CWE-20
Improper Input Validation
Description
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9
CVEs mapped to this weakness (13,352)
page 373 of 668| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-14983 | Med | 0.36 | 5.5 | 0.00 | Apr 25, 2019 | The Sony Xperia L1 Android device with a build fingerprint of Sony/G3313/G3313:7.0/43.0.A.6.49/2867558199:user/release-keys contains the android framework (i.e., system_server) with a package name of android (versionCode=24, versionName=7.0) that has been modified by Sony or… | ||
| CVE-2018-4004 | Med | 0.36 | 5.5 | 0.00 | Apr 17, 2019 | An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the disconnectService functionality. A non-root user is able to kill any privileged process on the system. An attacker would need local access to the machine for a successful… | ||
| CVE-2019-1798 | Med | 0.36 | 5.5 | 0.01 | Apr 8, 2019 | A vulnerability in the Portable Executable (PE) file scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a… | ||
| CVE-2019-1788 | Med | 0.36 | 5.5 | 0.02 | Apr 8, 2019 | A vulnerability in the Object Linking & Embedding (OLE2) file scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is… | ||
| CVE-2019-1787 | Med | 0.36 | 5.5 | 0.02 | Apr 8, 2019 | A vulnerability in the Portable Document Format (PDF) scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is… | ||
| CVE-2019-1786 | Med | 0.36 | 5.5 | 0.01 | Apr 8, 2019 | A vulnerability in the Portable Document Format (PDF) scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and 0.101.0 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is… | ||
| CVE-2018-4462 | Med | 0.36 | 5.5 | 0.01 | Apr 3, 2019 | A validation issue was addressed with improved input sanitization. This issue affected versions prior to macOS Mojave 10.14.2. | ||
| CVE-2018-4418 | Med | 0.36 | 5.5 | 0.01 | Apr 3, 2019 | A validation issue was addressed with improved input sanitization. This issue affected versions prior to macOS Mojave 10.14. | ||
| CVE-2018-4417 | Med | 0.36 | 5.5 | 0.01 | Apr 3, 2019 | A validation issue was addressed with improved input sanitization. This issue affected versions prior to macOS Mojave 10.14. | ||
| CVE-2018-4400 | Med | 0.36 | 5.5 | 0.01 | Apr 3, 2019 | A validation issue was addressed with improved logic. This issue affected versions prior to iOS 12.1, macOS Mojave 10.14.1, watchOS 5.1. | ||
| CVE-2018-4399 | Med | 0.36 | 5.5 | 0.01 | Apr 3, 2019 | An access issue existed with privileged API calls. This issue was addressed with additional restrictions. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5. | ||
| CVE-2018-4396 | Med | 0.36 | 5.5 | 0.01 | Apr 3, 2019 | A validation issue was addressed with improved input sanitization. This issue affected versions prior to macOS Mojave 10.14. | ||
| CVE-2018-4395 | Med | 0.36 | 5.5 | 0.00 | Apr 3, 2019 | This issue was addressed with improved checks. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5. | ||
| CVE-2018-4363 | Med | 0.36 | 5.5 | 0.01 | Apr 3, 2019 | An input validation issue existed in the kernel. This issue was addressed with improved input validation. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5. | ||
| CVE-2018-4348 | Med | 0.36 | 5.5 | 0.00 | Apr 3, 2019 | A validation issue was addressed with improved logic. This issue affected versions prior to macOS Mojave 10.14. | ||
| CVE-2018-4346 | Med | 0.36 | 5.5 | 0.01 | Apr 3, 2019 | A validation issue existed which allowed local file access. This was addressed with input sanitization. This issue affected versions prior to macOS Mojave 10.14. | ||
| CVE-2018-4342 | Med | 0.36 | 5.5 | 0.00 | Apr 3, 2019 | A configuration issue was addressed with additional restrictions. This issue affected versions prior to macOS Mojave 10.14.1. | ||
| CVE-2018-4338 | Med | 0.36 | 5.5 | 0.01 | Apr 3, 2019 | A validation issue was addressed with improved input sanitization. This issue affected versions prior to macOS Mojave 10.14. | ||
| CVE-2018-4335 | Med | 0.36 | 5.5 | 0.01 | Apr 3, 2019 | A validation issue was addressed with improved input sanitization. This issue affected versions prior to iOS 12. | ||
| CVE-2018-4333 | Med | 0.36 | 5.5 | 0.01 | Apr 3, 2019 | A validation issue was addressed with improved input sanitization. This issue affected versions prior to iOS 12, macOS Mojave 10.14. |
- risk 0.36cvss 5.5epss 0.00
The Sony Xperia L1 Android device with a build fingerprint of Sony/G3313/G3313:7.0/43.0.A.6.49/2867558199:user/release-keys contains the android framework (i.e., system_server) with a package name of android (versionCode=24, versionName=7.0) that has been modified by Sony or…
- risk 0.36cvss 5.5epss 0.00
An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the disconnectService functionality. A non-root user is able to kill any privileged process on the system. An attacker would need local access to the machine for a successful…
- risk 0.36cvss 5.5epss 0.01
A vulnerability in the Portable Executable (PE) file scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a…
- risk 0.36cvss 5.5epss 0.02
A vulnerability in the Object Linking & Embedding (OLE2) file scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is…
- risk 0.36cvss 5.5epss 0.02
A vulnerability in the Portable Document Format (PDF) scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is…
- risk 0.36cvss 5.5epss 0.01
A vulnerability in the Portable Document Format (PDF) scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and 0.101.0 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is…
- risk 0.36cvss 5.5epss 0.01
A validation issue was addressed with improved input sanitization. This issue affected versions prior to macOS Mojave 10.14.2.
- risk 0.36cvss 5.5epss 0.01
A validation issue was addressed with improved input sanitization. This issue affected versions prior to macOS Mojave 10.14.
- risk 0.36cvss 5.5epss 0.01
A validation issue was addressed with improved input sanitization. This issue affected versions prior to macOS Mojave 10.14.
- risk 0.36cvss 5.5epss 0.01
A validation issue was addressed with improved logic. This issue affected versions prior to iOS 12.1, macOS Mojave 10.14.1, watchOS 5.1.
- risk 0.36cvss 5.5epss 0.01
An access issue existed with privileged API calls. This issue was addressed with additional restrictions. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
- risk 0.36cvss 5.5epss 0.01
A validation issue was addressed with improved input sanitization. This issue affected versions prior to macOS Mojave 10.14.
- risk 0.36cvss 5.5epss 0.00
This issue was addressed with improved checks. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.
- risk 0.36cvss 5.5epss 0.01
An input validation issue existed in the kernel. This issue was addressed with improved input validation. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5.
- risk 0.36cvss 5.5epss 0.00
A validation issue was addressed with improved logic. This issue affected versions prior to macOS Mojave 10.14.
- risk 0.36cvss 5.5epss 0.01
A validation issue existed which allowed local file access. This was addressed with input sanitization. This issue affected versions prior to macOS Mojave 10.14.
- risk 0.36cvss 5.5epss 0.00
A configuration issue was addressed with additional restrictions. This issue affected versions prior to macOS Mojave 10.14.1.
- risk 0.36cvss 5.5epss 0.01
A validation issue was addressed with improved input sanitization. This issue affected versions prior to macOS Mojave 10.14.
- risk 0.36cvss 5.5epss 0.01
A validation issue was addressed with improved input sanitization. This issue affected versions prior to iOS 12.
- risk 0.36cvss 5.5epss 0.01
A validation issue was addressed with improved input sanitization. This issue affected versions prior to iOS 12, macOS Mojave 10.14.