CWE-20
Improper Input Validation
Description
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9
CVEs mapped to this weakness (13,352)
page 362 of 668| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-20733 | Med | 0.36 | 5.5 | 0.03 | Feb 15, 2024 | Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an Improper Input Validation vulnerability that could lead to an application denial-of-service. An attacker could leverage this vulnerability to cause the application to crash, resulting in a denial… | ||
| CVE-2024-22119 | Med | 0.36 | 5.5 | 0.01 | Feb 9, 2024 | The cause of vulnerability is improper validation of form input field “Name” on Graph page in Items section. | ||
| CVE-2023-4552 | Med | 0.36 | 5.5 | 0.00 | Jan 29, 2024 | Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. An authenticated AppBuilder user with the ability to create or manage existing databases can leverage them to exploit the AppBuilder server - including access to its… | ||
| CVE-2023-48354 | Med | 0.36 | 5.5 | 0.00 | Jan 18, 2024 | In telephone service, there is a possible improper input validation. This could lead to local information disclosure with no additional execution privileges needed | ||
| CVE-2023-48346 | Med | 0.36 | 5.5 | 0.00 | Jan 18, 2024 | In video decoder, there is a possible improper input validation. This could lead to local denial of service with no additional execution privileges needed | ||
| CVE-2024-20721 | Med | 0.36 | 5.5 | 0.01 | Jan 15, 2024 | Acrobat Reader T5 (MSFT Edge) versions 120.0.2210.91 and earlier are affected by an Improper Input Validation vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation… | ||
| CVE-2024-20709 | Med | 0.36 | 5.5 | 0.01 | Jan 15, 2024 | Acrobat Reader T5 (MSFT Edge) versions 120.0.2210.91 and earlier are affected by an Improper Input Validation vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation… | ||
| CVE-2023-49248 | Med | 0.36 | 5.5 | 0.00 | Dec 6, 2023 | Vulnerability of unauthorized file access in the Settings app. Successful exploitation of this vulnerability may cause unauthorized file access. | ||
| CVE-2023-35136 | Med | 0.36 | 5.5 | 0.00 | Nov 28, 2023 | An improper input validation vulnerability in the “Quagga” package of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware… | ||
| CVE-2023-36406 | Med | 0.36 | 5.5 | 0.01 | Nov 14, 2023 | Windows Hyper-V Information Disclosure Vulnerability | ||
| CVE-2023-42527 | Med | 0.36 | 5.6 | 0.00 | Nov 7, 2023 | Improper input validation vulnerability in ProcessWriteFile of libsec-ril prior to SMR Nov-2023 Release 1 allows local attackers to expose sensitive information. | ||
| CVE-2022-48459 | Med | 0.36 | 5.5 | 0.00 | Nov 1, 2023 | In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed | ||
| CVE-2022-48458 | Med | 0.36 | 5.5 | 0.00 | Nov 1, 2023 | In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed | ||
| CVE-2022-48457 | Med | 0.36 | 5.5 | 0.00 | Nov 1, 2023 | In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed | ||
| CVE-2023-21284 | Med | 0.36 | 5.5 | 0.00 | Aug 14, 2023 | In multiple functions of DevicePolicyManager.java, there is a possible way to prevent enabling the Find my Device feature due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for… | ||
| CVE-2023-27373 | Med | 0.36 | 5.5 | 0.00 | Aug 7, 2023 | An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. Due to insufficient input validation, an attacker can tamper with a runtime-accessible EFI variable to cause a dynamic BAR setting to overlap SMRAM. | ||
| CVE-2023-3433 | Med | 0.36 | 5.5 | 0.00 | Jul 14, 2023 | The "nickname" field within Savoir-faire Linux's Jami application is susceptible to a failed state when a user inserts special characters into the field. When present, these special characters, make it so the application cannot create the signature for the user and results in a… | ||
| CVE-2023-36872 | Med | 0.36 | 5.5 | 0.01 | Jul 11, 2023 | VP9 Video Extensions Information Disclosure Vulnerability | ||
| CVE-2023-35306 | Med | 0.36 | 5.5 | 0.01 | Jul 11, 2023 | Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | ||
| CVE-2023-21143 | Med | 0.36 | 5.5 | 0.00 | Jun 15, 2023 | In multiple functions of multiple files, there is a possible way to make the device unusable due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… |
- risk 0.36cvss 5.5epss 0.03
Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an Improper Input Validation vulnerability that could lead to an application denial-of-service. An attacker could leverage this vulnerability to cause the application to crash, resulting in a denial…
- risk 0.36cvss 5.5epss 0.01
The cause of vulnerability is improper validation of form input field “Name” on Graph page in Items section.
- risk 0.36cvss 5.5epss 0.00
Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. An authenticated AppBuilder user with the ability to create or manage existing databases can leverage them to exploit the AppBuilder server - including access to its…
- risk 0.36cvss 5.5epss 0.00
In telephone service, there is a possible improper input validation. This could lead to local information disclosure with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In video decoder, there is a possible improper input validation. This could lead to local denial of service with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.01
Acrobat Reader T5 (MSFT Edge) versions 120.0.2210.91 and earlier are affected by an Improper Input Validation vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation…
- risk 0.36cvss 5.5epss 0.01
Acrobat Reader T5 (MSFT Edge) versions 120.0.2210.91 and earlier are affected by an Improper Input Validation vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation…
- risk 0.36cvss 5.5epss 0.00
Vulnerability of unauthorized file access in the Settings app. Successful exploitation of this vulnerability may cause unauthorized file access.
- risk 0.36cvss 5.5epss 0.00
An improper input validation vulnerability in the “Quagga” package of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware…
- risk 0.36cvss 5.5epss 0.01
Windows Hyper-V Information Disclosure Vulnerability
- risk 0.36cvss 5.6epss 0.00
Improper input validation vulnerability in ProcessWriteFile of libsec-ril prior to SMR Nov-2023 Release 1 allows local attackers to expose sensitive information.
- risk 0.36cvss 5.5epss 0.00
In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In multiple functions of DevicePolicyManager.java, there is a possible way to prevent enabling the Find my Device feature due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for…
- risk 0.36cvss 5.5epss 0.00
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. Due to insufficient input validation, an attacker can tamper with a runtime-accessible EFI variable to cause a dynamic BAR setting to overlap SMRAM.
- risk 0.36cvss 5.5epss 0.00
The "nickname" field within Savoir-faire Linux's Jami application is susceptible to a failed state when a user inserts special characters into the field. When present, these special characters, make it so the application cannot create the signature for the user and results in a…
- risk 0.36cvss 5.5epss 0.01
VP9 Video Extensions Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.00
In multiple functions of multiple files, there is a possible way to make the device unusable due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…