VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,352)

page 361 of 668
  • CVE-2024-51529MedNov 5, 2024
    risk 0.36cvss 5.5epss 0.00

    Data verification vulnerability in the battery module Impact: Successful exploitation of this vulnerability may affect function stability.

  • CVE-2024-51520MedNov 5, 2024
    risk 0.36cvss 5.5epss 0.00

    Vulnerability of input parameters not being verified in the HDC module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-20274MedOct 23, 2024
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to inject arbitrary HTML content into a device-generated document. …

  • CVE-2024-45446MedSep 4, 2024
    risk 0.36cvss 5.5epss 0.00

    Access permission verification vulnerability in the camera driver module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-45444MedSep 4, 2024
    risk 0.36cvss 5.5epss 0.00

    Access permission verification vulnerability in the WMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-34118MedAug 14, 2024
    risk 0.36cvss 5.5epss 0.00

    Illustrator versions 28.5, 27.9.4 and earlier are affected by an Improper Input Validation vulnerability that could lead to an application denial-of-service condition. An attacker could exploit this vulnerability to render the application unresponsive or terminate its execution.…

  • CVE-2017-3772MedJul 31, 2024
    risk 0.36cvss 5.5epss 0.00

    A vulnerability was reported in Lenovo PC Manager versions prior to 2.6.40.3154 that could allow an attacker to cause a system reboot.

  • CVE-2024-6978MedJul 31, 2024
    risk 0.36cvss 5.6epss 0.00

    Cato Networks Windows SDP Client Local root certificates can be installed by low-privileged users.This issue affects SDP Client: before 5.10.28.

  • CVE-2024-39827MedJul 15, 2024
    risk 0.36cvss 5.5epss 0.00

    Improper input validation in the installer for Zoom Workplace Desktop App for Windows before version 6.0.10 may allow an authenticated user to conduct a denial of service via local access.

  • CVE-2024-39513MedJul 10, 2024
    risk 0.36cvss 5.5epss 0.00

    An Improper Input Validation vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved allows a local, low-privileged attacker to cause a Denial of Service (DoS). When a specific "clear" command is run, the Advanced Forwarding Toolkit manager…

  • CVE-2024-39511MedJul 10, 2024
    risk 0.36cvss 5.5epss 0.00

    An Improper Input Validation vulnerability in the 802.1X Authentication (dot1x) Daemon of Juniper Networks Junos OS allows a local, low-privileged attacker with access to the CLI to cause a Denial of Service (DoS). On running a specific operational dot1x command, the dot1x…

  • CVE-2024-38055MedJul 9, 2024
    risk 0.36cvss 5.5epss 0.01

    Microsoft Windows Codecs Library Information Disclosure Vulnerability

  • CVE-2024-27805MedJun 10, 2024
    risk 0.36cvss 5.5epss 0.00

    An issue was addressed with improved validation of environment variables. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7, tvOS 17.5, watchOS 10.5. An app may be able to access…

  • CVE-2024-35384MedMay 21, 2024
    risk 0.36cvss 5.5epss 0.00

    An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_array_length function in the mjs.c file.

  • CVE-2024-20394MedMay 15, 2024
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in Cisco AppDynamics Network Visibility Agent could allow an unauthenticated, local attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to the inability to handle unexpected input. An attacker who has local…

  • CVE-2024-3488MedMay 15, 2024
    risk 0.36cvss 5.6epss 0.00

    File Upload vulnerability in unauthenticated session found in OpenText™ iManager 3.2.6.0200. The vulnerability could allow ant attacker to upload a file without authentication.

  • CVE-2024-0022MedMay 7, 2024
    risk 0.36cvss 5.5epss 0.00

    In multiple functions of CompanionDeviceManagerService.java, there is a possible launch NotificationAccessConfirmationActivity of another user profile due to improper input validation. This could lead to local information disclosure with no additional execution privileges…

  • CVE-2024-20334MedApr 3, 2024
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) could allow a low-privileged, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient input…

  • CVE-2024-26181MedMar 12, 2024
    risk 0.36cvss 5.5epss 0.01

    Windows Kernel Denial of Service Vulnerability

  • CVE-2023-44345MedFeb 29, 2024
    risk 0.36cvss 5.5epss 0.00

    Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by a Improper Input Validation vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user.…