VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,387)

page 294 of 670
  • CVE-2023-36706MedOct 10, 2023
    risk 0.42cvss 6.5epss 0.02

    Windows Deployment Services Information Disclosure Vulnerability

  • CVE-2023-36566MedOct 10, 2023
    risk 0.42cvss 6.5epss 0.03

    Microsoft Common Data Model SDK Denial of Service Vulnerability

  • CVE-2023-42508MedOct 3, 2023
    risk 0.42cvss 6.5epss 0.00

    JFrog Artifactory prior to version 7.66.0 is vulnerable to specific endpoint abuse with a specially crafted payload, which can lead to unauthenticated users being able to send emails with manipulated email body.

  • CVE-2023-39410HigSep 29, 2023
    risk 0.42cvss 7.5epss 0.02

    When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should…

  • CVE-2023-42805HigSep 21, 2023
    risk 0.42cvss 7.5epss 0.01

    quinn-proto is a state machine for the QUIC transport protocol. Prior to versions 0.9.5 and 0.10.5, receiving unknown QUIC frames in a QUIC packet could result in a panic. The problem has been fixed in 0.9.5 and 0.10.5 maintenance releases.

  • CVE-2023-39208MedSep 12, 2023
    risk 0.42cvss 6.5epss 0.01

    Improper input validation in Zoom Desktop Client for Linux before version 5.15.10 may allow an unauthenticated user to conduct a denial of service via network access.

  • CVE-2023-34317MedSep 5, 2023
    risk 0.42cvss 6.5epss 0.01

    An improper input validation vulnerability exists in the OAS Engine User Creation functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to unexpected data in the configuration. An attacker can send a sequence…

  • CVE-2023-4698HigSep 1, 2023
    risk 0.42cvss 7.5epss 0.01

    Improper Input Validation in GitHub repository usememos/memos prior to 0.13.2.

  • CVE-2023-39553HigAug 11, 2023
    risk 0.42cvss 7.5epss 0.02

    Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider. Apache Airflow Drill Provider is affected by a vulnerability that allows an attacker to pass in malicious parameters when establishing a connection with DrillHook giving an…

  • CVE-2023-38254MedAug 8, 2023
    risk 0.42cvss 6.5epss 0.02

    Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

  • CVE-2023-36893MedAug 8, 2023
    risk 0.42cvss 6.5epss 0.02

    Microsoft Outlook Spoofing Vulnerability

  • CVE-2023-35377MedAug 8, 2023
    risk 0.42cvss 6.5epss 0.02

    Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

  • CVE-2023-35376MedAug 8, 2023
    risk 0.42cvss 6.5epss 0.02

    Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

  • CVE-2023-21647MedAug 8, 2023
    risk 0.42cvss 6.5epss 0.00

    Information disclosure in Bluetooth when an GATT packet is received due to improper input validation.

  • CVE-2023-37559MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, potentially leading to a…

  • CVE-2023-37558MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, potentially leading to a…

  • CVE-2023-37556MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a…

  • CVE-2023-37555MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a…

  • CVE-2023-37554MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a…

  • CVE-2023-37553MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a…