VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,352)

page 371 of 668
  • CVE-2019-11998MedJan 16, 2020
    risk 0.36cvss 5.5epss 0.01

    HPE Superdome Flex Server is vulnerable to multiple remote vulnerabilities via improper input validation of administrator commands. This vulnerability could allow an Administrator to bypass security restrictions and access multiple remote vulnerabilities including information…

  • CVE-2019-8817MedDec 18, 2019
    risk 0.36cvss 5.5epss 0.01

    A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Catalina 10.15.1. An application may be able to read restricted memory.

  • CVE-2019-8794MedDec 18, 2019
    risk 0.36cvss 5.5epss 0.01

    A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to read restricted memory.

  • CVE-2019-8507MedDec 18, 2019
    risk 0.36cvss 5.5epss 0.00

    Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Mojave 10.14.4. Processing malicious data may lead to unexpected application termination.

  • CVE-2014-8178MedDec 17, 2019
    risk 0.36cvss 5.5epss 0.00

    Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 do not use a globally unique identifier to store image layers, which makes it easier for attackers to poison the image cache via a crafted image in pull or push commands.

  • CVE-2019-13707MedNov 25, 2019
    risk 0.36cvss 5.5epss 0.00

    Insufficient validation of untrusted input in intents in Google Chrome on Android prior to 78.0.3904.70 allowed a local attacker to leak files via a crafted application.

  • CVE-2019-10535MedNov 21, 2019
    risk 0.36cvss 5.5epss 0.00

    Improper validation for loop variable received from firmware can lead to out of bound access in WLAN function while iterating through loop in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…

  • CVE-2014-0084MedNov 21, 2019
    risk 0.36cvss 5.5epss 0.00

    Ruby gem openshift-origin-node before 2014-02-14 does not contain a cronjob timeout which could result in a denial of service in cron.daily and cron.weekly.

  • CVE-2015-1607MedNov 20, 2019
    risk 0.36cvss 5.5epss 0.02

    kbx/keybox-search.c in GnuPG before 1.4.19, 2.0.x before 2.0.27, and 2.1.x before 2.1.2 does not properly handle bitwise left-shifts, which allows remote attackers to cause a denial of service (invalid read operation) via a crafted keyring file, related to sign extensions and…

  • CVE-2014-5118MedNov 18, 2019
    risk 0.36cvss 5.5epss 0.00

    Trusted Boot (tboot) before 1.8.2 has a 'loader.c' Security Bypass Vulnerability

  • CVE-2019-6663MedNov 15, 2019
    risk 0.36cvss 5.5epss 0.01

    The BIG-IP 15.0.0-15.0.1, 14.0.0-14.1.2.2, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.1-11.6.5.1, BIG-IQ 7.0.0, 6.0.0-6.1.0, and 5.2.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1 configuration utility is vulnerable to Anti DNS Pinning (DNS Rebinding) attack.

  • CVE-2019-14591MedNov 14, 2019
    risk 0.36cvss 5.5epss 0.00

    Improper input validation in the API for Intel(R) Graphics Driver versions before 26.20.100.7209 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2019-11089MedNov 14, 2019
    risk 0.36cvss 5.5epss 0.00

    Insufficient input validation in Kernel Mode module for Intel(R) Graphics Driver before version 25.20.100.6519 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2019-0149MedNov 14, 2019
    risk 0.36cvss 5.5epss 0.00

    Insufficient input validation in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 2.8.43 may allow an authenticated user to potentially enable a denial of service via local access.

  • CVE-2019-0147MedNov 14, 2019
    risk 0.36cvss 5.5epss 0.00

    Insufficient input validation in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow an authenticated user to potentially enable a denial of service via local access.

  • CVE-2019-5230MedNov 13, 2019
    risk 0.36cvss 5.5epss 0.00

    P20 Pro, P20, Mate RS smartphones with versions earlier than Charlotte-AL00A 9.1.0.321(C00E320R1P1T8), versions earlier than Emily-AL00A 9.1.0.321(C00E320R1P1T8), versions earlier than NEO-AL00D NEO-AL00 9.1.0.321(C786E320R1P1T8) have an improper validation vulnerability. The…

  • CVE-2013-1820MedNov 8, 2019
    risk 0.36cvss 5.5epss 0.00

    tuned before 2.x allows local users to kill running processes due to insecure permissions with tuned's ktune service.

  • CVE-2013-3718MedNov 1, 2019
    risk 0.36cvss 5.5epss 0.01

    evince is missing a check on number of pages which can lead to a segmentation fault

  • CVE-2010-3373MedOct 29, 2019
    risk 0.36cvss 5.5epss 0.00

    paxtest handles temporary files insecurely

  • CVE-2010-3293MedOct 28, 2019
    risk 0.36cvss 5.5epss 0.00

    mailscanner can allow local users to prevent virus signatures from being updated