CWE-20
Improper Input Validation
Description
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9
CVEs mapped to this weakness (13,352)
page 363 of 668| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-21136 | Med | 0.36 | 5.5 | 0.00 | Jun 15, 2023 | In multiple functions of JobStore.java, there is a possible way to cause a crash on startup due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2023-29353 | Med | 0.36 | 5.5 | 0.01 | Jun 14, 2023 | Sysinternals Process Monitor for Windows Denial of Service Vulnerability | ||
| CVE-2023-21111 | Med | 0.36 | 5.5 | 0.00 | May 15, 2023 | In several functions of PhoneAccountRegistrar.java, there is a possible way to prevent an access to emergency services due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2023-20705 | Med | 0.36 | 5.5 | 0.00 | May 15, 2023 | In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767870; Issue ID: ALPS07767870. | ||
| CVE-2023-20704 | Med | 0.36 | 5.5 | 0.00 | May 15, 2023 | In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767826; Issue ID: ALPS07767826. | ||
| CVE-2022-25976 | Med | 0.36 | 5.5 | 0.00 | May 10, 2023 | Improper input validation in the Intel(R) VROC software before version 7.7.6.1003 may allow an authenticated user to potentially enable denial of service via local access. | ||
| CVE-2023-28200 | Med | 0.36 | 5.5 | 0.00 | May 8, 2023 | A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Ventura 13.3, iOS 15.7.4 and iPadOS 15.7.4, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. An app may be able to disclose kernel memory. | ||
| CVE-2023-27961 | Med | 0.36 | 5.5 | 0.00 | May 8, 2023 | Multiple validation issues were addressed with improved input sanitization. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, macOS Monterey 12.6.4, watchOS 9.4, macOS Big Sur 11.7.5. Importing a maliciously crafted calendar… | ||
| CVE-2023-21504 | Med | 0.36 | 5.6 | 0.01 | May 4, 2023 | Potential buffer overflow vulnerability in mm_Plmncoordination.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access. | ||
| CVE-2023-21503 | Med | 0.36 | 5.6 | 0.01 | May 4, 2023 | Potential buffer overflow vulnerability in mm_LteInterRatManagement.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access. | ||
| CVE-2023-21494 | Med | 0.36 | 5.6 | 0.01 | May 4, 2023 | Potential buffer overflow vulnerability in auth api in mm_Authentication.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access. | ||
| CVE-2023-23409 | Med | 0.36 | 5.5 | 0.00 | Mar 14, 2023 | Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability | ||
| CVE-2023-24579 | Med | 0.36 | 5.5 | 0.00 | Mar 13, 2023 | McAfee Total Protection prior to 16.0.51 allows attackers to trick a victim into uninstalling the application via the command prompt. | ||
| CVE-2023-24465 | Med | 0.36 | 5.5 | 0.00 | Mar 10, 2023 | Communication Wi-Fi subsystem within OpenHarmony-v3.1.4 and prior versions, OpenHarmony-v3.0.7 and prior versions has a null pointer reference vulnerability which local attackers can exploit this vulnerability to cause the current application to crash. | ||
| CVE-2023-0615 | Med | 0.36 | 5.5 | 0.00 | Feb 6, 2023 | A memory leak flaw and potential divide by zero and Integer overflow was found in the Linux kernel V4L2 and vivid test code functionality. This issue occurs when a user triggers ioctls, such as VIDIOC_S_DV_TIMINGS ioctl. This could allow a local user to crash the system if vivid… | ||
| CVE-2022-32482 | Med | 0.36 | 5.6 | 0.00 | Feb 1, 2023 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable. | ||
| CVE-2022-43455 | Med | 0.36 | 5.5 | 0.01 | Jan 18, 2023 | Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 is vulnerable to improper input validation of user input to the service_start, service_stop, and service_restart modules of the software. This could allow an attacker to start,… | ||
| CVE-2021-26404 | Med | 0.36 | 5.5 | 0.00 | Jan 11, 2023 | Improper input validation and bounds checking in SEV firmware may leak scratch buffer bytes leading to potential information disclosure. | ||
| CVE-2023-21559 | Med | 0.36 | 5.5 | 0.01 | Jan 10, 2023 | Windows Cryptographic Information Disclosure Vulnerability | ||
| CVE-2023-21550 | Med | 0.36 | 5.5 | 0.01 | Jan 10, 2023 | Windows Cryptographic Information Disclosure Vulnerability |
- risk 0.36cvss 5.5epss 0.00
In multiple functions of JobStore.java, there is a possible way to cause a crash on startup due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.36cvss 5.5epss 0.01
Sysinternals Process Monitor for Windows Denial of Service Vulnerability
- risk 0.36cvss 5.5epss 0.00
In several functions of PhoneAccountRegistrar.java, there is a possible way to prevent an access to emergency services due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for…
- risk 0.36cvss 5.5epss 0.00
In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767870; Issue ID: ALPS07767870.
- risk 0.36cvss 5.5epss 0.00
In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767826; Issue ID: ALPS07767826.
- risk 0.36cvss 5.5epss 0.00
Improper input validation in the Intel(R) VROC software before version 7.7.6.1003 may allow an authenticated user to potentially enable denial of service via local access.
- risk 0.36cvss 5.5epss 0.00
A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Ventura 13.3, iOS 15.7.4 and iPadOS 15.7.4, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. An app may be able to disclose kernel memory.
- risk 0.36cvss 5.5epss 0.00
Multiple validation issues were addressed with improved input sanitization. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, macOS Monterey 12.6.4, watchOS 9.4, macOS Big Sur 11.7.5. Importing a maliciously crafted calendar…
- risk 0.36cvss 5.6epss 0.01
Potential buffer overflow vulnerability in mm_Plmncoordination.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access.
- risk 0.36cvss 5.6epss 0.01
Potential buffer overflow vulnerability in mm_LteInterRatManagement.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access.
- risk 0.36cvss 5.6epss 0.01
Potential buffer overflow vulnerability in auth api in mm_Authentication.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access.
- risk 0.36cvss 5.5epss 0.00
Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.00
McAfee Total Protection prior to 16.0.51 allows attackers to trick a victim into uninstalling the application via the command prompt.
- risk 0.36cvss 5.5epss 0.00
Communication Wi-Fi subsystem within OpenHarmony-v3.1.4 and prior versions, OpenHarmony-v3.0.7 and prior versions has a null pointer reference vulnerability which local attackers can exploit this vulnerability to cause the current application to crash.
- risk 0.36cvss 5.5epss 0.00
A memory leak flaw and potential divide by zero and Integer overflow was found in the Linux kernel V4L2 and vivid test code functionality. This issue occurs when a user triggers ioctls, such as VIDIOC_S_DV_TIMINGS ioctl. This could allow a local user to crash the system if vivid…
- risk 0.36cvss 5.6epss 0.00
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable.
- risk 0.36cvss 5.5epss 0.01
Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 is vulnerable to improper input validation of user input to the service_start, service_stop, and service_restart modules of the software. This could allow an attacker to start,…
- risk 0.36cvss 5.5epss 0.00
Improper input validation and bounds checking in SEV firmware may leak scratch buffer bytes leading to potential information disclosure.
- risk 0.36cvss 5.5epss 0.01
Windows Cryptographic Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows Cryptographic Information Disclosure Vulnerability