VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,352)

page 366 of 668
  • CVE-2021-33025MedMay 16, 2022
    risk 0.36cvss 5.6epss 0.00

    xArrow SCADA versions 7.2 and prior permits unvalidated registry keys to be run with application-level privileges.

  • CVE-2021-26351MedMay 12, 2022
    risk 0.36cvss 5.5epss 0.00

    Insufficient DRAM address validation in System Management Unit (SMU) may result in a DMA (Direct Memory Access) read/write from/to invalid DRAM address that could result in denial of service.

  • CVE-2022-21136MedMay 12, 2022
    risk 0.36cvss 5.5epss 0.00

    Improper input validation for some Intel(R) Xeon(R) Processors may allow a privileged user to potentially enable denial of service via local access.

  • CVE-2021-26373MedMay 11, 2022
    risk 0.36cvss 5.5epss 0.00

    Insufficient bound checks in the System Management Unit (SMU) may result in a system voltage malfunction that could result in denial of resources and/or possibly denial of service.

  • CVE-2022-28193MedApr 27, 2022
    risk 0.36cvss 5.6epss 0.00

    NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot module tegrabl_cbo.c, where insufficient validation of untrusted data may allow a local attacker with elevated privileges to cause a memory buffer overflow, which may lead to code execution, loss of…

  • CVE-2021-39778MedMar 30, 2022
    risk 0.36cvss 5.5epss 0.00

    In Telecomm, there is a possible way to determine whether an app is installed, without query permissions, due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-39740MedMar 30, 2022
    risk 0.36cvss 5.5epss 0.00

    In Messaging, there is a possible way to bypass attachment restrictions due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-4219MedMar 23, 2022
    risk 0.36cvss 5.5epss 0.01

    A flaw was found in ImageMagick. The vulnerability occurs due to improper use of open functions and leads to a denial of service. This flaw allows an attacker to crash the system.

  • CVE-2022-26336MedMar 4, 2022
    risk 0.36cvss 5.5epss 0.02

    A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception. This package is used to read TNEF files (Microsoft Outlook and Microsoft Exchange Server). If an application uses poi-scratchpad to parse TNEF files and the…

  • CVE-2022-0675MedMar 2, 2022
    risk 0.36cvss 5.6epss 0.01

    In certain situations it is possible for an unmanaged rule to exist on the target system that has the same comment as the rule specified in the manifest. This could allow for unmanaged rules to exist on the target system and leave the system in an unsafe state.

  • CVE-2022-20037MedFeb 9, 2022
    risk 0.36cvss 5.5epss 0.00

    In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06171705; Issue ID:…

  • CVE-2022-20036MedFeb 9, 2022
    risk 0.36cvss 5.5epss 0.00

    In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06171689; Issue ID:…

  • CVE-2022-20017MedFeb 9, 2022
    risk 0.36cvss 5.5epss 0.00

    In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05862991; Issue ID:…

  • CVE-2021-0076MedFeb 9, 2022
    risk 0.36cvss 5.5epss 0.00

    Improper Validation of Specified Index, Position, or Offset in Input in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in Windows 10 and 11 may allow a privileged user to potentially enable denial of service via local…

  • CVE-2021-0072MedFeb 9, 2022
    risk 0.36cvss 5.5epss 0.00

    Improper input validation in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in Windows 10 and 11 may allow a privileged user to potentially enable information disclosure via local access.

  • CVE-2022-22820MedJan 20, 2022
    risk 0.36cvss 5.5epss 0.01

    Due to the lack of media file checks before rendering, it was possible for an attacker to cause abnormal CPU consumption for message recipient by sending specially crafted gif image in LINE for Windows before 7.4.

  • CVE-2022-20020MedJan 4, 2022
    risk 0.36cvss 5.5epss 0.00

    In libvcodecdrv, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05943906; Issue ID:…

  • CVE-2022-20019MedJan 4, 2022
    risk 0.36cvss 5.5epss 0.00

    In libMtkOmxGsmDec, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05917620; Issue ID:…

  • CVE-2021-33098MedNov 17, 2021
    risk 0.36cvss 5.5epss 0.00

    Improper input validation in the Intel(R) Ethernet ixgbe driver for Linux before version 3.17.3 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2021-26327MedNov 16, 2021
    risk 0.36cvss 5.5epss 0.00

    Insufficient validation of guest context in the SNP Firmware could lead to a potential loss of guest confidentiality.