VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,352)

page 363 of 668
  • CVE-2023-21136MedJun 15, 2023
    risk 0.36cvss 5.5epss 0.00

    In multiple functions of JobStore.java, there is a possible way to cause a crash on startup due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2023-29353MedJun 14, 2023
    risk 0.36cvss 5.5epss 0.01

    Sysinternals Process Monitor for Windows Denial of Service Vulnerability

  • CVE-2023-21111MedMay 15, 2023
    risk 0.36cvss 5.5epss 0.00

    In several functions of PhoneAccountRegistrar.java, there is a possible way to prevent an access to emergency services due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2023-20705MedMay 15, 2023
    risk 0.36cvss 5.5epss 0.00

    In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767870; Issue ID: ALPS07767870.

  • CVE-2023-20704MedMay 15, 2023
    risk 0.36cvss 5.5epss 0.00

    In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767826; Issue ID: ALPS07767826.

  • CVE-2022-25976MedMay 10, 2023
    risk 0.36cvss 5.5epss 0.00

    Improper input validation in the Intel(R) VROC software before version 7.7.6.1003 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2023-28200MedMay 8, 2023
    risk 0.36cvss 5.5epss 0.00

    A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Ventura 13.3, iOS 15.7.4 and iPadOS 15.7.4, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. An app may be able to disclose kernel memory.

  • CVE-2023-27961MedMay 8, 2023
    risk 0.36cvss 5.5epss 0.00

    Multiple validation issues were addressed with improved input sanitization. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, macOS Monterey 12.6.4, watchOS 9.4, macOS Big Sur 11.7.5. Importing a maliciously crafted calendar…

  • CVE-2023-21504MedMay 4, 2023
    risk 0.36cvss 5.6epss 0.01

    Potential buffer overflow vulnerability in mm_Plmncoordination.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access.

  • CVE-2023-21503MedMay 4, 2023
    risk 0.36cvss 5.6epss 0.01

    Potential buffer overflow vulnerability in mm_LteInterRatManagement.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access.

  • CVE-2023-21494MedMay 4, 2023
    risk 0.36cvss 5.6epss 0.01

    Potential buffer overflow vulnerability in auth api in mm_Authentication.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access.

  • CVE-2023-23409MedMar 14, 2023
    risk 0.36cvss 5.5epss 0.00

    Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability

  • CVE-2023-24579MedMar 13, 2023
    risk 0.36cvss 5.5epss 0.00

    McAfee Total Protection prior to 16.0.51 allows attackers to trick a victim into uninstalling the application via the command prompt.

  • CVE-2023-24465MedMar 10, 2023
    risk 0.36cvss 5.5epss 0.00

    Communication Wi-Fi subsystem within OpenHarmony-v3.1.4 and prior versions, OpenHarmony-v3.0.7 and prior versions has a null pointer reference vulnerability which local attackers can exploit this vulnerability to cause the current application to crash.

  • CVE-2023-0615MedFeb 6, 2023
    risk 0.36cvss 5.5epss 0.00

    A memory leak flaw and potential divide by zero and Integer overflow was found in the Linux kernel V4L2 and vivid test code functionality. This issue occurs when a user triggers ioctls, such as VIDIOC_S_DV_TIMINGS ioctl. This could allow a local user to crash the system if vivid…

  • CVE-2022-32482MedFeb 1, 2023
    risk 0.36cvss 5.6epss 0.00

    Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

  • CVE-2022-43455MedJan 18, 2023
    risk 0.36cvss 5.5epss 0.01

    Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 is vulnerable to improper input validation of user input to the service_start, service_stop, and service_restart modules of the software. This could allow an attacker to start,…

  • CVE-2021-26404MedJan 11, 2023
    risk 0.36cvss 5.5epss 0.00

    Improper input validation and bounds checking in SEV firmware may leak scratch buffer bytes leading to potential information disclosure.

  • CVE-2023-21559MedJan 10, 2023
    risk 0.36cvss 5.5epss 0.01

    Windows Cryptographic Information Disclosure Vulnerability

  • CVE-2023-21550MedJan 10, 2023
    risk 0.36cvss 5.5epss 0.01

    Windows Cryptographic Information Disclosure Vulnerability