CWE-20
Improper Input Validation
Description
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-101 · CAPEC-104 · CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-136 · CAPEC-14 · CAPEC-153 · CAPEC-182 · CAPEC-209 · CAPEC-22 · CAPEC-23 · CAPEC-230 · CAPEC-231 · CAPEC-24 · CAPEC-250 · CAPEC-261 · CAPEC-267 · CAPEC-28 · CAPEC-3 · CAPEC-31 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-473 · CAPEC-52 · CAPEC-53 · CAPEC-588 · CAPEC-63 · CAPEC-64 · CAPEC-664 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-73 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-81 · CAPEC-83 · CAPEC-85 · CAPEC-88 · CAPEC-9
CVEs mapped to this weakness (13,352)
page 396 of 668| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2014-1935 | Med | 0.35 | 5.3 | 0.01 | Nov 21, 2019 | 9base 1:6-6 and 1:6-7 insecurely creates temporary files which results in predictable filenames. | ||
| CVE-2013-4101 | Med | 0.35 | 5.3 | 0.01 | Nov 4, 2019 | Cryptocat before 2.0.22 Link Markup Decorator HTML Handling Weakness | ||
| CVE-2010-2490 | Med | 0.35 | 6.5 | 0.02 | Oct 31, 2019 | Mumble: murmur-server has DoS due to malformed client query | ||
| CVE-2019-9283 | Med | 0.35 | 6.5 | 0.01 | Sep 27, 2019 | In AAC Codec, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID:… | ||
| CVE-2019-1969 | Med | 0.35 | 5.3 | 0.01 | Aug 30, 2019 | A vulnerability in the implementation of the Simple Network Management Protocol (SNMP) Access Control List (ACL) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to perform SNMP polling of an affected device, even if it is configured to deny SNMP… | ||
| CVE-2019-14979 | Med | 0.35 | 5.3 | 0.01 | Aug 29, 2019 | cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.17 for WordPress allows Parameter Tampering in an amount parameter (such as amount_1), as demonstrated by purchasing an item for lower than the intended price. NOTE: The plugin author states… | ||
| CVE-2019-14978 | Med | 0.35 | 5.3 | 0.01 | Aug 29, 2019 | /payu/icpcheckout/ in the WooCommerce PayU India Payment Gateway plugin 2.1.1 for WordPress allows Parameter Tampering in the purchaseQuantity=1 parameter, as demonstrated by purchasing an item for lower than the intended price. | ||
| CVE-2016-10899 | Med | 0.35 | 5.3 | 0.01 | Aug 21, 2019 | The total-security plugin before 3.4.1 for WordPress has a settings-change vulnerability. | ||
| CVE-2017-18444 | Med | 0.35 | 5.3 | 0.01 | Aug 2, 2019 | cPanel before 64.0.21 allows demo accounts to execute SSH API commands (SEC-248). | ||
| CVE-2019-11698 | Med | 0.35 | 5.3 | 0.01 | Jul 23, 2019 | If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookmark is subsequently dragged and dropped into the web content area, an arbitrary query of a user's browser history can be run and transmitted to the content page via drop event… | ||
| CVE-2019-3571 | Med | 0.35 | 5.3 | 0.01 | Jul 16, 2019 | An input validation issue affected WhatsApp Desktop versions prior to 0.3.3793 which allows malicious clients to send files to users that would be displayed with a wrong extension. | ||
| CVE-2018-20852 | Med | 0.35 | 5.3 | 0.04 | Jul 13, 2019 | http.cookiejar.DefaultPolicy.domain_return_ok in Lib/http/cookiejar.py in Python before 3.7.3 does not correctly validate the domain: it can be tricked into sending existing cookies to the wrong server. An attacker may abuse this flaw by using a server with a hostname that has… | ||
| CVE-2018-19580 | Med | 0.35 | 5.3 | 0.01 | Jul 10, 2019 | All versions of GitLab prior to 11.5.1, 11.4.8, and 11.3.11 do not send an email to the old email address when an email address change is made. | ||
| CVE-2017-8341 | Med | 0.35 | 5.3 | 0.01 | May 22, 2019 | Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Content Spoofing. | ||
| CVE-2018-12270 | Med | 0.35 | 5.4 | 0.01 | May 20, 2019 | In Valve Steam 1528829181 BETA, it is possible to perform a homograph / homoglyph attack to create fake URLs in the client, which may trick users into visiting unintended web sites. | ||
| CVE-2019-1844 | Med | 0.35 | 5.3 | 0.02 | May 3, 2019 | A vulnerability in certain attachment detection mechanisms of the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the filtering functionality of an affected device. The vulnerability is due to improper detection of certain content… | ||
| CVE-2019-9801 | Med | 0.35 | 5.3 | 0.01 | Apr 26, 2019 | Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows operating systems. This should only happen if the program has specifically registered itself as a "URL Handler" in the… | ||
| CVE-2019-1837 | Med | 0.35 | 5.3 | 0.02 | Apr 18, 2019 | A vulnerability in the User Data Services (UDS) API of Cisco Unified Communications Manager (Unified CM) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the management GUI. The vulnerability is due to improper validation of input… | ||
| CVE-2019-1711 | Med | 0.35 | 5.3 | 0.02 | Apr 17, 2019 | A vulnerability in the Event Management Service daemon (emsd) of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper handling of gRPC requests. An attacker… | ||
| CVE-2019-0768 | Med | 0.35 | 4.3 | 0.48 | Apr 9, 2019 | A security feature bypass vulnerability exists when Internet Explorer VBScript execution policy does not properly restrict VBScript under specific conditions, and to allow requests that should otherwise be ignored, aka 'Internet Explorer Security Feature Bypass Vulnerability'.… |
- risk 0.35cvss 5.3epss 0.01
9base 1:6-6 and 1:6-7 insecurely creates temporary files which results in predictable filenames.
- risk 0.35cvss 5.3epss 0.01
Cryptocat before 2.0.22 Link Markup Decorator HTML Handling Weakness
- risk 0.35cvss 6.5epss 0.02
Mumble: murmur-server has DoS due to malformed client query
- risk 0.35cvss 6.5epss 0.01
In AAC Codec, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID:…
- risk 0.35cvss 5.3epss 0.01
A vulnerability in the implementation of the Simple Network Management Protocol (SNMP) Access Control List (ACL) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to perform SNMP polling of an affected device, even if it is configured to deny SNMP…
- risk 0.35cvss 5.3epss 0.01
cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.17 for WordPress allows Parameter Tampering in an amount parameter (such as amount_1), as demonstrated by purchasing an item for lower than the intended price. NOTE: The plugin author states…
- risk 0.35cvss 5.3epss 0.01
/payu/icpcheckout/ in the WooCommerce PayU India Payment Gateway plugin 2.1.1 for WordPress allows Parameter Tampering in the purchaseQuantity=1 parameter, as demonstrated by purchasing an item for lower than the intended price.
- risk 0.35cvss 5.3epss 0.01
The total-security plugin before 3.4.1 for WordPress has a settings-change vulnerability.
- risk 0.35cvss 5.3epss 0.01
cPanel before 64.0.21 allows demo accounts to execute SSH API commands (SEC-248).
- risk 0.35cvss 5.3epss 0.01
If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookmark is subsequently dragged and dropped into the web content area, an arbitrary query of a user's browser history can be run and transmitted to the content page via drop event…
- risk 0.35cvss 5.3epss 0.01
An input validation issue affected WhatsApp Desktop versions prior to 0.3.3793 which allows malicious clients to send files to users that would be displayed with a wrong extension.
- risk 0.35cvss 5.3epss 0.04
http.cookiejar.DefaultPolicy.domain_return_ok in Lib/http/cookiejar.py in Python before 3.7.3 does not correctly validate the domain: it can be tricked into sending existing cookies to the wrong server. An attacker may abuse this flaw by using a server with a hostname that has…
- risk 0.35cvss 5.3epss 0.01
All versions of GitLab prior to 11.5.1, 11.4.8, and 11.3.11 do not send an email to the old email address when an email address change is made.
- risk 0.35cvss 5.3epss 0.01
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Content Spoofing.
- risk 0.35cvss 5.4epss 0.01
In Valve Steam 1528829181 BETA, it is possible to perform a homograph / homoglyph attack to create fake URLs in the client, which may trick users into visiting unintended web sites.
- risk 0.35cvss 5.3epss 0.02
A vulnerability in certain attachment detection mechanisms of the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the filtering functionality of an affected device. The vulnerability is due to improper detection of certain content…
- risk 0.35cvss 5.3epss 0.01
Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows operating systems. This should only happen if the program has specifically registered itself as a "URL Handler" in the…
- risk 0.35cvss 5.3epss 0.02
A vulnerability in the User Data Services (UDS) API of Cisco Unified Communications Manager (Unified CM) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the management GUI. The vulnerability is due to improper validation of input…
- risk 0.35cvss 5.3epss 0.02
A vulnerability in the Event Management Service daemon (emsd) of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper handling of gRPC requests. An attacker…
- risk 0.35cvss 4.3epss 0.48
A security feature bypass vulnerability exists when Internet Explorer VBScript execution policy does not properly restrict VBScript under specific conditions, and to allow requests that should otherwise be ignored, aka 'Internet Explorer Security Feature Bypass Vulnerability'.…