CWE-20
Improper Input Validation
Description
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9
CVEs mapped to this weakness (13,352)
page 371 of 668| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-11998 | Med | 0.36 | 5.5 | 0.01 | Jan 16, 2020 | HPE Superdome Flex Server is vulnerable to multiple remote vulnerabilities via improper input validation of administrator commands. This vulnerability could allow an Administrator to bypass security restrictions and access multiple remote vulnerabilities including information… | ||
| CVE-2019-8817 | Med | 0.36 | 5.5 | 0.01 | Dec 18, 2019 | A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Catalina 10.15.1. An application may be able to read restricted memory. | ||
| CVE-2019-8794 | Med | 0.36 | 5.5 | 0.01 | Dec 18, 2019 | A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to read restricted memory. | ||
| CVE-2019-8507 | Med | 0.36 | 5.5 | 0.00 | Dec 18, 2019 | Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Mojave 10.14.4. Processing malicious data may lead to unexpected application termination. | ||
| CVE-2014-8178 | Med | 0.36 | 5.5 | 0.00 | Dec 17, 2019 | Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 do not use a globally unique identifier to store image layers, which makes it easier for attackers to poison the image cache via a crafted image in pull or push commands. | ||
| CVE-2019-13707 | Med | 0.36 | 5.5 | 0.00 | Nov 25, 2019 | Insufficient validation of untrusted input in intents in Google Chrome on Android prior to 78.0.3904.70 allowed a local attacker to leak files via a crafted application. | ||
| CVE-2019-10535 | Med | 0.36 | 5.5 | 0.00 | Nov 21, 2019 | Improper validation for loop variable received from firmware can lead to out of bound access in WLAN function while iterating through loop in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… | ||
| CVE-2014-0084 | Med | 0.36 | 5.5 | 0.00 | Nov 21, 2019 | Ruby gem openshift-origin-node before 2014-02-14 does not contain a cronjob timeout which could result in a denial of service in cron.daily and cron.weekly. | ||
| CVE-2015-1607 | Med | 0.36 | 5.5 | 0.02 | Nov 20, 2019 | kbx/keybox-search.c in GnuPG before 1.4.19, 2.0.x before 2.0.27, and 2.1.x before 2.1.2 does not properly handle bitwise left-shifts, which allows remote attackers to cause a denial of service (invalid read operation) via a crafted keyring file, related to sign extensions and… | ||
| CVE-2014-5118 | Med | 0.36 | 5.5 | 0.00 | Nov 18, 2019 | Trusted Boot (tboot) before 1.8.2 has a 'loader.c' Security Bypass Vulnerability | ||
| CVE-2019-6663 | Med | 0.36 | 5.5 | 0.01 | Nov 15, 2019 | The BIG-IP 15.0.0-15.0.1, 14.0.0-14.1.2.2, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.1-11.6.5.1, BIG-IQ 7.0.0, 6.0.0-6.1.0, and 5.2.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1 configuration utility is vulnerable to Anti DNS Pinning (DNS Rebinding) attack. | ||
| CVE-2019-14591 | Med | 0.36 | 5.5 | 0.00 | Nov 14, 2019 | Improper input validation in the API for Intel(R) Graphics Driver versions before 26.20.100.7209 may allow an authenticated user to potentially enable denial of service via local access. | ||
| CVE-2019-11089 | Med | 0.36 | 5.5 | 0.00 | Nov 14, 2019 | Insufficient input validation in Kernel Mode module for Intel(R) Graphics Driver before version 25.20.100.6519 may allow an authenticated user to potentially enable denial of service via local access. | ||
| CVE-2019-0149 | Med | 0.36 | 5.5 | 0.00 | Nov 14, 2019 | Insufficient input validation in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 2.8.43 may allow an authenticated user to potentially enable a denial of service via local access. | ||
| CVE-2019-0147 | Med | 0.36 | 5.5 | 0.00 | Nov 14, 2019 | Insufficient input validation in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow an authenticated user to potentially enable a denial of service via local access. | ||
| CVE-2019-5230 | Med | 0.36 | 5.5 | 0.00 | Nov 13, 2019 | P20 Pro, P20, Mate RS smartphones with versions earlier than Charlotte-AL00A 9.1.0.321(C00E320R1P1T8), versions earlier than Emily-AL00A 9.1.0.321(C00E320R1P1T8), versions earlier than NEO-AL00D NEO-AL00 9.1.0.321(C786E320R1P1T8) have an improper validation vulnerability. The… | ||
| CVE-2013-1820 | Med | 0.36 | 5.5 | 0.00 | Nov 8, 2019 | tuned before 2.x allows local users to kill running processes due to insecure permissions with tuned's ktune service. | ||
| CVE-2013-3718 | Med | 0.36 | 5.5 | 0.01 | Nov 1, 2019 | evince is missing a check on number of pages which can lead to a segmentation fault | ||
| CVE-2010-3373 | Med | 0.36 | 5.5 | 0.00 | Oct 29, 2019 | paxtest handles temporary files insecurely | ||
| CVE-2010-3293 | Med | 0.36 | 5.5 | 0.00 | Oct 28, 2019 | mailscanner can allow local users to prevent virus signatures from being updated |
- risk 0.36cvss 5.5epss 0.01
HPE Superdome Flex Server is vulnerable to multiple remote vulnerabilities via improper input validation of administrator commands. This vulnerability could allow an Administrator to bypass security restrictions and access multiple remote vulnerabilities including information…
- risk 0.36cvss 5.5epss 0.01
A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Catalina 10.15.1. An application may be able to read restricted memory.
- risk 0.36cvss 5.5epss 0.01
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to read restricted memory.
- risk 0.36cvss 5.5epss 0.00
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Mojave 10.14.4. Processing malicious data may lead to unexpected application termination.
- risk 0.36cvss 5.5epss 0.00
Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 do not use a globally unique identifier to store image layers, which makes it easier for attackers to poison the image cache via a crafted image in pull or push commands.
- risk 0.36cvss 5.5epss 0.00
Insufficient validation of untrusted input in intents in Google Chrome on Android prior to 78.0.3904.70 allowed a local attacker to leak files via a crafted application.
- risk 0.36cvss 5.5epss 0.00
Improper validation for loop variable received from firmware can lead to out of bound access in WLAN function while iterating through loop in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…
- risk 0.36cvss 5.5epss 0.00
Ruby gem openshift-origin-node before 2014-02-14 does not contain a cronjob timeout which could result in a denial of service in cron.daily and cron.weekly.
- risk 0.36cvss 5.5epss 0.02
kbx/keybox-search.c in GnuPG before 1.4.19, 2.0.x before 2.0.27, and 2.1.x before 2.1.2 does not properly handle bitwise left-shifts, which allows remote attackers to cause a denial of service (invalid read operation) via a crafted keyring file, related to sign extensions and…
- risk 0.36cvss 5.5epss 0.00
Trusted Boot (tboot) before 1.8.2 has a 'loader.c' Security Bypass Vulnerability
- risk 0.36cvss 5.5epss 0.01
The BIG-IP 15.0.0-15.0.1, 14.0.0-14.1.2.2, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.1-11.6.5.1, BIG-IQ 7.0.0, 6.0.0-6.1.0, and 5.2.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1 configuration utility is vulnerable to Anti DNS Pinning (DNS Rebinding) attack.
- risk 0.36cvss 5.5epss 0.00
Improper input validation in the API for Intel(R) Graphics Driver versions before 26.20.100.7209 may allow an authenticated user to potentially enable denial of service via local access.
- risk 0.36cvss 5.5epss 0.00
Insufficient input validation in Kernel Mode module for Intel(R) Graphics Driver before version 25.20.100.6519 may allow an authenticated user to potentially enable denial of service via local access.
- risk 0.36cvss 5.5epss 0.00
Insufficient input validation in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 2.8.43 may allow an authenticated user to potentially enable a denial of service via local access.
- risk 0.36cvss 5.5epss 0.00
Insufficient input validation in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow an authenticated user to potentially enable a denial of service via local access.
- risk 0.36cvss 5.5epss 0.00
P20 Pro, P20, Mate RS smartphones with versions earlier than Charlotte-AL00A 9.1.0.321(C00E320R1P1T8), versions earlier than Emily-AL00A 9.1.0.321(C00E320R1P1T8), versions earlier than NEO-AL00D NEO-AL00 9.1.0.321(C786E320R1P1T8) have an improper validation vulnerability. The…
- risk 0.36cvss 5.5epss 0.00
tuned before 2.x allows local users to kill running processes due to insecure permissions with tuned's ktune service.
- risk 0.36cvss 5.5epss 0.01
evince is missing a check on number of pages which can lead to a segmentation fault
- risk 0.36cvss 5.5epss 0.00
paxtest handles temporary files insecurely
- risk 0.36cvss 5.5epss 0.00
mailscanner can allow local users to prevent virus signatures from being updated