CWE-20
Improper Input Validation
Description
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9
CVEs mapped to this weakness (13,387)
page 295 of 670| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-37552 | Med | 0.42 | 6.5 | 0.01 | Aug 3, 2023 | In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a… | ||
| CVE-2023-37550 | Med | 0.42 | 6.5 | 0.01 | Aug 3, 2023 | In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a… | ||
| CVE-2023-37549 | Med | 0.42 | 6.5 | 0.01 | Aug 3, 2023 | In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a… | ||
| CVE-2023-37548 | Med | 0.42 | 6.5 | 0.01 | Aug 3, 2023 | In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a… | ||
| CVE-2023-37547 | Med | 0.42 | 6.5 | 0.01 | Aug 3, 2023 | In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a… | ||
| CVE-2023-37546 | Med | 0.42 | 6.5 | 0.01 | Aug 3, 2023 | In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a… | ||
| CVE-2023-37545 | Med | 0.42 | 6.5 | 0.01 | Aug 3, 2023 | In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a… | ||
| CVE-2022-4925 | Med | 0.42 | 6.5 | 0.01 | Jul 29, 2023 | Insufficient validation of untrusted input in QUIC in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to perform header splitting via malicious network traffic. (Chromium security severity: Low) | ||
| CVE-2022-4911 | Med | 0.42 | 6.5 | 0.01 | Jul 29, 2023 | Insufficient data validation in DevTools in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low) | ||
| CVE-2023-38502 | Med | 0.42 | 6.5 | 0.01 | Jul 25, 2023 | TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to version 3.0.7.1, TDengine DataBase crashes on UDF nested query. This issue affects TDengine Databases which let users connect and run arbitrary queries. Version 3.0.7.1 has a… | ||
| CVE-2023-35336 | Med | 0.42 | 6.5 | 0.01 | Jul 11, 2023 | Windows MSHTML Platform Security Feature Bypass Vulnerability | ||
| CVE-2023-32037 | Med | 0.42 | 6.5 | 0.01 | Jul 11, 2023 | Windows Layer-2 Bridge Network Driver Information Disclosure Vulnerability | ||
| CVE-2023-28955 | Med | 0.42 | 6.5 | 0.01 | Jul 10, 2023 | IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 could allow an authenticated user send a specially crafted request that could cause a denial of service. IBM X-Force ID: 251704. | ||
| CVE-2023-34150 | Med | 0.42 | 6.5 | 0.01 | Jul 5, 2023 | ** UNSUPPORTED WHEN ASSIGNED ** Use of TikaEncodingDetector in Apache Any23 can cause excessive memory usage. | ||
| CVE-2023-34422 | Med | 0.42 | 6.5 | 0.00 | Jun 26, 2023 | A valid, authenticated LXCA user with elevated privileges may be able to delete folders in the LXCA filesystem through a specifically crafted web API call due to insufficient input validation. | ||
| CVE-2023-34421 | Med | 0.42 | 6.5 | 0.00 | Jun 26, 2023 | A valid, authenticated LXCA user with elevated privileges may be able to replace filesystem data through a specifically crafted web API call due to insufficient input validation. | ||
| CVE-2023-30631 | Hig | 0.42 | 7.5 | 0.02 | Jun 14, 2023 | Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server. The configuration option proxy.config.http.push_method_enabled didn't function. However, by default the PUSH method is blocked in the ip_allow configuration file.This issue affects… | ||
| CVE-2023-24937 | Med | 0.42 | 6.5 | 0.02 | Jun 14, 2023 | Windows CryptoAPI Denial of Service Vulnerability | ||
| CVE-2023-32032 | Med | 0.42 | 6.5 | 0.01 | Jun 14, 2023 | .NET and Visual Studio Elevation of Privilege Vulnerability | ||
| CVE-2022-47392 | Med | 0.42 | 6.5 | 0.01 | May 15, 2023 | An authenticated, remote attacker may use a improper input validation vulnerability in the CmpApp/CmpAppBP/CmpAppForce Components of multiple CODESYS products in multiple versions to read from an invalid address which can lead to a denial-of-service condition. |
- risk 0.42cvss 6.5epss 0.01
In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a…
- risk 0.42cvss 6.5epss 0.01
In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a…
- risk 0.42cvss 6.5epss 0.01
In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a…
- risk 0.42cvss 6.5epss 0.01
In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a…
- risk 0.42cvss 6.5epss 0.01
In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a…
- risk 0.42cvss 6.5epss 0.01
In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a…
- risk 0.42cvss 6.5epss 0.01
In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a…
- risk 0.42cvss 6.5epss 0.01
Insufficient validation of untrusted input in QUIC in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to perform header splitting via malicious network traffic. (Chromium security severity: Low)
- risk 0.42cvss 6.5epss 0.01
Insufficient data validation in DevTools in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)
- risk 0.42cvss 6.5epss 0.01
TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to version 3.0.7.1, TDengine DataBase crashes on UDF nested query. This issue affects TDengine Databases which let users connect and run arbitrary queries. Version 3.0.7.1 has a…
- risk 0.42cvss 6.5epss 0.01
Windows MSHTML Platform Security Feature Bypass Vulnerability
- risk 0.42cvss 6.5epss 0.01
Windows Layer-2 Bridge Network Driver Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.01
IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 could allow an authenticated user send a specially crafted request that could cause a denial of service. IBM X-Force ID: 251704.
- risk 0.42cvss 6.5epss 0.01
** UNSUPPORTED WHEN ASSIGNED ** Use of TikaEncodingDetector in Apache Any23 can cause excessive memory usage.
- risk 0.42cvss 6.5epss 0.00
A valid, authenticated LXCA user with elevated privileges may be able to delete folders in the LXCA filesystem through a specifically crafted web API call due to insufficient input validation.
- risk 0.42cvss 6.5epss 0.00
A valid, authenticated LXCA user with elevated privileges may be able to replace filesystem data through a specifically crafted web API call due to insufficient input validation.
- risk 0.42cvss 7.5epss 0.02
Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server. The configuration option proxy.config.http.push_method_enabled didn't function. However, by default the PUSH method is blocked in the ip_allow configuration file.This issue affects…
- risk 0.42cvss 6.5epss 0.02
Windows CryptoAPI Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.01
.NET and Visual Studio Elevation of Privilege Vulnerability
- risk 0.42cvss 6.5epss 0.01
An authenticated, remote attacker may use a improper input validation vulnerability in the CmpApp/CmpAppBP/CmpAppForce Components of multiple CODESYS products in multiple versions to read from an invalid address which can lead to a denial-of-service condition.