VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,387)

page 295 of 670
  • CVE-2023-37552MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a…

  • CVE-2023-37550MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a…

  • CVE-2023-37549MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a…

  • CVE-2023-37548MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a…

  • CVE-2023-37547MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a…

  • CVE-2023-37546MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a…

  • CVE-2023-37545MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    In multiple Codesys products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a…

  • CVE-2022-4925MedJul 29, 2023
    risk 0.42cvss 6.5epss 0.01

    Insufficient validation of untrusted input in QUIC in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to perform header splitting via malicious network traffic. (Chromium security severity: Low)

  • CVE-2022-4911MedJul 29, 2023
    risk 0.42cvss 6.5epss 0.01

    Insufficient data validation in DevTools in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2023-38502MedJul 25, 2023
    risk 0.42cvss 6.5epss 0.01

    TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to version 3.0.7.1, TDengine DataBase crashes on UDF nested query. This issue affects TDengine Databases which let users connect and run arbitrary queries. Version 3.0.7.1 has a…

  • CVE-2023-35336MedJul 11, 2023
    risk 0.42cvss 6.5epss 0.01

    Windows MSHTML Platform Security Feature Bypass Vulnerability

  • CVE-2023-32037MedJul 11, 2023
    risk 0.42cvss 6.5epss 0.01

    Windows Layer-2 Bridge Network Driver Information Disclosure Vulnerability

  • CVE-2023-28955MedJul 10, 2023
    risk 0.42cvss 6.5epss 0.01

    IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 could allow an authenticated user send a specially crafted request that could cause a denial of service. IBM X-Force ID: 251704.

  • CVE-2023-34150MedJul 5, 2023
    risk 0.42cvss 6.5epss 0.01

    ** UNSUPPORTED WHEN ASSIGNED ** Use of TikaEncodingDetector in Apache Any23 can cause excessive memory usage.

  • CVE-2023-34422MedJun 26, 2023
    risk 0.42cvss 6.5epss 0.00

    A valid, authenticated LXCA user with elevated privileges may be able to delete folders in the LXCA filesystem through a specifically crafted web API call due to insufficient input validation.

  • CVE-2023-34421MedJun 26, 2023
    risk 0.42cvss 6.5epss 0.00

    A valid, authenticated LXCA user with elevated privileges may be able to replace filesystem data through a specifically crafted web API call due to insufficient input validation.

  • CVE-2023-30631HigJun 14, 2023
    risk 0.42cvss 7.5epss 0.02

    Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.  The configuration option proxy.config.http.push_method_enabled didn't function.  However, by default the PUSH method is blocked in the ip_allow configuration file.This issue affects…

  • CVE-2023-24937MedJun 14, 2023
    risk 0.42cvss 6.5epss 0.02

    Windows CryptoAPI Denial of Service Vulnerability

  • CVE-2023-32032MedJun 14, 2023
    risk 0.42cvss 6.5epss 0.01

    .NET and Visual Studio Elevation of Privilege Vulnerability

  • CVE-2022-47392MedMay 15, 2023
    risk 0.42cvss 6.5epss 0.01

    An authenticated, remote attacker may use a improper input validation vulnerability in the CmpApp/CmpAppBP/CmpAppForce Components of multiple CODESYS products in multiple versions to read from an invalid address which can lead to a denial-of-service condition.