CWE-20
Improper Input Validation
Description
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9
CVEs mapped to this weakness (13,387)
page 310 of 670| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-9348 | Med | 0.42 | 6.5 | 0.01 | Sep 27, 2019 | In libstagefright, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID:… | ||
| CVE-2018-11782 | Med | 0.42 | 6.5 | 0.02 | Sep 26, 2019 | In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a well-formed read-only request produces a particular answer. This can lead to disruption for users of the server. | ||
| CVE-2019-3760 | Med | 0.42 | 6.4 | 0.01 | Sep 11, 2019 | The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a SQL Injection vulnerability in Workflow Architect. A remote authenticated malicious user could potentially exploit this vulnerability to execute SQL… | ||
| CVE-2019-16141 | Hig | 0.42 | 7.5 | 0.02 | Sep 9, 2019 | An issue was discovered in the once_cell crate before 1.0.1 for Rust. There is a panic during initialization of Lazy. | ||
| CVE-2019-12588 | Med | 0.42 | 6.5 | 0.01 | Sep 4, 2019 | The client 802.11 mac implementation in Espressif ESP8266_NONOS_SDK 2.2.0 through 3.1.0 does not validate correctly the RSN AuthKey suite list count in beacon frames, probe responses, and association responses, which allows attackers in radio range to cause a denial of service… | ||
| CVE-2017-18589 | Hig | 0.42 | 7.5 | 0.02 | Aug 26, 2019 | An issue was discovered in the cookie crate before 0.7.6 for Rust. Large integers in the Max-Age of a cookie cause a panic. | ||
| CVE-2019-1984 | Med | 0.42 | 6.5 | 0.02 | Aug 21, 2019 | A vulnerability in Cisco Enterprise Network Functions Virtualization Infrastructure Software (NFVIS) could allow an authenticated, remote attacker with administrator privileges to overwrite files on the underlying operating system (OS) of an affected device. The vulnerability is… | ||
| CVE-2019-10745 | Hig | 0.42 | 7.5 | 0.01 | Aug 20, 2019 | assign-deep is vulnerable to Prototype Pollution in versions before 0.4.8 and version 1.0.0. The function assign-deep could be tricked into adding or modifying properties of Object.prototype using either a constructor or a _proto_ payload. | ||
| CVE-2016-10807 | Med | 0.42 | 6.5 | 0.01 | Aug 7, 2019 | cPanel before 57.9999.54 allows certain denial-of-service outcomes via /scripts/killpvhost (SEC-112). | ||
| CVE-2017-18482 | Med | 0.42 | 6.5 | 0.01 | Aug 5, 2019 | cPanel before 62.0.4 allows resellers to use the WHM enqueue_transfer_item API for queueing non-rearrange modules (SEC-213). | ||
| CVE-2016-10775 | Med | 0.42 | 6.5 | 0.01 | Aug 5, 2019 | cPanel before 60.0.25 allows arbitrary file-chown operations via reassign_post_terminate_cruft (SEC-173). | ||
| CVE-2016-10770 | Med | 0.42 | 6.5 | 0.01 | Aug 5, 2019 | cPanel before 60.0.25 allows arbitrary file-overwrite operations during a Roundcube update (SEC-164). | ||
| CVE-2016-10768 | Med | 0.42 | 6.5 | 0.01 | Aug 5, 2019 | cPanel before 60.0.25 allows file-overwrite operations during preparation for MySQL upgrades (SEC-161). | ||
| CVE-2017-18410 | Med | 0.42 | 6.5 | 0.01 | Aug 2, 2019 | In cPanel before 67.9999.103, a user account's backup archive could contain all MySQL databases on the server (SEC-284). | ||
| CVE-2017-18409 | Med | 0.42 | 6.5 | 0.01 | Aug 2, 2019 | In cPanel before 67.9999.103, the backup interface could return a backup archive with all MySQL databases (SEC-283). | ||
| CVE-2016-10842 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2019 | cPanel before 11.54.0.4 allows certain file-read operations in bin/setup_global_spam_filter.pl (SEC-74). | ||
| CVE-2018-20883 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2019 | cPanel before 74.0.8 allows FTP access during account suspension (SEC-449). | ||
| CVE-2018-20861 | Med | 0.42 | 6.5 | 0.01 | Jul 30, 2019 | libopenmpt before 0.3.11 allows a crash with certain malformed custom tunings in MPTM files. | ||
| CVE-2018-20860 | Med | 0.42 | 6.5 | 0.01 | Jul 30, 2019 | libopenmpt before 0.3.13 allows a crash with malformed MED files. | ||
| CVE-2018-20864 | Med | 0.42 | 6.5 | 0.01 | Jul 30, 2019 | cPanel before 76.0.8 allows a persistent Virtual FTP accounts after removal of its associated domain (SEC-454). |
- risk 0.42cvss 6.5epss 0.01
In libstagefright, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID:…
- risk 0.42cvss 6.5epss 0.02
In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a well-formed read-only request produces a particular answer. This can lead to disruption for users of the server.
- risk 0.42cvss 6.4epss 0.01
The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a SQL Injection vulnerability in Workflow Architect. A remote authenticated malicious user could potentially exploit this vulnerability to execute SQL…
- risk 0.42cvss 7.5epss 0.02
An issue was discovered in the once_cell crate before 1.0.1 for Rust. There is a panic during initialization of Lazy.
- risk 0.42cvss 6.5epss 0.01
The client 802.11 mac implementation in Espressif ESP8266_NONOS_SDK 2.2.0 through 3.1.0 does not validate correctly the RSN AuthKey suite list count in beacon frames, probe responses, and association responses, which allows attackers in radio range to cause a denial of service…
- risk 0.42cvss 7.5epss 0.02
An issue was discovered in the cookie crate before 0.7.6 for Rust. Large integers in the Max-Age of a cookie cause a panic.
- risk 0.42cvss 6.5epss 0.02
A vulnerability in Cisco Enterprise Network Functions Virtualization Infrastructure Software (NFVIS) could allow an authenticated, remote attacker with administrator privileges to overwrite files on the underlying operating system (OS) of an affected device. The vulnerability is…
- risk 0.42cvss 7.5epss 0.01
assign-deep is vulnerable to Prototype Pollution in versions before 0.4.8 and version 1.0.0. The function assign-deep could be tricked into adding or modifying properties of Object.prototype using either a constructor or a _proto_ payload.
- risk 0.42cvss 6.5epss 0.01
cPanel before 57.9999.54 allows certain denial-of-service outcomes via /scripts/killpvhost (SEC-112).
- risk 0.42cvss 6.5epss 0.01
cPanel before 62.0.4 allows resellers to use the WHM enqueue_transfer_item API for queueing non-rearrange modules (SEC-213).
- risk 0.42cvss 6.5epss 0.01
cPanel before 60.0.25 allows arbitrary file-chown operations via reassign_post_terminate_cruft (SEC-173).
- risk 0.42cvss 6.5epss 0.01
cPanel before 60.0.25 allows arbitrary file-overwrite operations during a Roundcube update (SEC-164).
- risk 0.42cvss 6.5epss 0.01
cPanel before 60.0.25 allows file-overwrite operations during preparation for MySQL upgrades (SEC-161).
- risk 0.42cvss 6.5epss 0.01
In cPanel before 67.9999.103, a user account's backup archive could contain all MySQL databases on the server (SEC-284).
- risk 0.42cvss 6.5epss 0.01
In cPanel before 67.9999.103, the backup interface could return a backup archive with all MySQL databases (SEC-283).
- risk 0.42cvss 6.5epss 0.01
cPanel before 11.54.0.4 allows certain file-read operations in bin/setup_global_spam_filter.pl (SEC-74).
- risk 0.42cvss 6.5epss 0.01
cPanel before 74.0.8 allows FTP access during account suspension (SEC-449).
- risk 0.42cvss 6.5epss 0.01
libopenmpt before 0.3.11 allows a crash with certain malformed custom tunings in MPTM files.
- risk 0.42cvss 6.5epss 0.01
libopenmpt before 0.3.13 allows a crash with malformed MED files.
- risk 0.42cvss 6.5epss 0.01
cPanel before 76.0.8 allows a persistent Virtual FTP accounts after removal of its associated domain (SEC-454).