VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,352)

page 362 of 668
  • CVE-2024-20733MedFeb 15, 2024
    risk 0.36cvss 5.5epss 0.03

    Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an Improper Input Validation vulnerability that could lead to an application denial-of-service. An attacker could leverage this vulnerability to cause the application to crash, resulting in a denial…

  • CVE-2024-22119MedFeb 9, 2024
    risk 0.36cvss 5.5epss 0.01

    The cause of vulnerability is improper validation of form input field “Name” on Graph page in Items section.

  • CVE-2023-4552MedJan 29, 2024
    risk 0.36cvss 5.5epss 0.00

    Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. An authenticated AppBuilder user with the ability to create or manage existing databases can leverage them to exploit the AppBuilder server - including access to its…

  • CVE-2023-48354MedJan 18, 2024
    risk 0.36cvss 5.5epss 0.00

    In telephone service, there is a possible improper input validation. This could lead to local information disclosure with no additional execution privileges needed

  • CVE-2023-48346MedJan 18, 2024
    risk 0.36cvss 5.5epss 0.00

    In video decoder, there is a possible improper input validation. This could lead to local denial of service with no additional execution privileges needed

  • CVE-2024-20721MedJan 15, 2024
    risk 0.36cvss 5.5epss 0.01

    Acrobat Reader T5 (MSFT Edge) versions 120.0.2210.91 and earlier are affected by an Improper Input Validation vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation…

  • CVE-2024-20709MedJan 15, 2024
    risk 0.36cvss 5.5epss 0.01

    Acrobat Reader T5 (MSFT Edge) versions 120.0.2210.91 and earlier are affected by an Improper Input Validation vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation…

  • CVE-2023-49248MedDec 6, 2023
    risk 0.36cvss 5.5epss 0.00

    Vulnerability of unauthorized file access in the Settings app. Successful exploitation of this vulnerability may cause unauthorized file access.

  • CVE-2023-35136MedNov 28, 2023
    risk 0.36cvss 5.5epss 0.00

    An improper input validation vulnerability in the “Quagga” package of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware…

  • CVE-2023-36406MedNov 14, 2023
    risk 0.36cvss 5.5epss 0.01

    Windows Hyper-V Information Disclosure Vulnerability

  • CVE-2023-42527MedNov 7, 2023
    risk 0.36cvss 5.6epss 0.00

    Improper input validation vulnerability in ProcessWriteFile of libsec-ril prior to SMR Nov-2023 Release 1 allows local attackers to expose sensitive information.

  • CVE-2022-48459MedNov 1, 2023
    risk 0.36cvss 5.5epss 0.00

    In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed

  • CVE-2022-48458MedNov 1, 2023
    risk 0.36cvss 5.5epss 0.00

    In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed

  • CVE-2022-48457MedNov 1, 2023
    risk 0.36cvss 5.5epss 0.00

    In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed

  • CVE-2023-21284MedAug 14, 2023
    risk 0.36cvss 5.5epss 0.00

    In multiple functions of DevicePolicyManager.java, there is a possible way to prevent enabling the Find my Device feature due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for…

  • CVE-2023-27373MedAug 7, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. Due to insufficient input validation, an attacker can tamper with a runtime-accessible EFI variable to cause a dynamic BAR setting to overlap SMRAM.

  • CVE-2023-3433MedJul 14, 2023
    risk 0.36cvss 5.5epss 0.00

    The "nickname" field within Savoir-faire Linux's Jami application is susceptible to a failed state when a user inserts special characters into the field. When present, these special characters, make it so the application cannot create the signature for the user and results in a…

  • CVE-2023-36872MedJul 11, 2023
    risk 0.36cvss 5.5epss 0.01

    VP9 Video Extensions Information Disclosure Vulnerability

  • CVE-2023-35306MedJul 11, 2023
    risk 0.36cvss 5.5epss 0.01

    Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability

  • CVE-2023-21143MedJun 15, 2023
    risk 0.36cvss 5.5epss 0.00

    In multiple functions of multiple files, there is a possible way to make the device unusable due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…