VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,387)

page 312 of 670
  • CVE-2018-2015MedMay 2, 2019
    risk 0.42cvss 6.4epss 0.02

    IBM API Connect 2018.1 and 2018.4.1.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch…

  • CVE-2018-20835HigApr 30, 2019
    risk 0.42cvss 7.5epss 0.02

    A vulnerability was found in tar-fs before 1.16.2. An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink. This plain file…

  • CVE-2017-18367HigApr 24, 2019
    risk 0.42cvss 7.5epss 0.02

    libseccomp-golang 0.9.0 and earlier incorrectly generates BPFs that OR multiple arguments rather than ANDing them. A process running under a restrictive seccomp filter that specified multiple syscall arguments could bypass intended access restrictions by specifying a single…

  • CVE-2019-1841MedApr 18, 2019
    risk 0.42cvss 6.5epss 0.03

    A vulnerability in the Software Image Management feature of Cisco DNA Center could allow an authenticated, remote attacker to access to internal services without additional authentication. The vulnerability is due to insufficient validation of user-supplied input. An attacker…

  • CVE-2019-1800MedApr 18, 2019
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability exist because the software improperly…

  • CVE-2019-1799MedApr 18, 2019
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability exist because the software improperly…

  • CVE-2019-1796MedApr 18, 2019
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability exist because the software improperly…

  • CVE-2019-1721MedApr 18, 2019
    risk 0.42cvss 6.5epss 0.02

    A vulnerability in the phone book feature of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to cause the CPU to increase to 100% utilization, causing a denial of service (DoS) condition on an affected…

  • CVE-2019-3460MedApr 11, 2019
    risk 0.42cvss 6.5epss 0.02

    A heap data infoleak in multiple locations including L2CAP_PARSE_CONF_RSP was found in the Linux kernel before 5.1-rc1.

  • CVE-2019-11069HigApr 10, 2019
    risk 0.42cvss 7.5epss 0.02

    Sequelize version 5 before 5.3.0 does not properly ensure that standard conforming strings are used.

  • CVE-2018-4460MedApr 3, 2019
    risk 0.42cvss 6.5epss 0.02

    A denial of service issue was addressed by removing the vulnerable code. This issue affected versions prior to iOS 12.1.1, macOS Mojave 10.14.2, tvOS 12.1.1, watchOS 5.1.2.

  • CVE-2018-4439MedApr 3, 2019
    risk 0.42cvss 6.5epss 0.02

    A logic issue was addressed with improved validation. This issue affected versions prior to iOS 12.1.1, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.

  • CVE-2018-4429MedApr 3, 2019
    risk 0.42cvss 6.5epss 0.01

    A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1.1, watchOS 5.1.2.

  • CVE-2018-4406MedApr 3, 2019
    risk 0.42cvss 6.5epss 0.01

    A denial of service issue was addressed with improved validation. This issue affected versions prior to macOS Mojave 10.14.

  • CVE-2018-4389MedApr 3, 2019
    risk 0.42cvss 6.5epss 0.01

    An inconsistent user interface issue was addressed with improved state management. This issue affected versions prior to macOS Mojave 10.14.1.

  • CVE-2018-4385MedApr 3, 2019
    risk 0.42cvss 6.5epss 0.01

    A logic issue was addressed with improved state management. This issue affected versions prior to iOS 12.1.

  • CVE-2018-4368MedApr 3, 2019
    risk 0.42cvss 6.5epss 0.02

    A denial of service issue was addressed with improved validation. This issue affected versions prior to iOS 12.1, macOS Mojave 10.14.1, tvOS 12.1, watchOS 5.1.

  • CVE-2018-4362MedApr 3, 2019
    risk 0.42cvss 6.5epss 0.01

    An inconsistent user interface issue was addressed with improved state management. This issue affected versions prior to Safari 11.1.2, iOS 12.

  • CVE-2018-4305MedApr 3, 2019
    risk 0.42cvss 6.5epss 0.01

    An input validation issue was addressed with improved input validation. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5.

  • CVE-2018-4260MedApr 3, 2019
    risk 0.42cvss 6.5epss 0.01

    An inconsistent user interface issue was addressed with improved state management. This issue affected versions prior to iOS 11.4.1, Safari 11.1.2.