VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,352)

page 334 of 668
  • CVE-2024-54121MedJan 8, 2025
    risk 0.40cvss 6.2epss 0.00

    Startup control vulnerability in the ability module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

  • CVE-2024-54101MedDec 12, 2024
    risk 0.40cvss 6.2epss 0.00

    Denial of service (DoS) vulnerability in the installation module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-54100MedDec 12, 2024
    risk 0.40cvss 6.2epss 0.00

    Vulnerability of improper access control in the secure input module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

  • CVE-2024-37027MedNov 13, 2024
    risk 0.40cvss 6.1epss 0.00

    Improper Input validation in some Intel(R) VTune(TM) Profiler software before version 2024.2.0 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2024-51512MedNov 5, 2024
    risk 0.40cvss 6.2epss 0.00

    Vulnerability of parameter type not being verified in the WantAgent module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-51511MedNov 5, 2024
    risk 0.40cvss 6.2epss 0.00

    Vulnerability of parameter type not being verified in the WantAgent module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-45441MedSep 4, 2024
    risk 0.40cvss 6.2epss 0.00

    Input verification vulnerability in the system service module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2021-38122MedAug 28, 2024
    risk 0.40cvss 6.2epss 0.00

    A Cross-Site Scripting vulnerable identified in NetIQ Advance Authentication that impacts the server functionality and disclose sensitive information. This issue affects NetIQ Advance Authentication before 6.3.5.1

  • CVE-2024-5913MedJul 10, 2024
    risk 0.40cvss 6.1epss 0.00

    An improper input validation vulnerability in Palo Alto Networks PAN-OS software enables an attacker with the ability to tamper with the physical file system to elevate privileges.

  • CVE-2024-6284HigJul 3, 2024
    risk 0.40cvss 7.3epss 0.00

    In https://github.com/google/nftables  IP addresses were encoded in the wrong byte order, resulting in an nftables configuration which does not work as intended (might block or not block the desired addresses). This issue affects:  https://pkg.go.dev/github.com/google/nftabl…

  • CVE-2024-35212MedJun 11, 2024
    risk 0.40cvss 6.2epss 0.00

    A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected application lacks input validation due to which an attacker can gain access to the Database entries.

  • CVE-2024-32990MedMay 14, 2024
    risk 0.40cvss 6.1epss 0.00

    Permission verification vulnerability in the system sharing pop-up module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-3841MedApr 17, 2024
    risk 0.40cvss 6.1epss 0.01

    Insufficient data validation in Browser Switcher in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to inject scripts or HTML into a privileged page via a malicious file. (Chromium security severity: Medium)

  • CVE-2023-52385MedApr 8, 2024
    risk 0.40cvss 6.2epss 0.00

    Out-of-bounds write vulnerability in the RSMC module. Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2023-51444HigMar 20, 2024
    risk 0.40cvss 7.2epss 0.02

    GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. An arbitrary file upload vulnerability exists in versions prior to 2.23.4 and 2.24.1 that enables an authenticated administrator with permissions to modify coverage…

  • CVE-2023-50378MedMar 1, 2024
    risk 0.40cvss 6.1epss 0.01

    Lack of proper input validation and constraint enforcement in Apache Ambari prior to 2.7.8    Impact : As it will be stored XSS, Could be exploited to perform unauthorized actions, varying from data access to session hijacking and delivering malicious payloads. Users are…

  • CVE-2023-28374MedFeb 14, 2024
    risk 0.40cvss 6.1epss 0.00

    Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

  • CVE-2024-24941MedFeb 6, 2024
    risk 0.40cvss 6.1epss 0.00

    In JetBrains IntelliJ IDEA before 2023.3.3 a plugin for JetBrains Space was able to send an authentication token to an inappropriate URL

  • CVE-2023-45171MedJan 11, 2024
    risk 0.40cvss 6.2epss 0.00

    IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the kernel to cause a denial of service. IBM X-Force ID: 267969.

  • CVE-2023-45169MedJan 11, 2024
    risk 0.40cvss 6.2epss 0.00

    IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the pmsvcs kernel extension to cause a denial of service. IBM X-Force ID: 267967.