CWE-20
Improper Input Validation
Description
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9
CVEs mapped to this weakness (13,352)
page 361 of 668| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-51529 | Med | 0.36 | 5.5 | 0.00 | Nov 5, 2024 | Data verification vulnerability in the battery module Impact: Successful exploitation of this vulnerability may affect function stability. | ||
| CVE-2024-51520 | Med | 0.36 | 5.5 | 0.00 | Nov 5, 2024 | Vulnerability of input parameters not being verified in the HDC module Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2024-20274 | Med | 0.36 | 5.5 | 0.00 | Oct 23, 2024 | A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to inject arbitrary HTML content into a device-generated document. … | ||
| CVE-2024-45446 | Med | 0.36 | 5.5 | 0.00 | Sep 4, 2024 | Access permission verification vulnerability in the camera driver module Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2024-45444 | Med | 0.36 | 5.5 | 0.00 | Sep 4, 2024 | Access permission verification vulnerability in the WMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2024-34118 | Med | 0.36 | 5.5 | 0.00 | Aug 14, 2024 | Illustrator versions 28.5, 27.9.4 and earlier are affected by an Improper Input Validation vulnerability that could lead to an application denial-of-service condition. An attacker could exploit this vulnerability to render the application unresponsive or terminate its execution.… | ||
| CVE-2017-3772 | Med | 0.36 | 5.5 | 0.00 | Jul 31, 2024 | A vulnerability was reported in Lenovo PC Manager versions prior to 2.6.40.3154 that could allow an attacker to cause a system reboot. | ||
| CVE-2024-6978 | Med | 0.36 | 5.6 | 0.00 | Jul 31, 2024 | Cato Networks Windows SDP Client Local root certificates can be installed by low-privileged users.This issue affects SDP Client: before 5.10.28. | ||
| CVE-2024-39827 | Med | 0.36 | 5.5 | 0.00 | Jul 15, 2024 | Improper input validation in the installer for Zoom Workplace Desktop App for Windows before version 6.0.10 may allow an authenticated user to conduct a denial of service via local access. | ||
| CVE-2024-39513 | Med | 0.36 | 5.5 | 0.00 | Jul 10, 2024 | An Improper Input Validation vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved allows a local, low-privileged attacker to cause a Denial of Service (DoS). When a specific "clear" command is run, the Advanced Forwarding Toolkit manager… | ||
| CVE-2024-39511 | Med | 0.36 | 5.5 | 0.00 | Jul 10, 2024 | An Improper Input Validation vulnerability in the 802.1X Authentication (dot1x) Daemon of Juniper Networks Junos OS allows a local, low-privileged attacker with access to the CLI to cause a Denial of Service (DoS). On running a specific operational dot1x command, the dot1x… | ||
| CVE-2024-38055 | Med | 0.36 | 5.5 | 0.01 | Jul 9, 2024 | Microsoft Windows Codecs Library Information Disclosure Vulnerability | ||
| CVE-2024-27805 | Med | 0.36 | 5.5 | 0.00 | Jun 10, 2024 | An issue was addressed with improved validation of environment variables. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7, tvOS 17.5, watchOS 10.5. An app may be able to access… | ||
| CVE-2024-35384 | Med | 0.36 | 5.5 | 0.00 | May 21, 2024 | An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_array_length function in the mjs.c file. | ||
| CVE-2024-20394 | Med | 0.36 | 5.5 | 0.00 | May 15, 2024 | A vulnerability in Cisco AppDynamics Network Visibility Agent could allow an unauthenticated, local attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to the inability to handle unexpected input. An attacker who has local… | ||
| CVE-2024-3488 | Med | 0.36 | 5.6 | 0.00 | May 15, 2024 | File Upload vulnerability in unauthenticated session found in OpenText™ iManager 3.2.6.0200. The vulnerability could allow ant attacker to upload a file without authentication. | ||
| CVE-2024-0022 | Med | 0.36 | 5.5 | 0.00 | May 7, 2024 | In multiple functions of CompanionDeviceManagerService.java, there is a possible launch NotificationAccessConfirmationActivity of another user profile due to improper input validation. This could lead to local information disclosure with no additional execution privileges… | ||
| CVE-2024-20334 | Med | 0.36 | 5.5 | 0.00 | Apr 3, 2024 | A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) could allow a low-privileged, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient input… | ||
| CVE-2024-26181 | Med | 0.36 | 5.5 | 0.01 | Mar 12, 2024 | Windows Kernel Denial of Service Vulnerability | ||
| CVE-2023-44345 | Med | 0.36 | 5.5 | 0.00 | Feb 29, 2024 | Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by a Improper Input Validation vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user.… |
- risk 0.36cvss 5.5epss 0.00
Data verification vulnerability in the battery module Impact: Successful exploitation of this vulnerability may affect function stability.
- risk 0.36cvss 5.5epss 0.00
Vulnerability of input parameters not being verified in the HDC module Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.36cvss 5.5epss 0.00
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to inject arbitrary HTML content into a device-generated document. …
- risk 0.36cvss 5.5epss 0.00
Access permission verification vulnerability in the camera driver module Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.36cvss 5.5epss 0.00
Access permission verification vulnerability in the WMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.36cvss 5.5epss 0.00
Illustrator versions 28.5, 27.9.4 and earlier are affected by an Improper Input Validation vulnerability that could lead to an application denial-of-service condition. An attacker could exploit this vulnerability to render the application unresponsive or terminate its execution.…
- risk 0.36cvss 5.5epss 0.00
A vulnerability was reported in Lenovo PC Manager versions prior to 2.6.40.3154 that could allow an attacker to cause a system reboot.
- risk 0.36cvss 5.6epss 0.00
Cato Networks Windows SDP Client Local root certificates can be installed by low-privileged users.This issue affects SDP Client: before 5.10.28.
- risk 0.36cvss 5.5epss 0.00
Improper input validation in the installer for Zoom Workplace Desktop App for Windows before version 6.0.10 may allow an authenticated user to conduct a denial of service via local access.
- risk 0.36cvss 5.5epss 0.00
An Improper Input Validation vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved allows a local, low-privileged attacker to cause a Denial of Service (DoS). When a specific "clear" command is run, the Advanced Forwarding Toolkit manager…
- risk 0.36cvss 5.5epss 0.00
An Improper Input Validation vulnerability in the 802.1X Authentication (dot1x) Daemon of Juniper Networks Junos OS allows a local, low-privileged attacker with access to the CLI to cause a Denial of Service (DoS). On running a specific operational dot1x command, the dot1x…
- risk 0.36cvss 5.5epss 0.01
Microsoft Windows Codecs Library Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.00
An issue was addressed with improved validation of environment variables. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7, tvOS 17.5, watchOS 10.5. An app may be able to access…
- risk 0.36cvss 5.5epss 0.00
An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_array_length function in the mjs.c file.
- risk 0.36cvss 5.5epss 0.00
A vulnerability in Cisco AppDynamics Network Visibility Agent could allow an unauthenticated, local attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to the inability to handle unexpected input. An attacker who has local…
- risk 0.36cvss 5.6epss 0.00
File Upload vulnerability in unauthenticated session found in OpenText™ iManager 3.2.6.0200. The vulnerability could allow ant attacker to upload a file without authentication.
- risk 0.36cvss 5.5epss 0.00
In multiple functions of CompanionDeviceManagerService.java, there is a possible launch NotificationAccessConfirmationActivity of another user profile due to improper input validation. This could lead to local information disclosure with no additional execution privileges…
- risk 0.36cvss 5.5epss 0.00
A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) could allow a low-privileged, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient input…
- risk 0.36cvss 5.5epss 0.01
Windows Kernel Denial of Service Vulnerability
- risk 0.36cvss 5.5epss 0.00
Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by a Improper Input Validation vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user.…