VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,387)

page 310 of 670
  • CVE-2019-9348MedSep 27, 2019
    risk 0.42cvss 6.5epss 0.01

    In libstagefright, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID:…

  • CVE-2018-11782MedSep 26, 2019
    risk 0.42cvss 6.5epss 0.02

    In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a well-formed read-only request produces a particular answer. This can lead to disruption for users of the server.

  • CVE-2019-3760MedSep 11, 2019
    risk 0.42cvss 6.4epss 0.01

    The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a SQL Injection vulnerability in Workflow Architect. A remote authenticated malicious user could potentially exploit this vulnerability to execute SQL…

  • CVE-2019-16141HigSep 9, 2019
    risk 0.42cvss 7.5epss 0.02

    An issue was discovered in the once_cell crate before 1.0.1 for Rust. There is a panic during initialization of Lazy.

  • CVE-2019-12588MedSep 4, 2019
    risk 0.42cvss 6.5epss 0.01

    The client 802.11 mac implementation in Espressif ESP8266_NONOS_SDK 2.2.0 through 3.1.0 does not validate correctly the RSN AuthKey suite list count in beacon frames, probe responses, and association responses, which allows attackers in radio range to cause a denial of service…

  • CVE-2017-18589HigAug 26, 2019
    risk 0.42cvss 7.5epss 0.02

    An issue was discovered in the cookie crate before 0.7.6 for Rust. Large integers in the Max-Age of a cookie cause a panic.

  • CVE-2019-1984MedAug 21, 2019
    risk 0.42cvss 6.5epss 0.02

    A vulnerability in Cisco Enterprise Network Functions Virtualization Infrastructure Software (NFVIS) could allow an authenticated, remote attacker with administrator privileges to overwrite files on the underlying operating system (OS) of an affected device. The vulnerability is…

  • CVE-2019-10745HigAug 20, 2019
    risk 0.42cvss 7.5epss 0.01

    assign-deep is vulnerable to Prototype Pollution in versions before 0.4.8 and version 1.0.0. The function assign-deep could be tricked into adding or modifying properties of Object.prototype using either a constructor or a _proto_ payload.

  • CVE-2016-10807MedAug 7, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 57.9999.54 allows certain denial-of-service outcomes via /scripts/killpvhost (SEC-112).

  • CVE-2017-18482MedAug 5, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 62.0.4 allows resellers to use the WHM enqueue_transfer_item API for queueing non-rearrange modules (SEC-213).

  • CVE-2016-10775MedAug 5, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 60.0.25 allows arbitrary file-chown operations via reassign_post_terminate_cruft (SEC-173).

  • CVE-2016-10770MedAug 5, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 60.0.25 allows arbitrary file-overwrite operations during a Roundcube update (SEC-164).

  • CVE-2016-10768MedAug 5, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 60.0.25 allows file-overwrite operations during preparation for MySQL upgrades (SEC-161).

  • CVE-2017-18410MedAug 2, 2019
    risk 0.42cvss 6.5epss 0.01

    In cPanel before 67.9999.103, a user account's backup archive could contain all MySQL databases on the server (SEC-284).

  • CVE-2017-18409MedAug 2, 2019
    risk 0.42cvss 6.5epss 0.01

    In cPanel before 67.9999.103, the backup interface could return a backup archive with all MySQL databases (SEC-283).

  • CVE-2016-10842MedAug 1, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 11.54.0.4 allows certain file-read operations in bin/setup_global_spam_filter.pl (SEC-74).

  • CVE-2018-20883MedAug 1, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 74.0.8 allows FTP access during account suspension (SEC-449).

  • CVE-2018-20861MedJul 30, 2019
    risk 0.42cvss 6.5epss 0.01

    libopenmpt before 0.3.11 allows a crash with certain malformed custom tunings in MPTM files.

  • CVE-2018-20860MedJul 30, 2019
    risk 0.42cvss 6.5epss 0.01

    libopenmpt before 0.3.13 allows a crash with malformed MED files.

  • CVE-2018-20864MedJul 30, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 76.0.8 allows a persistent Virtual FTP accounts after removal of its associated domain (SEC-454).