558 | Med | 0.42 | 6.5 | 0.01 | Aug 3, 2023 | After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, potentially leading to a… | ||
| CVE-2023-37556 | Med | 0.42 | 6.5 | 0.01 | Aug 3, 2023 | In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a… | ||
| CVE-2023-37555 | Med | 0.42 | 6.5 | 0.01 | Aug 3, 2023 | In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a… | ||
| CVE-2023-37554 | Med | 0.42 | 6.5 | 0.01 | Aug 3, 2023 | In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a… | ||
| CVE-2023-37553 | Med | 0.42 | 6.5 | 0.01 | Aug 3, 2023 | In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a… |
- risk 0.42cvss 6.5epss 0.02
Windows Deployment Services Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.03
Microsoft Common Data Model SDK Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.00
JFrog Artifactory prior to version 7.66.0 is vulnerable to specific endpoint abuse with a specially crafted payload, which can lead to unauthenticated users being able to send emails with manipulated email body.
- risk 0.42cvss 7.5epss 0.02
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should…
- risk 0.42cvss 7.5epss 0.01
quinn-proto is a state machine for the QUIC transport protocol. Prior to versions 0.9.5 and 0.10.5, receiving unknown QUIC frames in a QUIC packet could result in a panic. The problem has been fixed in 0.9.5 and 0.10.5 maintenance releases.
- risk 0.42cvss 6.5epss 0.01
Improper input validation in Zoom Desktop Client for Linux before version 5.15.10 may allow an unauthenticated user to conduct a denial of service via network access.
- risk 0.42cvss 6.5epss 0.01
An improper input validation vulnerability exists in the OAS Engine User Creation functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to unexpected data in the configuration. An attacker can send a sequence…
- risk 0.42cvss 7.5epss 0.01
Improper Input Validation in GitHub repository usememos/memos prior to 0.13.2.
- risk 0.42cvss 7.5epss 0.02
Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider. Apache Airflow Drill Provider is affected by a vulnerability that allows an attacker to pass in malicious parameters when establishing a connection with DrillHook giving an…
- risk 0.42cvss 6.5epss 0.02
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.02
Microsoft Outlook Spoofing Vulnerability
- risk 0.42cvss 6.5epss 0.02
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.02
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.00
Information disclosure in Bluetooth when an GATT packet is received due to improper input validation.
- risk 0.42cvss 6.5epss 0.01
After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, potentially leading to a…
- risk 0.42cvss 6.5epss 0.01
After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, potentially leading to a…
- risk 0.42cvss 6.5epss 0.01
In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a…
- risk 0.42cvss 6.5epss 0.01
In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a…
- risk 0.42cvss 6.5epss 0.01
In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a…
- risk 0.42cvss 6.5epss 0.01
In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a…