VYPR

CWE-20

Improper Input Validation

ClassStableLikelihood: High

Description

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9

CVEs mapped to this weakness (13,352)

page 372 of 668
  • CVE-2019-12400MedAug 23, 2019
    risk 0.36cvss 5.5epss 0.01

    In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static pool of DocumentBuilders. However, if some untrusted code can register a malicious implementation with the thread context class…

  • CVE-2019-2136MedAug 20, 2019
    risk 0.36cvss 5.5epss 0.00

    In Status::readFromParcel of Status.cpp, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android.…

  • CVE-2017-18449MedAug 2, 2019
    risk 0.36cvss 5.5epss 0.00

    cPanel before 64.0.21 allows certain file-rename operations in the context of the root account via scripts/convert_roundcube_mysql2sqlite (SEC-254).

  • CVE-2017-18405MedAug 2, 2019
    risk 0.36cvss 5.5epss 0.00

    cPanel before 68.0.15 allows arbitrary file-read operations because of the backup .htaccess modification logic (SEC-345).

  • CVE-2018-20917MedAug 1, 2019
    risk 0.36cvss 5.5epss 0.00

    cPanel before 70.0.23 allows any user to disable Solr (SEC-371).

  • CVE-2018-20891MedAug 1, 2019
    risk 0.36cvss 5.5epss 0.00

    cPanel before 74.0.0 allows arbitrary file-read operations during File Restoration (SEC-436).

  • CVE-2019-2330MedJul 25, 2019
    risk 0.36cvss 5.5epss 0.00

    improper input validation in allocation request for secure allocations can lead to page fault. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired…

  • CVE-2018-15738MedJul 9, 2019
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains an Arbitrary Write vulnerability due to not validating the output buffer address value from IOCtl 0x8000205F.

  • CVE-2018-15735MedJun 21, 2019
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains an Arbitrary Write vulnerability due to not validating the output buffer address value from IOCtl 0x8000206F.

  • CVE-2018-15734MedJun 21, 2019
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains an Arbitrary Write vulnerability due to not validating the output buffer address value from IOCtl 0x8000206B.

  • CVE-2018-15732MedJun 21, 2019
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains an Arbitrary Write vulnerability due to not validating the output buffer address value from IOCtl 0x80002063.

  • CVE-2018-15731MedJun 21, 2019
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulnerability due to not validating the output buffer address value from IOCtl 0x8000205B.

  • CVE-2018-15730MedJun 21, 2019
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulnerability due to not validating the output buffer address value from IOCtl 0x80002067.

  • CVE-2018-15729MedJun 21, 2019
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulnerability due to not validating the output buffer address value from IOCtl 0x8000204B.

  • CVE-2018-15737MedJun 21, 2019
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulnerability due to not validating the output buffer address value from IOCtl 0x80002043.

  • CVE-2018-15736MedJun 21, 2019
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulnerability due to not validating the output buffer address value from IOCtl 0x8000204F.

  • CVE-2019-0157MedJun 13, 2019
    risk 0.36cvss 5.5epss 0.00

    Insufficient input validation in the Intel(R) SGX driver for Linux may allow an authenticated user to potentially enable a denial of service via local access.

  • CVE-2019-5244MedJun 4, 2019
    risk 0.36cvss 5.5epss 0.01

    Mate 9 Pro Huawei smartphones earlier than LON-L29C 8.0.0.361(C636) versions have an information leak vulnerability due to the lack of input validation. An attacker tricks the user who has root privilege to install an application on the smart phone, and the application can read…

  • CVE-2019-9221MedMay 29, 2019
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 3 of 5).

  • CVE-2019-0115MedMay 17, 2019
    risk 0.36cvss 5.5epss 0.00

    Insufficient input validation in KMD module for Intel(R) Graphics Driver before version 10.18.14.5067 (aka 15.36.x.5067) and 10.18.10.5069 (aka 15.33.x.5069) may allow an authenticated user to potentially enable denial of service via local access.